Skip to content

docs(release): a trusted publisher is a release-day step, npm expires unvalidated configs after 48 h - #888

Merged
debugmcpdev merged 1 commit into
mainfrom
docs/trusted-publisher-48h-window
Oct 9, 2026
Merged

debugmcpdev merged 1 commit into
mainfrom
docs/trusted-publisher-48h-window

Conversation

@debugmcpdev

Copy link
Copy Markdown
Collaborator

Why

npm now expires a newly created trusted publisher 48 hours after creation unless a publish validates it (changelog 2026-10-02, docs). An expired entry stays listed but cannot authorize or be edited; the only fix is delete and recreate. release.yml cannot validate one by itself: the CLI version comes from the tag ref and every package publishes by its package.json version, so there is no one-package dispatch and only a real tag counts.

Hit on @debugmcp/adapter-dart (#790): its first version was published by hand today, the trusted publisher was created right after, and npmjs.com answered "Publish once before Oct 11, 2026, 8:35 PM UTC to validate this configuration". Decision: let it lapse and recreate it on release day; #887 tracks that.

What changed

  • docs/release-checklist.md
    • npm trusted publishing configured: states the 48-hour rule and that a configuration is created within 48 hours before the tag, never weeks ahead.
    • First-time packages: the hand publish can happen any time, the trusted publisher cannot; why release.yml has no one-package path.
    • First-publish follow-up (post-release): was "configure trusted publishers now", which would create an entry nothing validates for weeks. Now a verification: npm view @debugmcp/<pkg>@x.y.z _npmUser shows GitHub Actions (trustedPublisher).
  • .github/workflows/release.yml: the comment above the publish steps carries the same rule next to the first-publish rule it already had. Comment only.

Checks

  • node scripts/check-docs.mjs: clean.
  • No changelog fragment: docs/ and .github/ are outside the gate's user-visible roots, and nothing shipped changes.

Related: #886 (the dry-run cannot see a never-published package, nor trusted-publisher state), #887 (release-day step for adapter-dart).

🤖 Generated with Claude Code

https://claude.ai/code/session_01Mk4YHZHY5rw5cUsQG1tVxB

… unvalidated configs after 48 h

Since 2026-10-02 npm expires a newly created trusted publisher 48 hours
after creation unless a publish validates it; an expired entry stays
listed but cannot authorize or be edited, and only a delete-and-recreate
gives a fresh window. release.yml cannot validate one on its own: the CLI
version comes from the tag ref and every package publishes by its
package.json version, so only a real tag does.

The checklist said to configure the trusted publisher right after a new
package's first hand publish, and to configure publishers as a post-release
follow-up. Both now say the opposite: create the configuration within 48
hours before the tag push, and after the run confirm it validated
(_npmUser shows GitHub Actions (trustedPublisher)). The comment above the
publish step in release.yml says the same, next to the first-publish rule
it already carries.

Found on @debugmcp/adapter-dart (#790): its first version was published by
hand, its trusted publisher was created the same evening, and #887 tracks
recreating it on release day.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Mk4YHZHY5rw5cUsQG1tVxB
@codecov

codecov Bot commented Oct 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@debugmcpdev
debugmcpdev merged commit 8b43c38 into main Oct 9, 2026
19 of 24 checks passed
@debugmcpdev
debugmcpdev deleted the docs/trusted-publisher-48h-window branch October 9, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants