Skip to content

ci(release): Publish to npm with trusted publishing - #309

Closed
TheCodeDestroyer wants to merge 1 commit into
mainfrom
ci/npm-trusted-publishing
Closed

TheCodeDestroyer wants to merge 1 commit into
mainfrom
ci/npm-trusted-publishing

Conversation

@TheCodeDestroyer

Copy link
Copy Markdown
Owner

Summary

  • npm classic tokens no longer work, so the release workflow cannot publish with NPM_TOKEN.
  • Move publishing to npm trusted publishing (OIDC). No npm token is needed.

Changes

  • Release workflow: remove NPM_TOKEN. Add the id-token: write permission, plus the contents: write and pull-requests: write permissions that the action needs. Install npm 11 before publishing, because trusted publishing needs npm 11.5.1 or later and pnpm publish runs the npm CLI.
  • package.json URLs: use TheCodeDestroyer in the repository, homepage and bugs URLs. npm compares repository.url with the GitHub OIDC claims and the comparison is case-sensitive.
  • The workflow stays on changesets/action@v1. v1.7 and later support trusted publishing, and v2 needs Changesets CLI v3.

Test plan

  • Set up a trusted publisher on npmjs.com for each package: TheCodeDestroyer / devkit / release.yml.
  • Merge this PR, then merge the next "Version Packages" PR. Check that the publish step works and that the packages on npm show provenance.
  • If publishing fails with ENEEDAUTH, fall back to pnpm pack + npm publish <tarball>.

🤖 Generated with Claude Code

- Remove NPM_TOKEN; npm classic tokens are gone and changesets/action
  v1.7+ publishes through OIDC when no token is set
- Add id-token: write, plus contents and pull-requests write that the
  action needs, as job permissions
- Install npm 11 before publish; trusted publishing needs npm 11.5.1+
  and pnpm publish runs the npm CLI
- Use the exact GitHub owner case (TheCodeDestroyer) in package.json
  repository, homepage and bugs URLs, because npm matches
  repository.url against the OIDC claims case-sensitively

Refs devkit-uur

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
@changeset-bot

changeset-bot Bot commented Sep 22, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 5e1c498

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@TheCodeDestroyer

Copy link
Copy Markdown
Owner Author

Merged into #308.

@TheCodeDestroyer
TheCodeDestroyer deleted the ci/npm-trusted-publishing branch September 22, 2026 20:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant