Skip to content

ci: migrate to npm trusted publishing (OIDC) - #374

Merged
theogravity merged 2 commits into
masterfrom
feat/trusted-publishing
May 12, 2026
Merged

theogravity merged 2 commits into
masterfrom
feat/trusted-publishing

Conversation

@theogravity

@theogravity theogravity commented May 12, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Migrate from NPM_TOKEN secret-based publishing to npm trusted publishing via OIDC.

Changes

  • Remove NPM_TOKEN env var — npm CLI now authenticates automatically via GitHub Actions OIDC
  • Add id-token: write permission (required for OIDC token exchange)
  • Bump Node from 20 → 22 (npm trusted publishing requires Node ≥22.14.0 and npm ≥11.5.1)
  • Set registry-url in setup-node step
  • Disable package-manager-cache for release builds
  • Remove deprecated permissions (actions, checks, deployments, statuses)

Post-merge

Remove the NPM_TOKEN secret from repo Settings → Secrets → Actions (no longer needed)

- Remove NPM_TOKEN, use id-token: write for OIDC auth
- Bump Node from 20 to 22 (required for npm >=11.5.1)
- Set registry-url in setup-node step
- Disable cache for release builds
- Remove deprecated permissions (actions, checks, deployments, statuses)
- Add publish access configuration script for restricting token access
@theogravity
theogravity merged commit 92c179f into master May 12, 2026
@theogravity
theogravity deleted the feat/trusted-publishing branch May 12, 2026 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant