Skip to content

Publish the npm launcher from the release workflow - #46

Merged
tauanbinato merged 1 commit into
mainfrom
npm-trusted-publishing
Sep 28, 2026
Merged

tauanbinato merged 1 commit into
mainfrom
npm-trusted-publishing

Conversation

@tauanbinato

Copy link
Copy Markdown
Contributor

0.30.0's npm package was published by hand: npm had the maintainer sign in with a security key in the browser, which an automated run cannot do. This adds an npm job to release.yml, after the GitHub release, that publishes it through npm's trusted publishing: the job's OIDC token stands in for an npm token, and npm adds the package's provenance itself, as the release archives already have.

  • The job runs in a new GitHub environment, npm, whose deployments are limited to v* tags, like crates-io. npm's trusted publisher for the package is this repository, the workflow release.yml and the environment npm.
  • It sets up Node 24 with actions/setup-node v7.0.0 (pinned by SHA, no package cache, as setup-node's trusted-publishing guide says) and stops with an error if npm is older than 11.5.1, which trusted publishing needs.
  • It checks that npm/package.json has the tag's version, skips a version npm already has, so a rerun is safe, and ships the release's SHA256SUMS in the package, as the hand publish did.
  • actionlint passes; the job itself first runs on the next tag.

0.30.0's package was published by hand, with the maintainer's security
key in the browser, which an automated run cannot do. A job after the
GitHub release now publishes it through npm's trusted publishing: the
environment npm (v* tags only, like crates-io) and the job's OIDC token
stand in for a token, and npm adds the package's provenance itself.

It checks that npm is 11.5.1 or later, which trusted publishing needs,
and that npm/package.json has the tag's version; it skips a version npm
already has, so a rerun is safe; and it ships the release's SHA256SUMS
in the package as the hand publish did.
@tauanbinato
tauanbinato merged commit e893650 into main Sep 28, 2026
12 checks passed
@tauanbinato
tauanbinato deleted the npm-trusted-publishing branch September 28, 2026 23:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant