Skip to content

ci(release): publish to npm with trusted publishing (OIDC) - #130

Merged
justin-carper merged 1 commit into
mainfrom
ci/release-oidc
Sep 29, 2026
Merged

justin-carper merged 1 commit into
mainfrom
ci/release-oidc

Conversation

@justin-carper

Copy link
Copy Markdown
Collaborator

The v0.10.0-next.0 release run failed at npm publish with E404 on the PUT, after every gate (typecheck, tests, build, integration smoke) had passed. The runner had npm 10.9.8, which has no OIDC support.

Change

  • release.yml: node-version 22.x -> 24.x (latest 24.x is v24.21.0, bundling npm 11.19.0; OIDC needs npm >= 11.5.1).
  • release.yml: remove NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} from the publish step. id-token: write, --provenance, the idempotent already-published skip and the tag/version gate are unchanged.
  • CONTRIBUTING.md: document trusted publishing, drop the NPM_TOKEN row.

Depends on a trusted publisher on npmjs.com for stablekernel/opencode-cursor, workflow release.yml, allowing npm publish (set up per the maintainer). I can't see that setting; the first publish after this merges is what proves it.

Not changed: cache: npm in setup-node (npm's docs advise against caching in release builds). Low risk here because PR caches cannot reach tag-ref runs and npm ci verifies lockfile hashes; left alone to keep this diff to the publish fix.

The v0.10.0-next.0 release failed at `npm publish` with E404 on the PUT.
The runner had npm 10.9.8, which has no OIDC support, and the NPM_TOKEN
secret is no longer the publishing path.

Use Node 24.x (bundles npm >= 11.5.1), drop NODE_AUTH_TOKEN from the
publish step so npm authenticates through the trusted publisher configured
for this repo and release.yml, and update CONTRIBUTING accordingly.
@justin-carper
justin-carper merged commit c7cebb5 into main Sep 29, 2026
8 checks passed
@justin-carper
justin-carper deleted the ci/release-oidc branch September 29, 2026 16:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant