Skip to content

Commit 3da8e29

Browse files
CI Botclaude
andcommitted
fix: switch npm publish from NPM_TOKEN to OIDC trusted publishing
Removes the manual NPM_TOKEN auth in release.yml — npm publish now authenticates via GitHub Actions OIDC identity, which is already configured for all four published packages. This eliminates the need to manage and rotate an npm automation token. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
1 parent 58be008 commit 3da8e29

3 files changed

Lines changed: 9 additions & 18 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -291,8 +291,8 @@ jobs:
291291
292292
- name: Publish to npm (workspaces)
293293
run: |
294-
# Authenticate npm
295-
npm config set //registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}
294+
# Auth via OIDC trusted publishing (id-token: write + setup-node registry-url)
295+
# No NPM_TOKEN needed — GitHub Actions identity is verified by npm directly
296296
297297
# Publish packages in dependency order if the target version does NOT yet exist
298298
# --provenance adds signed build attestation (requires id-token: write)
@@ -319,8 +319,6 @@ jobs:
319319
else
320320
npm publish -w @debugmcp/mcp-debugger --access public --provenance --tag ${NPM_TAG}
321321
fi
322-
env:
323-
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
324322
325323
create-release:
326324
name: Create GitHub Release

‎docs/release-checklist.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ Pre-release validation for mcp-debugger. Run `npm run release:dry-run` to automa
55
## Before Tagging
66

77
### Automated (via `npm run release:dry-run`)
8-
- [ ] Package versions match (the dry-run script checks root plus the packages listed in its `PUBLISHED_PKGS`; adapter-go, adapter-java, and adapter-dotnet may not be included in the automated check yet)
8+
- [ ] Package versions match (the dry-run script checks root plus all workspace packages including adapter-dotnet)
99
- [ ] `CHANGELOG.md` has `[x.y.z] - YYYY-MM-DD` entry with date
1010
- [ ] `CHANGELOG.md` has empty `[Unreleased]` section at top
1111
- [ ] `npm run build` succeeds
@@ -16,7 +16,7 @@ Pre-release validation for mcp-debugger. Run `npm run release:dry-run` to automa
1616
- [ ] `release.yml` changelog extraction strips `v` prefix (`refs/tags/v}` not `refs/tags/}`)
1717

1818
### Manual
19-
- [ ] **npm trusted publishing configured** — each `@debugmcp/*` package must have trusted publishing enabled at npmjs.com → package Settings → Configure Trusted Publishing (repo: `debugmcp/mcp-debugger`, workflow: `release.yml`). Note: the release dry-run script still checks for `NPM_TOKEN` as a repository secret.
19+
- [ ] **npm trusted publishing configured** — each published `@debugmcp/*` package must have trusted publishing enabled at npmjs.com → package Settings → Configure Trusted Publishing (repo: `debugmcp/mcp-debugger`, workflow: `release.yml`). npm auth is via OIDC — no `NPM_TOKEN` secret needed.
2020
- [ ] **Docker Hub credentials** — `DOCKER_USERNAME` and `DOCKER_PASSWORD` secrets are current
2121
- [ ] **PyPI token** — `PYPI_TOKEN` secret is current
2222
- [ ] `release.yml` default ref updated to current tag (for workflow_dispatch reruns)

‎scripts/release-dry-run.sh‎

Lines changed: 5 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -102,22 +102,15 @@ for pkg_dir in "${PUBLISHED_PKGS[@]}"; do
102102
fi
103103
done
104104

105-
# --- 6. Check npm token and GitHub secrets ---
105+
# --- 6. Check GitHub secrets (npm uses OIDC trusted publishing, no token needed) ---
106106
echo ""
107-
echo "── npm authentication ──"
108-
109-
# Test local npm login
110-
if npm whoami > /dev/null 2>&1; then
111-
NPM_USER=$(npm whoami)
112-
pass "Local npm login: $NPM_USER"
113-
else
114-
warn "Not logged in to npm locally"
115-
fi
107+
echo "── Publishing credentials ──"
108+
echo " npm: OIDC trusted publishing (no token needed)"
116109

117110
if command -v gh > /dev/null 2>&1; then
118-
# Check secrets exist
111+
# Check secrets exist (npm uses OIDC, only Docker and PyPI need tokens)
119112
SECRETS_LIST=$(gh secret list 2>/dev/null || echo "")
120-
for secret in NPM_TOKEN DOCKER_USERNAME DOCKER_PASSWORD PYPI_TOKEN; do
113+
for secret in DOCKER_USERNAME DOCKER_PASSWORD PYPI_TOKEN; do
121114
if echo "$SECRETS_LIST" | grep -q "^${secret}"; then
122115
pass "GitHub secret $secret exists"
123116
else

0 commit comments

Comments
 (0)