Repository navigation
Enable tokenless npm releases on GitHub-hosted CI - #1
Merged
Merged
Conversation
| exit 1 | ||
| fi | ||
| npm publish "release/$ARCHIVE" --access public --ignore-scripts | ||
| npm publish "release/$ARCHIVE" --access public --ignore-scripts --provenance |
There was a problem hiding this comment.
🟠 High workflows/ci.yml:78
Main-branch releases are rejected instead of publishing the archive because npm publish requests provenance for this private repository, where npm does not support provenance attestations. Remove --provenance for this repository so tokenless releases can complete.
Suggested change
| npm publish "release/$ARCHIVE" --access public --ignore-scripts --provenance | |
| npm publish "release/$ARCHIVE" --access public --ignore-scripts |
🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @.github/workflows/ci.yml around line 78:
Main-branch releases are rejected instead of publishing the archive because `npm publish` requests provenance for this private repository, where npm does not support provenance attestations. Remove `--provenance` for this repository so tokenless releases can complete.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This makes releases from
malhashemi/workflow-observerpublish without a stored npm token. GitHub-hosted CI checks and packages the app, then a separate job publishes that tested archive using the repository's npm trusted-publisher identity and creates the GitHub release with provenance.Both jobs use GitHub-hosted runners because Blacksmith supports organization repositories only. The release guide and README now describe the working setup. Version 0.9.5 exercises the automatic release on merge.
Validation: 127 tests pass, TypeScript/OXC checks pass, and the read-only package smoke test passes. The workflow passes actionlint and the README passes its style check. The npm trusted publisher is configured for
malhashemi/workflow-observerandci.yml, with direct publishing allowed.Note
Switch CI and npm releases from Blacksmith runner and NPM_TOKEN to GitHub-hosted OIDC trusted publishing
check-and-packageandreleasejobs in ci.yml from the named Blacksmith runner to GitHub-hostedubuntu-latestand removes the repo-level actionlint config that declared the Blacksmith labelNPM_TOKENsecret with GitHub Actions OIDC-based npm trusted publishing, adds theid-token: writepermission, and enables--provenanceon the archive publication command0.9.4to0.9.5id-token: writepermission and npm trusted-publisher setup in docs/releasing.md must be complete before the next publish📊 Macroscope summarized cd97e27. 3 files reviewed, 1 issue evaluated, 0 issues filtered, 1 comment posted
🗂️ Filtered Issues