Skip to content

ci: authenticate the first publish with the token, after all - #14

Merged
github-actions[bot] merged 1 commit into
mainfrom
ci/token-bootstrap
Aug 16, 2026
Merged

ci: authenticate the first publish with the token, after all#14
github-actions[bot] merged 1 commit into
mainfrom
ci/token-bootstrap

Conversation

@catomean

Copy link
Copy Markdown
Collaborator

I removed this env block one PR ago (#13) in favour of trusted publishing. That was the right destination reached in the wrong order: a trusted publisher is configured on a package, and neither package exists yet. With the token wiring gone and OIDC not yet possible, a tag push would have failed to authenticate by either route.

So the bootstrap release authenticates with NPM_TOKEN — now set correctly on this repo. The ordering that actually works:

  1. this PR → tag → CI publishes v0.1.1 using the token
  2. package now exists → configure the trusted publisher against publish.yml
  3. delete this env block again
  4. revoke the token, set Require 2FA and disallow tokens

node-version: '24' stays — required for OIDC in step 2, harmless now.

Provenance is unaffected. id-token: write is what npm needs to attest the build, and that's independent of how the publish authenticates. So this bootstrap release still gets a real attestation, rather than the --provenance=false I'd been proposing for a laptop publish.

🤖 Generated with Claude Code

I removed this env block one PR ago in favour of trusted publishing, and that
was the right destination reached in the wrong order: a trusted publisher is
configured on a PACKAGE, and neither package exists yet. With the token wiring
gone and OIDC not yet possible, a tag push would have failed to authenticate
by either route.

So the bootstrap release authenticates with NPM_TOKEN (now set correctly on
this repo). Once the package exists on the registry, the trusted publisher is
configured against this workflow, this env block goes away again, and the token
is revoked — that ordering actually works.

Node 24 stays: it is required for OIDC later and harmless now.

Provenance is unaffected. `id-token: write` is what npm needs to attest the
build, and that is independent of how the publish authenticates — so the
bootstrap release still gets a real attestation rather than --provenance=false.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@github-actions
github-actions Bot merged commit 1912577 into main Aug 16, 2026
1 check passed
@github-actions
github-actions Bot deleted the ci/token-bootstrap branch August 16, 2026 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant