You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
publish.yml authenticates to npm with a long-lived NPM_TOKEN secret. Two costs:
It expires. The token created 2026-05-20 expired 2026-08-18 and broke the v2.1.0 release (see publish.yml: notify on failure #101). Every replacement token carries the same fuse.
npm is restricting this path. The npm dashboard currently warns: "npm tokens that bypass 2FA are being restricted — account changes (Aug 2026) and direct publishing (Jan 2027)." Our token needs the 2FA-bypass flag set, because CI cannot answer an OTP prompt. That combination is on a deprecation clock.
npm supports Trusted Publishing: GitHub Actions authenticates over OIDC, no stored credential. The workflow is most of the way there already — it has permissions: id-token: write, publishes with --provenance, and uses OIDC for the MCP Registry publish two steps later. The npm step is the odd one out.
Acceptance criteria
stonematt/mcp-obsidian-cli is registered as a trusted publisher for the mcp-obsidian-cli package on npmjs.com, scoped to publish.yml.
The Publish to npm step no longer sets NODE_AUTH_TOKEN.
A real release publishes to npm end to end with no token present.
Provenance attestation still attaches (the current setup signs to sigstore; do not lose that).
The NPM_TOKEN secret is deleted from repo secrets only after a successful tokenless release, not before.
docs/agents/issue-tracker.md release ritual section updated if the steps change.
Notes
Verify the setup against npm's current Trusted Publishing docs before editing the workflow — the feature has moved quickly and details may have shifted.
Sequencing: land #101 first. A failure notification is worth having in place before changing how releases authenticate, so a botched migration announces itself instead of silently dropping another version.
Problem
publish.ymlauthenticates to npm with a long-livedNPM_TOKENsecret. Two costs:npm supports Trusted Publishing: GitHub Actions authenticates over OIDC, no stored credential. The workflow is most of the way there already — it has
permissions: id-token: write, publishes with--provenance, and uses OIDC for the MCP Registry publish two steps later. The npm step is the odd one out.Acceptance criteria
stonematt/mcp-obsidian-cliis registered as a trusted publisher for themcp-obsidian-clipackage on npmjs.com, scoped topublish.yml.Publish to npmstep no longer setsNODE_AUTH_TOKEN.NPM_TOKENsecret is deleted from repo secrets only after a successful tokenless release, not before.docs/agents/issue-tracker.mdrelease ritual section updated if the steps change.Notes
Verify the setup against npm's current Trusted Publishing docs before editing the workflow — the feature has moved quickly and details may have shifted.
Sequencing: land #101 first. A failure notification is worth having in place before changing how releases authenticate, so a botched migration announces itself instead of silently dropping another version.