Skip to content

Commit 9eded63

Browse files
committed
ci: publish with a 2FA-bypass token and attach provenance
The account's second factor is a passkey, so CI cannot produce an OTP. A granular token created with the 2FA-bypass option does work, and npm keeps that capability for direct publishing until January 2027. Documents the migration to trusted publishing inline, so the deadline is visible at the point where the token is used rather than only in a changelog.
1 parent 22f0c81 commit 9eded63

1 file changed

Lines changed: 12 additions & 6 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,6 @@ on:
55
tags: ["v*"]
66
workflow_dispatch:
77

8-
# Trusted publishing (OIDC). npm exchanges this short-lived identity token for a
9-
# scoped publish token, so no long-lived npm secret is stored anywhere.
10-
# Provenance attestations are generated automatically for public packages built
11-
# from public repositories — `--provenance` is not needed and would be redundant.
128
permissions:
139
contents: write
1410
id-token: write
@@ -24,15 +20,25 @@ jobs:
2420
node-version: 24
2521
registry-url: https://registry.npmjs.org
2622
# Never restore a cache in a release build: the published artefact
27-
# should be built from exactly what is in the tag.
23+
# should come from exactly what is in the tag.
2824
cache: ""
2925

3026
- run: npm ci
3127
- run: npm run check
3228
- run: npm run build
3329

30+
# Publishing uses a granular token with the 2FA bypass enabled, since the
31+
# account's second factor is a passkey and cannot produce an OTP for CI.
32+
#
33+
# npm has announced that 2FA-bypass tokens lose direct publishing around
34+
# January 2027 (https://gh.io/npm-gat-bypass2fa-deprecation). Before then
35+
# this should move to trusted publishing (OIDC), which needs no secret at
36+
# all: configure it at npmjs.com/package/opencode-github-sync/access, then
37+
# delete both the NPM_TOKEN secret and the env block below.
3438
- name: Publish to npm
35-
run: npm publish --access public
39+
run: npm publish --access public --provenance
40+
env:
41+
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
3642

3743
- name: Create the GitHub release
3844
uses: softprops/action-gh-release@v2

0 commit comments

Comments
 (0)