Skip to content

feat: fix npm OIDC publishing by using @semantic-release/exec - #8

Merged
dogmar merged 5 commits into
mainfrom
ci/trigger-release
Apr 8, 2026
Merged

dogmar merged 5 commits into
mainfrom
ci/trigger-release

Conversation

@dogmar

@dogmar dogmar commented Apr 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

@semantic-release/npm passes --userconfig <empty-temp-file> to npm publish, which overrides npm's normal config resolution and prevents the OIDC token exchange from working with trusted publishing.

Fix:

  • Use @semantic-release/npm only for version bumping (npmPublish: false)
  • Use @semantic-release/exec with publishCmd: "npm publish package" to call npm directly
  • npm then uses its native OIDC flow via the .npmrc created by actions/setup-node
  • Add actions/setup-node with registry-url to configure npm for OIDC

dogmar and others added 5 commits April 8, 2026 15:42
prepublishOnly triggers vp run build which spawns a child process
that loses the OIDC auth token. The build already runs explicitly
in the workflow, so lifecycle scripts are redundant.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@semantic-release/npm verifies OIDC works but doesn't pass
--provenance to npm publish. Setting NPM_CONFIG_PROVENANCE=true
tells npm to handle OIDC auth directly during publish.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
The npm trusted publishing OIDC flow requires the registry URL
to be configured via actions/setup-node. This creates the .npmrc
that enables npm to perform OIDC token exchange during publish.

Per npm docs, no --provenance flag or NPM_TOKEN is needed when
trusted publishing is configured — npm handles auth automatically.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@semantic-release/npm passes --userconfig <empty-temp-file> to
npm publish, overriding npm's normal config resolution and
preventing the OIDC token exchange from working.

Fix: use @semantic-release/npm only for version bumping
(npmPublish: false) and @semantic-release/exec to call
npm publish directly, which uses npm's native OIDC flow
via the .npmrc created by actions/setup-node.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@dogmar
dogmar merged commit 27b342a into main Apr 8, 2026
2 checks passed
@dogmar
dogmar deleted the ci/trigger-release branch April 8, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant