Similar to #504, we can use the https://github.blog/2023-04-19-introducing-npm-package-provenance/ feature. This involves adding `--provenance` to `npm publish`, and using the `id-token: write` permission.