Skip to content

feat: configure npm OIDC trusted publishing for release workflow - #7

Merged
dogmar merged 6 commits into
mainfrom
ci/trigger-release
Apr 8, 2026
Merged

dogmar merged 6 commits into
mainfrom
ci/trigger-release

Conversation

@dogmar

@dogmar dogmar commented Apr 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Add actions/setup-node with registry-url: https://registry.npmjs.org to the release workflow
  • npm's trusted publishing OIDC flow requires the registry URL to be configured in .npmrc, which actions/setup-node handles
  • Without this, @semantic-release/npm verifies OIDC works but npm itself has no registry config to perform the token exchange during publish, causing ENEEDAUTH
  • Per npm docs, no --provenance flag or NPM_TOKEN is needed — npm handles auth and provenance automatically when trusted publishing is configured
  • prepublishOnly lifecycle scripts continue to work normally

dogmar and others added 4 commits April 8, 2026 15:13
Verifies the release pipeline (version calculation, changelog
generation, npm pack) without actually publishing.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Branch protection prevents pushing directly to main. Remove
@semantic-release/changelog and @semantic-release/git — GitHub
Releases are sufficient for changelog.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
prepublishOnly triggers vp run build which spawns a child process
that loses the OIDC auth token. The build already runs explicitly
in the workflow, so lifecycle scripts are redundant.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@semantic-release/npm verifies OIDC works but doesn't pass
--provenance to npm publish. Setting NPM_CONFIG_PROVENANCE=true
tells npm to handle OIDC auth directly during publish.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@dogmar dogmar changed the title fix: skip npm lifecycle scripts during semantic-release publish fix: pass provenance flag to npm via env var for OIDC auth Apr 8, 2026
dogmar and others added 2 commits April 8, 2026 15:32
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The npm trusted publishing OIDC flow requires the registry URL
to be configured via actions/setup-node. This creates the .npmrc
that enables npm to perform OIDC token exchange during publish.

Per npm docs, no --provenance flag or NPM_TOKEN is needed when
trusted publishing is configured — npm handles auth automatically.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@dogmar dogmar changed the title fix: pass provenance flag to npm via env var for OIDC auth feat: configure npm OIDC trusted publishing for release workflow Apr 8, 2026
@dogmar
dogmar merged commit 4905765 into main Apr 8, 2026
4 checks passed
@dogmar
dogmar deleted the ci/trigger-release branch April 8, 2026 22:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant