Skip to content

ci: publish npm package via Trusted Publishing (OIDC) - #5

Merged
waterbang merged 1 commit into
mainfrom
ci/npm-trusted-publishing
Sep 19, 2026
Merged

waterbang merged 1 commit into
mainfrom
ci/npm-trusted-publishing

Conversation

@waterbang

@waterbang waterbang commented Sep 19, 2026 •

Copy link
Copy Markdown
Collaborator

Why

Every npm publish since v0.4.18 failed with npm error 404 PUT https://registry.npmjs.org/cccc-sdk. npm returns 404 for invalid credentials: the NPM_TOKEN secret (set 2026-02-17) hit the 90-day maximum lifetime for granular tokens on 2026-05-18. v0.4.40 was published today by rotating the token and re-running the job, but that will break again in 90 days, and npm is retiring bypass-2FA tokens for direct publishing in Jan 2027.

What

  • ts-publish-npm.yml: grant id-token: write and upgrade npm to 11 (Trusted Publishing needs >= 11.5.1; Node 20 ships npm 10). Provenance is generated automatically by npm under Trusted Publishing, so no --provenance flag.
  • NPM_TOKEN stays as a transitional fallback. The npm CLI tries OIDC first and silently falls back to the configured token if the exchange fails, so this PR is safe to merge regardless of npmjs.com state.
  • RELEASING.md: document the Trusted Publisher setup and that the secret should be removed, not rotated, once it works.

npmjs.com side (done)

Trusted Publisher for cccc-sdk is configured: GitHub Actions, ChesterRa/cccc-sdk, workflow ts-publish-npm.yml, no environment, npm publish allowed.

Follow-up after the next successful tag publish

  1. Confirm the job log shows oidc: Successfully retrieved and set token.
  2. gh secret delete NPM_TOKEN --repo ChesterRa/cccc-sdk and drop the NODE_AUTH_TOKEN env lines from the workflow.
  3. Switch the package's Publishing access to "Require two-factor authentication and disallow bypass 2fa tokens".

Grant id-token: write, upgrade npm to 11 and add --provenance so the
ts-publish-npm workflow can authenticate through the npmjs.com Trusted
Publisher for this repository. NPM_TOKEN stays only as a transitional
fallback; granular tokens expire after 90 days, which broke every npm
publish since v0.4.18.
@waterbang
waterbang marked this pull request as ready for review September 19, 2026 06:26
@waterbang
waterbang merged commit 4cdbd68 into main Sep 19, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant