Skip to content

ci(release): npm trusted publishing, drop NPM_TOKEN - #52

Open
karngyan wants to merge 1 commit into
mainfrom
ci/npm-trusted-publishing
Open

karngyan wants to merge 1 commit into
mainfrom
ci/npm-trusted-publishing

Conversation

@karngyan

@karngyan karngyan commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Why

The release run after merging Version Packages (#47) failed at publish:

🦋  error an error occurred while publishing @karnstack/reins: E404 undefined
🦋  packages failed to publish: @karnstack/reins@0.6.1

Build and tests passed. npm answers a publish it won't authorize with 404. The NPM_TOKEN secret was created 2026-07-04, and npm caps write tokens at 90 days, which ran out on 2026-10-02, the day of the run. 0.6.0 published fine with the same token on 2026-09-28. npm is also restricting tokens that bypass 2FA for direct publishing, so swapping in a new token would just put this off.

What

  • release.yml: remove NPM_TOKEN from the changesets step. With it unset, changesets/action@v1 writes no ~/.npmrc and logs "using npm trusted publishing". pnpm publish (11.9) trades the job's OIDC token for a short-lived npm token. id-token: write was already granted for provenance.
  • docs/RELEASING.md: drop NPM_TOKEN from required secrets, document the trusted publisher entry and the E404 it causes when missing.

⚠️ Before merging

Merging pushes to main, which runs release and publishes 0.6.1. First, on npmjs.com → @karnstack/reins → Settings → Trusted Publisher → GitHub Actions:

  • Organization or user: karnstack
  • Repository: reins
  • Workflow filename: release.yml
  • Environment: (blank)

Then delete the NPM_TOKEN repo secret (optional; it's already dead).

Test plan

  • workflow YAML lints
  • trusted publisher configured on npm
  • after merge: release run logs "using npm trusted publishing", publishes @karnstack/reins@0.6.1, tags + GitHub release appear

🤖 Generated with Claude Code

The 0.6.1 publish failed with E404: the NPM_TOKEN secret, created
2026-07-04, hit npm's 90-day cap on write tokens on 2026-10-02. With
NPM_TOKEN unset, changesets/action writes no ~/.npmrc and pnpm 11's
publish exchanges the job's OIDC token (id-token: write, already granted)
for a short-lived npm token. Needs a trusted publisher configured on
npmjs.com for @karnstack/reins; RELEASING.md says which.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant