662 . Log in to npm with the BeatAPI publishing account.
773 . Publish or reserve both package names: ` beatapi-client ` and ` beatapi ` .
884 . In GitHub, create an environment named ` npm ` .
9- 5 . Add an environment secret named ` NPM_TOKEN ` with publish access to both
10- packages. Keep required reviewer protection enabled for production releases.
9+ 5 . Add the publishing owner as a required reviewer for the ` npm ` environment
10+ and allow release tags matching ` v* ` .
11+ 6 . On npmjs.com, configure a GitHub Actions Trusted Publisher separately for
12+ ` beatapi-client ` and ` beatapi ` with these exact values:
13+ - organization: ` BeatAPI ` ;
14+ - repository: ` beatapi-cli ` ;
15+ - workflow filename: ` release.yml ` ;
16+ - environment: ` npm ` ;
17+ - allowed action: ` npm publish ` .
18+
19+ The release workflow uses npm Trusted Publishing over OIDC. It intentionally
20+ does not store or reference a long-lived ` NPM_TOKEN ` . GitHub grants the workflow
21+ a short-lived identity for each approved release, and npm automatically records
22+ provenance for public packages published from the public repository.
1123
1224The package names were unregistered when this repository was prepared. npm
1325names are first-come, first-served, so reserve them before announcing the
@@ -30,6 +42,11 @@ release.
304210 . Run ` beatapi --version ` , ` beatapi --help ` , and an authenticated
3143 ` beatapi auth status ` smoke test.
3244
45+ The workflow installs the current npm CLI on Node.js 24 because Trusted
46+ Publishing requires npm 11.5.1 or newer and Node.js 22.14.0 or newer. Do not add
47+ an ` NPM_TOKEN ` fallback: a missing OIDC trust relationship should fail closed
48+ instead of silently using a persistent credential.
49+
3350## Rollback
3451
3552npm package versions are immutable. If a release is defective:
0 commit comments