Repository navigation
Publish to npm with trusted publishing (OIDC) instead of NPM_TOKEN - #268
Merged
Merged
Conversation
The NPM_TOKEN secret has stopped working (the v0.35.1 publish got E404 on PUT). Each package is now configured on npmjs.com with this workflow as a trusted publisher, so drop the token. Trusted publishing needs npm 11.5.1 or later, and the npm bundled with Node 22.14 is older, so install a newer one first. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013mDr1nhgyzST2iPzCzMcCd
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Switches the release workflow from the
NPM_TOKENsecret to npm trusted publishing (OIDC).The
NPM_TOKENsecret (last updated 2025-02-23) no longer works: thev0.35.1publish failed withE404 Not Found - PUT .../litform-core, which is how npm reports a rejected token. All seven packages now have this workflow (release.yml) configured as a trusted publisher on npmjs.com.Changes
^11.5.1before publishing. Trusted publishing needs npm 11.5.1+, and the npm bundled with Node 22.14 (.node-version) is 10.9.x.NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}from the publish step.Unchanged:
id-token: writewas already granted, and--provenancestays (provenance is also automatic for public repos).Verifying
This can only really be tested by publishing. One thing to watch on the first run:
actions/setup-nodewithregistry-urlwrites an.npmrcthat expectsNODE_AUTH_TOKEN; npm's docs don't say whether that interferes with OIDC, so if the publish fails with an auth error, that's the first suspect.After merging
v0.35.1(or cut a new patch), and confirm all seven packages show the new version on npm.NPM_TOKENsecret, and consider "Require two-factor authentication and disallow tokens" on each package.🤖 Generated with Claude Code
https://claude.ai/code/session_013mDr1nhgyzST2iPzCzMcCd