Repository navigation
ci(release): publish every npm package through trusted publishing; drop NPM_TOKEN - #837
Merged
Merged
Conversation
…op NPM_TOKEN All 14 @debugmcp packages now have trusted publishers. The nine repo-versioned packages already published through OIDC at v0.25.0, even the four sent through the token step: npm prefers a matching trusted publisher over an .npmrc token. The maintainer has now configured the five codelldb-<platform> packages too, so the token has no remaining job. - release.yml: the three npm steps become two token-free steps. The CodeLLDB loop keeps its E404-vs-transient guard; the other nine share one publish_if_missing helper in dependency order. No NODE_AUTH_TOKEN, no .npmrc. - validate-secrets.yml drops the npm job, and release-dry-run.sh stops requiring NPM_TOKEN; Docker Hub is the only stored credential left. - The release checklist, SUPPLY-CHAIN-SECURITY.md and the assurance case say how a brand-new package gets its first version (npm cannot create a package through OIDC or staging, npm/cli#8544). The assurance case and the Rust performance doc drop claims that v0.25.0 made stale: Docker/PyPI unattested, codelldb packages unpublished. After the next release proves the path, the NPM_TOKEN and PYPI_TOKEN secrets can be deleted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ng3BuLvrQYMyMp3nqaU9US
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
3 of 4 tasks
debugmcpdev
added a commit
that referenced
this pull request
Sep 30, 2026
Patch release carrying: - the official MCP Registry listing (#836): the CLI package declares mcpName and the Docker image carries the registry label, the markers the registry checks before listing a version; the new mcp-registry-publish job lists io.github.debugmcp/mcp-debugger after npm and Docker publish - token-free npm publishing for every package (#837) - the ROADMAP update (#834) Versions: root + 13 workspace packages and server.json to 0.25.1 (the codelldb packages stay at the 1.11.8 pin and are skipped); launcher pyproject to 0.25.1; release.yml dispatch default to refs/tags/v0.25.1. Claude-Session: https://claude.ai/code/session_01Ng3BuLvrQYMyMp3nqaU9US Co-authored-by: JF <john.franklin@gmail.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every
@debugmcpnpm package now publishes through trusted publishing (OIDC), and the release workflow no longer readsNPM_TOKEN.Why it's safe
GitHub Actionswith atrustedPublisherid. That includesadapter-javascript,-go,-javaand-dotnet, which the workflow sent through its token step: npm 12 prefers a matching trusted publisher over an.npmrctoken.codelldb-<platform>packages were first-published by token in the v0.25.0-beta.1 run. The maintainer has since configured their trusted publishers. They are versioned by the CodeLLDB pin and skipped at an unchanged pin, so their OIDC path first runs at the next CodeLLDB bump. The skip guard is unchanged, and a misconfiguration would fail that step before anything else publishes.Changes
release.yml: the three npm steps (CodeLLDB by token, existing by OIDC, new by token) become two token-free steps.publish_if_missinghelper, in dependency order withsharedfirst and the CLI last.NODE_AUTH_TOKENand no.npmrcremain.validate-secrets.ymldrops the npm job, andrelease-dry-run.shstops requiringNPM_TOKEN. Docker Hub is the only stored credential left.SUPPLY-CHAIN-SECURITY.mdand the assurance case say CI holds no npm or PyPI token.docs/rust-adapter-performance.mddrop claims v0.25.0 made stale: Docker and PyPI unattested, codelldb packages unpublished.After merge
Once the next release has published through this path, delete the
NPM_TOKENandPYPI_TOKENrepository secrets. PyPI has used trusted publishing since #422.Test plan
release.ymlandvalidate-secrets.ymlparse;bash -n scripts/release-dry-run.shcodelldb-platform-packages.test.ts(which pins release.yml's five-platform lists): 10 passedcheck-docsclean; noNPM_TOKENreference left outsidedocs/archive/🤖 Generated with Claude Code
https://claude.ai/code/session_01Ng3BuLvrQYMyMp3nqaU9US