Skip to content

Enable tokenless npm releases on GitHub-hosted CI - #1

Merged
malhashemi merged 2 commits into
mainfrom
ci/trusted-publishing
Sep 15, 2026
Merged

malhashemi merged 2 commits into
mainfrom
ci/trusted-publishing

Conversation

@malhashemi

@malhashemi malhashemi commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner

This makes releases from malhashemi/workflow-observer publish without a stored npm token. GitHub-hosted CI checks and packages the app, then a separate job publishes that tested archive using the repository's npm trusted-publisher identity and creates the GitHub release with provenance.

Both jobs use GitHub-hosted runners because Blacksmith supports organization repositories only. The release guide and README now describe the working setup. Version 0.9.5 exercises the automatic release on merge.

Validation: 127 tests pass, TypeScript/OXC checks pass, and the read-only package smoke test passes. The workflow passes actionlint and the README passes its style check. The npm trusted publisher is configured for malhashemi/workflow-observer and ci.yml, with direct publishing allowed.

Note

Switch CI and npm releases from Blacksmith runner and NPM_TOKEN to GitHub-hosted OIDC trusted publishing

  • Moves the check-and-package and release jobs in ci.yml from the named Blacksmith runner to GitHub-hosted ubuntu-latest and removes the repo-level actionlint config that declared the Blacksmith label
  • Replaces the stored NPM_TOKEN secret with GitHub Actions OIDC-based npm trusted publishing, adds the id-token: write permission, and enables --provenance on the archive publication command
  • Updates README.md and docs/releasing.md to document GitHub-hosted runners, trusted-publisher setup, provenance, and the removal of the npm token
  • Bumps the package version in package.json from 0.9.4 to 0.9.5
  • Risk: releases now fail if the npm package is not preconfigured as a trusted publisher with the workflow's OIDC identity; the id-token: write permission and npm trusted-publisher setup in docs/releasing.md must be complete before the next publish
📊 Macroscope summarized cd97e27. 3 files reviewed, 1 issue evaluated, 0 issues filtered, 1 comment posted

🗂️ Filtered Issues

@malhashemi
malhashemi merged commit 46dc0cd into main Sep 15, 2026
3 checks passed
@malhashemi
malhashemi deleted the ci/trusted-publishing branch September 15, 2026 12:36
Comment thread .github/workflows/ci.yml
exit 1
fi
npm publish "release/$ARCHIVE" --access public --ignore-scripts
npm publish "release/$ARCHIVE" --access public --ignore-scripts --provenance

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High workflows/ci.yml:78

Main-branch releases are rejected instead of publishing the archive because npm publish requests provenance for this private repository, where npm does not support provenance attestations. Remove --provenance for this repository so tokenless releases can complete.

Suggested change
npm publish "release/$ARCHIVE" --access public --ignore-scripts --provenance
npm publish "release/$ARCHIVE" --access public --ignore-scripts
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @.github/workflows/ci.yml around line 78:

Main-branch releases are rejected instead of publishing the archive because `npm publish` requests provenance for this private repository, where npm does not support provenance attestations. Remove `--provenance` for this repository so tokenless releases can complete.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant