Skip to content

Use npm trusted publishing in release workflow - #20

Merged
KennethWussmann merged 1 commit into
mainfrom
ci/npm-trusted-publishing
Sep 19, 2026
Merged

KennethWussmann merged 1 commit into
mainfrom
ci/npm-trusted-publishing

Conversation

@KennethWussmann

Copy link
Copy Markdown
Owner

Why

Token-based npm auth requires maintaining a long-lived NPM_TOKEN secret. npm's trusted publishing (OIDC) removes that secret entirely and ties publishes to this repo's workflow via short-lived, provenance-backed credentials.

What

  • Removed registry-url from setup-node; it wrote an .npmrc expecting NODE_AUTH_TOKEN, which is no longer used.
  • Added npm install -g npm@latest; trusted publishing needs npm CLI >= 11.5.1, newer than what Node 24 ships.
  • Dropped --no-git-checks from npm publish (a pnpm flag, ignored by npm).

The id-token: write permission was already present, which OIDC requires.

Follow-up (not in this PR)

  • Configure the package's Trusted Publisher on npmjs.org to point at this repo and the publish workflow.
  • Delete the now-unused npm token secret afterwards.
  • GH_TOKEN is still needed for the tarball upload to the release.

Written by Claude Opus 4.8 via Pi

Co-authored-by: Claude Opus 4.8 via [Pi](https://pi.dev/) <noreply@pi.dev>
@KennethWussmann
KennethWussmann marked this pull request as ready for review September 19, 2026 19:07
@KennethWussmann
KennethWussmann merged commit 23b4077 into main Sep 19, 2026
1 check passed
@KennethWussmann
KennethWussmann deleted the ci/npm-trusted-publishing branch September 19, 2026 19:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant