Skip to content

Publish releases with npm trusted publishing - #48

Merged
pmochine merged 2 commits into
masterfrom
trusted-publishing
Oct 7, 2026
Merged

pmochine merged 2 commits into
masterfrom
trusted-publishing

Conversation

@pmochine

@pmochine pmochine commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Adds .github/workflows/release.yml: a version tag such as 1.2.3 publishes the package to npm with npm trusted publishing (OIDC). No npm token is stored and no 2FA prompt is needed.

How it works

  • verify (no OIDC permission): install, lint, tests, npm pack --dry-run, and for tags a check that the tag matches package.json and is on the default branch.
  • publish (tags only, environment npm-publish, id-token: write): checks the tag again before any repository code runs, installs with --ignore-scripts, then runs npm publish. Provenance is automatic.
  • check-trusted-publisher (manual run on the default branch only): asks npm for a publish token the same way npm publish does and reports the result. It publishes nothing and runs no repository scripts.

npm setup (once per package, right before a release)

On npmjs.com, add a trusted publisher: this repository, workflow release.yml, environment npm-publish, and under "Allowed actions" select npm publish. A new trusted publisher expires if it does not publish within 2 days.

Review

A Codex review (gpt-6-astra) found four problems: OIDC access during repository scripts, a manual check that failed for existing versions, the missing npm publish permission in the setup notes, and the concurrency of pending releases. The second commit fixes them. The re-review found no new problems. actionlint passes. npm ci --ignore-scripts plus npm pack produces the same tarball as the published version.

🤖 Generated with Claude Code

pmochine and others added 2 commits October 7, 2026 15:03
A new workflow publishes the package to npm when a version tag like
1.2.3 is pushed. npm trusts the workflow through OIDC, so no npm token is
stored and no 2FA prompt is needed. The workflow runs the lint and the
tests first, and stops if the tag does not match package.json or is not
on the default branch. Run by hand, it only checks the trusted publisher
setup with npm publish --dry-run and an OIDC token exchange.

The trusted publisher on npmjs.com must point to this repository, the
workflow file release.yml and the environment npm-publish.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Findings of the Codex Astra review of the release workflow:

- Install, lint and tests run in a verify job without the id-token
  permission. Only the publish job and the check job may request an OIDC
  token.
- The publish job checks the tag and its branch before any repository
  code runs, and installs with --ignore-scripts.
- The manual check runs only on the default branch and executes no
  repository scripts. It no longer runs npm publish --dry-run, which
  fails for a version that already exists.
- Each tag has its own concurrency group, so a pending release is not
  replaced by another run.
- The README says that the trusted publisher must allow npm publish and
  expires after 2 days without a publish.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@pmochine
pmochine merged commit ffb618a into master Oct 7, 2026
2 checks passed
@pmochine
pmochine deleted the trusted-publishing branch October 7, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant