Publish the npm launcher from the release workflow - #46
Merged
Merged
Conversation
0.30.0's package was published by hand, with the maintainer's security key in the browser, which an automated run cannot do. A job after the GitHub release now publishes it through npm's trusted publishing: the environment npm (v* tags only, like crates-io) and the job's OIDC token stand in for a token, and npm adds the package's provenance itself. It checks that npm is 11.5.1 or later, which trusted publishing needs, and that npm/package.json has the tag's version; it skips a version npm already has, so a rerun is safe; and it ships the release's SHA256SUMS in the package as the hand publish did.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
0.30.0's npm package was published by hand: npm had the maintainer sign in with a security key in the browser, which an automated run cannot do. This adds an
npmjob torelease.yml, after the GitHub release, that publishes it through npm's trusted publishing: the job's OIDC token stands in for an npm token, and npm adds the package's provenance itself, as the release archives already have.npm, whose deployments are limited tov*tags, likecrates-io. npm's trusted publisher for the package is this repository, the workflowrelease.ymland the environmentnpm.actions/setup-nodev7.0.0 (pinned by SHA, no package cache, as setup-node's trusted-publishing guide says) and stops with an error if npm is older than 11.5.1, which trusted publishing needs.npm/package.jsonhas the tag's version, skips a version npm already has, so a rerun is safe, and ships the release'sSHA256SUMSin the package, as the hand publish did.actionlintpasses; the job itself first runs on the next tag.