ci: publish npm package via Trusted Publishing (OIDC) - #5
Merged
Merged
Conversation
Grant id-token: write, upgrade npm to 11 and add --provenance so the ts-publish-npm workflow can authenticate through the npmjs.com Trusted Publisher for this repository. NPM_TOKEN stays only as a transitional fallback; granular tokens expire after 90 days, which broke every npm publish since v0.4.18.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Every npm publish since v0.4.18 failed with
npm error 404 PUT https://registry.npmjs.org/cccc-sdk. npm returns 404 for invalid credentials: theNPM_TOKENsecret (set 2026-02-17) hit the 90-day maximum lifetime for granular tokens on 2026-05-18. v0.4.40 was published today by rotating the token and re-running the job, but that will break again in 90 days, and npm is retiring bypass-2FA tokens for direct publishing in Jan 2027.What
ts-publish-npm.yml: grantid-token: writeand upgrade npm to 11 (Trusted Publishing needs >= 11.5.1; Node 20 ships npm 10). Provenance is generated automatically by npm under Trusted Publishing, so no--provenanceflag.NPM_TOKENstays as a transitional fallback. The npm CLI tries OIDC first and silently falls back to the configured token if the exchange fails, so this PR is safe to merge regardless of npmjs.com state.RELEASING.md: document the Trusted Publisher setup and that the secret should be removed, not rotated, once it works.npmjs.com side (done)
Trusted Publisher for
cccc-sdkis configured: GitHub Actions,ChesterRa/cccc-sdk, workflowts-publish-npm.yml, no environment,npm publishallowed.Follow-up after the next successful tag publish
oidc: Successfully retrieved and set token.gh secret delete NPM_TOKEN --repo ChesterRa/cccc-sdkand drop theNODE_AUTH_TOKENenv lines from the workflow.