Skip to content

ci(release): publish every npm package through trusted publishing; drop NPM_TOKEN - #837

Merged
debugmcpdev merged 1 commit into
mainfrom
ci/npm-oidc-only
Sep 30, 2026
Merged

debugmcpdev merged 1 commit into
mainfrom
ci/npm-oidc-only

Conversation

@debugmcpdev

Copy link
Copy Markdown
Collaborator

Summary

Every @debugmcp npm package now publishes through trusted publishing (OIDC), and the release workflow no longer reads NPM_TOKEN.

Why it's safe

  • The nine repo-versioned packages already use OIDC. npm records every 0.25.0 version as published by GitHub Actions with a trustedPublisher id. That includes adapter-javascript, -go, -java and -dotnet, which the workflow sent through its token step: npm 12 prefers a matching trusted publisher over an .npmrc token.
  • The five codelldb-<platform> packages were first-published by token in the v0.25.0-beta.1 run. The maintainer has since configured their trusted publishers. They are versioned by the CodeLLDB pin and skipped at an unchanged pin, so their OIDC path first runs at the next CodeLLDB bump. The skip guard is unchanged, and a misconfiguration would fail that step before anything else publishes.

Changes

  • release.yml: the three npm steps (CodeLLDB by token, existing by OIDC, new by token) become two token-free steps.
    • The CodeLLDB loop keeps its E404-vs-transient guard.
    • The other nine share a publish_if_missing helper, in dependency order with shared first and the CLI last.
    • No NODE_AUTH_TOKEN and no .npmrc remain.
  • validate-secrets.yml drops the npm job, and release-dry-run.sh stops requiring NPM_TOKEN. Docker Hub is the only stored credential left.
  • Docs:
    • The release checklist says how a brand-new package gets its first version. npm can't create a package through OIDC or staging (Allow publishing initial version with OIDC npm/cli#8544), so it takes one publish by hand with 2FA, or a short-lived token in a one-off workflow; then its trusted publisher.
    • SUPPLY-CHAIN-SECURITY.md and the assurance case say CI holds no npm or PyPI token.
    • The assurance case and docs/rust-adapter-performance.md drop claims v0.25.0 made stale: Docker and PyPI unattested, codelldb packages unpublished.

After merge

Once the next release has published through this path, delete the NPM_TOKEN and PYPI_TOKEN repository secrets. PyPI has used trusted publishing since #422.

Test plan

  • release.yml and validate-secrets.yml parse; bash -n scripts/release-dry-run.sh
  • codelldb-platform-packages.test.ts (which pins release.yml's five-platform lists): 10 passed
  • check-docs clean; no NPM_TOKEN reference left outside docs/archive/
  • CI
  • Next release tag: the nine packages publish with no token in the job

🤖 Generated with Claude Code

https://claude.ai/code/session_01Ng3BuLvrQYMyMp3nqaU9US

…op NPM_TOKEN

All 14 @debugmcp packages now have trusted publishers. The nine
repo-versioned packages already published through OIDC at v0.25.0, even
the four sent through the token step: npm prefers a matching trusted
publisher over an .npmrc token. The maintainer has now configured the
five codelldb-<platform> packages too, so the token has no remaining job.

- release.yml: the three npm steps become two token-free steps. The
  CodeLLDB loop keeps its E404-vs-transient guard; the other nine share
  one publish_if_missing helper in dependency order. No NODE_AUTH_TOKEN,
  no .npmrc.
- validate-secrets.yml drops the npm job, and release-dry-run.sh stops
  requiring NPM_TOKEN; Docker Hub is the only stored credential left.
- The release checklist, SUPPLY-CHAIN-SECURITY.md and the assurance case
  say how a brand-new package gets its first version (npm cannot create
  a package through OIDC or staging, npm/cli#8544). The assurance case
  and the Rust performance doc drop claims that v0.25.0 made stale:
  Docker/PyPI unattested, codelldb packages unpublished.

After the next release proves the path, the NPM_TOKEN and PYPI_TOKEN
secrets can be deleted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ng3BuLvrQYMyMp3nqaU9US
@debugmcpdev
debugmcpdev merged commit 06cc2b1 into main Sep 30, 2026
9 checks passed
@debugmcpdev
debugmcpdev deleted the ci/npm-oidc-only branch September 30, 2026 18:08
@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@debugmcpdev debugmcpdev mentioned this pull request Sep 30, 2026
3 of 4 tasks
debugmcpdev added a commit that referenced this pull request Sep 30, 2026
Patch release carrying:
- the official MCP Registry listing (#836): the CLI package declares
  mcpName and the Docker image carries the registry label, the markers the
  registry checks before listing a version; the new mcp-registry-publish
  job lists io.github.debugmcp/mcp-debugger after npm and Docker publish
- token-free npm publishing for every package (#837)
- the ROADMAP update (#834)

Versions: root + 13 workspace packages and server.json to 0.25.1 (the
codelldb packages stay at the 1.11.8 pin and are skipped); launcher
pyproject to 0.25.1; release.yml dispatch default to refs/tags/v0.25.1.


Claude-Session: https://claude.ai/code/session_01Ng3BuLvrQYMyMp3nqaU9US

Co-authored-by: JF <john.franklin@gmail.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants