From faf3b8ebf772a07599079b2d07441ea29c0da92a Mon Sep 17 00:00:00 2001 From: Andrew Poe Date: Fri, 4 Sep 2026 16:31:16 -0400 Subject: [PATCH] ci: publish via npm Trusted Publishing instead of NIO_NPM_TOKEN publish.yaml already ran on releases; it now authenticates with OIDC instead of JS-DevTools/npm-publish and the dead org token, takes a tag for manual re-runs, and fires on any published release. build.yaml drops an env block referencing a secret that does not exist. CONTXT-22349. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/build.yaml | 3 --- .github/workflows/publish.yaml | 39 +++++++++++++++++++++++++--------- 2 files changed, 29 insertions(+), 13 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index b924379..8887aaf 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -6,9 +6,6 @@ on: pull_request: branches: [main] -env: - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} - jobs: build: runs-on: ubuntu-latest diff --git a/.github/workflows/publish.yaml b/.github/workflows/publish.yaml index e08142e..e80c5be 100644 --- a/.github/workflows/publish.yaml +++ b/.github/workflows/publish.yaml @@ -1,24 +1,43 @@ +# Publishes a tagged release to npm via Trusted Publishing (OIDC): no npm token. +# npm trusts this exact workflow file for the package (CONTXT-22345). +# +# Runs when the release workflow creates a GitHub release. Re-run a failed +# publish from the Actions tab (workflow_dispatch) with the release tag. name: Publish on: - workflow_dispatch: release: - types: [released] + types: [published] + workflow_dispatch: + inputs: + tag: + description: Release tag to publish (e.g. v1.2.3) + required: true + type: string -env: - NPM_TOKEN: ${{ secrets.NIO_NPM_TOKEN }} +permissions: + contents: read + id-token: write jobs: publish: runs-on: ubuntu-latest + # Matches the trusted publisher's environment on npm. Protection rules + # (tag-only deploys, reviewers) go on this environment in repo settings. + environment: npm steps: - - uses: actions/checkout@v3 - - uses: actions/setup-node@v3 + - uses: actions/checkout@v4 + with: + ref: ${{ github.event.release.tag_name || inputs.tag }} + - uses: actions/setup-node@v4 with: node-version-file: .nvmrc cache: npm - - run: npm install + registry-url: https://registry.npmjs.org + # npm >= 11.5.1 does OIDC; npm 12 needs a newer Node than .nvmrc pins. + - name: Use an npm that supports trusted publishing + run: npm install -g npm@11 && npm --version + - run: npm ci - run: npm run build - - uses: JS-DevTools/npm-publish@v1 - with: - token: ${{ env.NPM_TOKEN }} + - name: Publish + run: npm publish