Skip to content

fix(ci): clear npm auth so OIDC trusted publishing works - #378

Merged
theogravity merged 1 commit into
masterfrom
fix/oidc-auth-fix
May 12, 2026
Merged

theogravity merged 1 commit into
masterfrom
fix/oidc-auth-fix

Conversation

@theogravity

Copy link
Copy Markdown
Collaborator

Summary

Fixes the E404 on @loglayer/[email protected] publish.

Root cause

setup-node with registry-url creates ~/.npmrc and sets NODE_AUTH_TOKEN with a GitHub Packages token. npm uses that auth instead of OIDC, causing E404 on registry.npmjs.org.

Even with NPM_TOKEN: (PR #375), the GitHub token in .npmrc takes precedence over OIDC.

Fix

  • Remove registry-url from setup-node so it no longer configures npm auth
  • Add step to upgrade npm and delete ~/.npmrc before changesets runs
  • Set `NODE_AUTH_TOKEN: '' in changesets step so it's not inherited by the publish command

References

Root cause: setup-node creates ~/.npmrc and sets NODE_AUTH_TOKEN with
a GitHub Packages token. npm uses that auth instead of OIDC, causing
E404 on registry.npmjs.org.

Fix:
- Remove registry-url from setup-node (no longer configures npm auth)
- Add step to upgrade npm and delete ~/.npmrc before changesets runs
- Set NODE_AUTH_TOKEN: '' in changesets step so it's not inherited
@theogravity
theogravity merged commit 65e4eb4 into master May 12, 2026
@theogravity
theogravity deleted the fix/oidc-auth-fix branch May 12, 2026 08:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant