Repository navigation
docs(release): a trusted publisher is a release-day step, npm expires unvalidated configs after 48 h - #888
Merged
Conversation
… unvalidated configs after 48 h Since 2026-10-02 npm expires a newly created trusted publisher 48 hours after creation unless a publish validates it; an expired entry stays listed but cannot authorize or be edited, and only a delete-and-recreate gives a fresh window. release.yml cannot validate one on its own: the CLI version comes from the tag ref and every package publishes by its package.json version, so only a real tag does. The checklist said to configure the trusted publisher right after a new package's first hand publish, and to configure publishers as a post-release follow-up. Both now say the opposite: create the configuration within 48 hours before the tag push, and after the run confirm it validated (_npmUser shows GitHub Actions (trustedPublisher)). The comment above the publish step in release.yml says the same, next to the first-publish rule it already carries. Found on @debugmcp/adapter-dart (#790): its first version was published by hand, its trusted publisher was created the same evening, and #887 tracks recreating it on release day. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Mk4YHZHY5rw5cUsQG1tVxB
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
npm now expires a newly created trusted publisher 48 hours after creation unless a publish validates it (changelog 2026-10-02, docs). An expired entry stays listed but cannot authorize or be edited; the only fix is delete and recreate.
release.ymlcannot validate one by itself: the CLI version comes from the tag ref and every package publishes by itspackage.jsonversion, so there is no one-package dispatch and only a real tag counts.Hit on
@debugmcp/adapter-dart(#790): its first version was published by hand today, the trusted publisher was created right after, and npmjs.com answered "Publish once before Oct 11, 2026, 8:35 PM UTC to validate this configuration". Decision: let it lapse and recreate it on release day; #887 tracks that.What changed
docs/release-checklist.mdrelease.ymlhas no one-package path.npm view @debugmcp/<pkg>@x.y.z _npmUsershowsGitHub Actions (trustedPublisher)..github/workflows/release.yml: the comment above the publish steps carries the same rule next to the first-publish rule it already had. Comment only.Checks
node scripts/check-docs.mjs: clean.docs/and.github/are outside the gate's user-visible roots, and nothing shipped changes.Related: #886 (the dry-run cannot see a never-published package, nor trusted-publisher state), #887 (release-day step for adapter-dart).
🤖 Generated with Claude Code
https://claude.ai/code/session_01Mk4YHZHY5rw5cUsQG1tVxB