@canup/ui and @canup/cli publish to npm via
npm Trusted Publishing (OIDC).
No npm token is involved — GitHub Actions authenticates with a short-lived
OIDC credential, and packages publish with
provenance.
The two packages version in lockstep: bump them to the same version and release them together.
- On a branch, bump the
versionin bothpackages/ui/package.jsonandpackages/cli/package.jsonto the new version and update each package'sCHANGELOG.md. Merge tomain. - Run the Release workflow from the Actions tab (
workflow_dispatch). It builds, tests, and publishes — with provenance, no token. (pnpm skips any package whose version is already on npm, so a re-run without a bump is a no-op.)
npm Trusted Publishing can't bootstrap a package name that doesn't exist yet, so the first publish of each package is manual and requires your npm 2FA:
pnpm install --frozen-lockfile
pnpm build
pnpm --filter @canup/ui publish --access public
pnpm --filter @canup/cli publish --access publicThen configure the trusted publisher for each package at
https://www.npmjs.com/package/<name>/access → Trusted Publisher →
GitHub Actions:
| Field | Value |
|---|---|
| Organization or user | sparkncraft |
| Repository | canup |
| Workflow filename | release.yml (filename only, not a path) |
| Environment | (leave blank) |
After that, the release.yml workflow publishes on its own — no token needed.
- npm ≥ 11.5.1 and Node ≥ 22 — the workflow installs
npm@latestbecause runners ship an older npm and pnpm delegates the publish to the npm CLI. id-token: writepermission on the release job.