From 517c4d39262ec7557e54ffb140eb625a41f1cd18 Mon Sep 17 00:00:00 2001 From: Mao Nakamoto Date: Sun, 16 Aug 2026 16:46:06 +0200 Subject: [PATCH] =?UTF-8?q?ci:=20OIDC=20cannot=20do=20the=20first=20publis?= =?UTF-8?q?h=20=E2=80=94=20keep=20a=20token=20for=20it?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Same fix as ai-forms, before hitting the same failure. Trusted publishing is configured per package on npmjs.com and cannot be configured for a package that has never been published, so the token-free workflow fails on the first release with E404 on the PUT. Co-Authored-By: Claude Opus 5 --- .github/workflows/publish.yml | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index c63e70c..9628dda 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -38,7 +38,17 @@ jobs: exit 1 fi - # No token: id-token above lets the CLI exchange a short-lived OIDC - # credential with npm. Provenance is generated automatically for a public - # package from a public repo, so --provenance is not needed either. + # OIDC (id-token above) is the preferred credential and needs no secret. + # But trusted publishing is configured per package on npmjs.com, and a + # package that has never been published cannot have it configured — so + # OIDC alone cannot do the FIRST publish. Confirmed on ai-forms: the + # provenance statement was signed and logged to sigstore, then the PUT + # returned E404 "could not be found or you do not have permission", + # which reads like a missing package rather than a missing credential. + # + # NPM_TOKEN covers only that first publish. Once this package exists and + # a trusted publisher is configured, npm prefers OIDC and the secret can + # be deleted. - run: npm publish + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}