Skip to content

ci(release): switch to npm OIDC trusted publishing - #3

Merged
hunterbecton merged 1 commit into
mainfrom
ci/npm-oidc
Apr 30, 2026
Merged

hunterbecton merged 1 commit into
mainfrom
ci/npm-oidc

Conversation

@hunterbecton

Copy link
Copy Markdown
Member

What/Why?

Replace the NPM_TOKEN secret with OIDC trusted publishing, since npm is already configured with GitHub Actions as a trusted publisher.

Changes:

  • Add actions/setup-node with registry-url to configure the npm auth flow
  • Set NPM_CONFIG_PROVENANCE: true so published packages get provenance attestation
  • Remove the NODE_AUTH_TOKEN / NPM_TOKEN reference — OIDC handles auth via the id-token: write permission

Testing

No functional change until a changeset is merged. The release workflow will be exercised on the first version bump.

Replace NPM_TOKEN secret with npm provenance via GitHub OIDC. This uses
the trusted publisher configured in npm instead of a long-lived token.
@hunterbecton
hunterbecton merged commit efa604c into main Apr 30, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant