Add line about `workflow_call` (#1721)

Describe how `workflow_call` works within trusted publishing.

Reggi committed Sep 22, 2025 at 11:10 UTC 1ccdca298819e04c51fc0ea1b356ede8dff769db
1 file changed +2
content/packages-and-modules/securing-your-code/trusted-publishers.mdx
+2
@@ -278,6 +278,8 @@ If your package has private dependencies and `npm install` or `npm ci` is failin
278
279 For packages in private repositories, provenance will not be generated even though you're using trusted publishing. This is a [known limitation](https://github.blog/changelog/2023-07-25-publishing-with-npm-provenance-from-private-source-repositories-is-no-longer-supported/) that applies regardless of whether your package itself is public or private.
280
281 +Some GitHub Actions workflows use `workflow_call` to invoke other workflows that run `npm publish`, or use `workflow_dispatch` for manual publishing. When this happens, validation checks the calling workflow's name instead of the workflow that actually contains the publish command, which can cause configuration mismatches.
282 +
283 ## Limitations and future improvements
284
285 Trusted publishing currently supports only cloud-hosted runners. Support for self-hosted runners is intended for a future release. Each package can only have one trusted publisher configured at a time, though you can update this configuration as needed.