Uses brand new token-less GitHub OIDC connector to NPM, ensure to link package in npm settings first The Trusted Publishing also provides provenance statements by default It happens after GitHub ...