ci: trusted publishing, and build before linting - #30
Merged
Merged
Conversation
npm mints a short lived publish token from the workflow's OIDC identity, so NPM_TOKEN is gone, and the github api calls use GITHUB_TOKEN instead of the bot PAT. Both expired in August and took the eslint-config release down with them. Trusted publishing needs npm 11.5.1 or newer, which needs a modern node, so .nvmrc moves from v18.18.0 to v24.13.0. engines is untouched. pull-requests: write sits alongside issues: write because this package's own GithubCreateIssueCommentsCommand comments on whatever the released commits reference, and a bare '#12' resolves to a pull request as readily as an issue. Without the permission the whole release throws and rolls back, which is what happened on eslint-config 3.0.1. provenance is set in publishConfig because NpmPublishPackageCommand builds the publish args itself and has no --provenance option. Requires a trusted publisher connection for @abstracter/atomic-release on npmjs.com (abstracter-io / atomic-release / build-and-release.yml, with 'Allow npm publish' ticked) before the next release.
scripts/release.js imports this package by name, and that self reference resolves through the exports field into build/, which does not exist until the build runs. Linting first fails with scripts/release.js:1:21 Package path . is exported from package ... but no valid target file was found n/no-missing-import Every run of this workflow since at least September 2025 has been red for this reason, including the four dependabot pull requests still open.
This was referenced Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Last of the four repos to get the treatment eslint-config got, where it replaced
the credentials that expired in August. This one is deliberately last: it is the
tool every other repo releases with.
The workflow was already red
Every run of Build & Release since at least September 2025 has failed, including
the four open dependabot PRs:
scripts/release.jsimports this package by name, and that self referenceresolves through
exportsintobuild/, which does not exist until the buildruns. Lint ran first. Moving Build ahead of Lint Code fixes it — the same
ordering fix web-app made for the same reason. This branch is the first green run
of this workflow in a year.
Trusted publishing
NPM_TOKENis gone; npm mints a short lived publish token from the workflow'sOIDC identity. GitHub API calls use
GITHUB_TOKENinstead of the bot PAT, andcheckout no longer takes a token.
.nvmrcv18.18.0 -> v24.13.0, because trusted publishing needs npm 11.5.1+.enginesis untouched.provenance: trueinpublishConfig, sinceNpmPublishPackageCommandbuildsthe publish args itself and has no
--provenanceoption.pull-requests: writealongsideissues: write. This package's ownGithubCreateIssueCommentsCommandcomments on whatever the released commitsreference, and a bare
#12resolves to a pull request as readily as an issue.Without the permission the command throws and the entire release rolls back —
that is what happened on eslint-config 3.0.1.
workflow_dispatch, so a release can be started deliberately.open dependabot PRs.
Before the next release
A trusted publisher connection for
@abstracter/atomic-releaseon npmjs.com:package Settings -> Trusted publishing,
abstracter-io/atomic-release/build-and-release.yml, with Allow npm publish ticked.Worth fixing here later
Two rough edges this migration surfaced in the library itself:
GithubHttpCommandlogsX-Accepted-GitHub-PermissionsasGitHub Missing Permissions: ...on any non-ok response. That header listswhat the endpoint accepts, not what the caller lacks, so a plain 404 prints a
misleading warning.
release that had already tagged and published nothing wrong. Referencing
another repo's issue as
owner/repo#Nis enough to trigger it.