Skip to content

Migrate npm publish to Trusted Publishing (OIDC), drop NPM_TOKEN #102

Description

@stonematt

Problem

publish.yml authenticates to npm with a long-lived NPM_TOKEN secret. Two costs:

  1. It expires. The token created 2026-05-20 expired 2026-08-18 and broke the v2.1.0 release (see publish.yml: notify on failure #101). Every replacement token carries the same fuse.
  2. npm is restricting this path. The npm dashboard currently warns: "npm tokens that bypass 2FA are being restricted — account changes (Aug 2026) and direct publishing (Jan 2027)." Our token needs the 2FA-bypass flag set, because CI cannot answer an OTP prompt. That combination is on a deprecation clock.

npm supports Trusted Publishing: GitHub Actions authenticates over OIDC, no stored credential. The workflow is most of the way there already — it has permissions: id-token: write, publishes with --provenance, and uses OIDC for the MCP Registry publish two steps later. The npm step is the odd one out.

Acceptance criteria

  • stonematt/mcp-obsidian-cli is registered as a trusted publisher for the mcp-obsidian-cli package on npmjs.com, scoped to publish.yml.
  • The Publish to npm step no longer sets NODE_AUTH_TOKEN.
  • A real release publishes to npm end to end with no token present.
  • Provenance attestation still attaches (the current setup signs to sigstore; do not lose that).
  • The NPM_TOKEN secret is deleted from repo secrets only after a successful tokenless release, not before.
  • docs/agents/issue-tracker.md release ritual section updated if the steps change.

Notes

Verify the setup against npm's current Trusted Publishing docs before editing the workflow — the feature has moved quickly and details may have shifted.

Sequencing: land #101 first. A failure notification is worth having in place before changing how releases authenticate, so a botched migration announces itself instead of silently dropping another version.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions