Release credentials
Release automation must not store or receive an npm token. The first npm publication uses an exact GitHub-attested candidate and an interactive maintainer session with passkey authentication because npm does not permit staging or trusted publishing before the package exists. Later npm staging and MCP Registry registration use GitHub OIDC, with npm restricted to stage-only trusted publishing and token-based publication disabled.
Release automation must attest the first-publication candidate, keep OIDC provenance enabled for later staged versions, verify the checksum-pinned MCP publisher, compare the reconstructed archive with npm's SHA-512 integrity before OCI or registry publication, and preserve full commit SHA pins for every GitHub Action.
Canonical source: SECURITY.md
Documentation generated for guildcontrol@0.0.0. Canonical source and edit history remain in the public repository. GuildControl is an independent project and is not affiliated with or endorsed by Discord Inc. Discord is used only to identify the platform that GuildControl connects to.