Skip to content

ci: token-less npm releases via Trusted Publishing (OIDC) - #25

Merged
cescox merged 1 commit into
mainfrom
ci/oidc-trusted-publishing
Jun 15, 2026
Merged

cescox merged 1 commit into
mainfrom
ci/oidc-trusted-publishing

Conversation

@cescox

@cescox cescox commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

What

Switch the canup release workflow from an NPM_TOKEN secret to token-less publishing via npm Trusted Publishing (OIDC), with provenance. No long-lived npm token lives in this repo anymore.

Changes

  • .github/workflows/release.yml
    • Remove NPM_TOKEN from the publish env.
    • Remove registry-url from setup-node — it writes an .npmrc with _authToken=${NODE_AUTH_TOKEN} that npm prefers over the OIDC exchange (a documented cause of E404 on publish).
    • Add npm install -g npm@latest — Trusted Publishing needs npm ≥ 11.5.1, and pnpm delegates the publish (and the OIDC token exchange) to the npm CLI; GitHub runners ship an older npm. This is the most common silent-failure cause.
    • Enable provenance via NPM_CONFIG_PROVENANCE: true — available because this is a public repository.
  • RELEASING.md — how releases work + one-time maintainer setup.

The Changesets flow is unchanged: PRs carry changesets → a "Version Packages" PR is opened → merging it publishes.

Required one-time setup (maintainer, on npmjs.com)

Trusted Publishing requires the package to exist before a publisher can be attached, so:

  1. Publish canup once manually: pnpm install && pnpm build && npm publish --access public (completes 2FA).
  2. Add the trusted publisher at https://www.npmjs.com/package/canup/access → Trusted Publisher → GitHub Actions:
    • Organization or user: sparkncraft
    • Repository: canup
    • Workflow filename: release.yml (filename only, not a path)
    • Environment: (leave blank)
  3. After OIDC publishing is confirmed, the NPM_TOKEN repo secret can be deleted.

Scope

Touches only release CI + docs. lint / typecheck / test / build were run locally and pass; nothing in the package output changes.

Replace the NPM_TOKEN-based release with token-less publishing through
GitHub OIDC. Remove the setup-node registry-url (it writes an _authToken
.npmrc that npm prefers over the OIDC exchange), install npm>=11.5.1
(pnpm delegates the publish to the npm CLI, which performs the exchange),
and enable provenance. Add RELEASING.md.
@github-actions

Copy link
Copy Markdown

size-limit report 📦

Path Size
UI entry (full import) 33.12 KB (0%)

@github-actions

Copy link
Copy Markdown

Coverage Report

Status Category Percentage Covered / Total
🔵 Lines 99.13% (🎯 95%) 1267 / 1278
🔵 Statements 99.02% (🎯 95%) 1326 / 1339
🔵 Functions 97.89% (🎯 95%) 232 / 237
🔵 Branches 94.87% (🎯 85%) 555 / 585
File CoverageNo changed files found.
Generated in workflow #34 for commit 4ee4afe by the Vitest Coverage Report Action

@cescox
cescox merged commit c44fa36 into main Jun 15, 2026
9 checks passed
@cescox
cescox deleted the ci/oidc-trusted-publishing branch June 15, 2026 04:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant