Skip to content

Publish to npm with trusted publishing (OIDC) instead of NPM_TOKEN - #268

Merged
nbudin merged 1 commit into
mainfrom
npm-trusted-publishing
Oct 5, 2026
Merged

nbudin merged 1 commit into
mainfrom
npm-trusted-publishing

Conversation

@nbudin

@nbudin nbudin commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

What

Switches the release workflow from the NPM_TOKEN secret to npm trusted publishing (OIDC).

The NPM_TOKEN secret (last updated 2025-02-23) no longer works: the v0.35.1 publish failed with E404 Not Found - PUT .../litform-core, which is how npm reports a rejected token. All seven packages now have this workflow (release.yml) configured as a trusted publisher on npmjs.com.

Changes

  • Install npm ^11.5.1 before publishing. Trusted publishing needs npm 11.5.1+, and the npm bundled with Node 22.14 (.node-version) is 10.9.x.
  • Remove NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} from the publish step.

Unchanged: id-token: write was already granted, and --provenance stays (provenance is also automatic for public repos).

Verifying

This can only really be tested by publishing. One thing to watch on the first run: actions/setup-node with registry-url writes an .npmrc that expects NODE_AUTH_TOKEN; npm's docs don't say whether that interferes with OIDC, so if the publish fails with an auth error, that's the first suspect.

After merging

  • Re-publish v0.35.1 (or cut a new patch), and confirm all seven packages show the new version on npm.
  • Delete the NPM_TOKEN secret, and consider "Require two-factor authentication and disallow tokens" on each package.

🤖 Generated with Claude Code

https://claude.ai/code/session_013mDr1nhgyzST2iPzCzMcCd

The NPM_TOKEN secret has stopped working (the v0.35.1 publish got E404 on PUT).
Each package is now configured on npmjs.com with this workflow as a trusted
publisher, so drop the token. Trusted publishing needs npm 11.5.1 or later, and
the npm bundled with Node 22.14 is older, so install a newer one first.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013mDr1nhgyzST2iPzCzMcCd
@nbudin nbudin added the patch label Oct 5, 2026
@nbudin
nbudin merged commit b45014e into main Oct 5, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant