ci: npm trusted publishing (OIDC) + framework 0.5.0 - #22
Merged
Merged
Conversation
Releases for @inkform/framework and @inkform/cli were a manual `npm publish`
from a maintainer's laptop. This replaces that with a tag-driven workflow.
Authentication is npm Trusted Publishing: GitHub mints a short-lived OIDC
token scoped to this exact workflow file, and npm accepts it because each
package's trusted-publisher settings name this repo and this filename. No
NPM_TOKEN is stored in the repository, and every release carries a provenance
attestation automatically.
Push `framework-v<version>` or `cli-v<version>` to release that package. The
job re-runs the full ci.yml gate against the tagged commit (a green PR check
is not proof the tag is green), refuses a tag whose version disagrees with
package.json, and refuses a version already on npm rather than surfacing
npm's bare 403. workflow_dispatch rehearses the whole thing in dry-run.
Hardening notes, since the repo is public:
- No pull_request trigger. A workflow holding id-token: write must never run
fork-supplied code.
- permissions are contents:read + id-token:write, nothing more.
- Every ${{ }} value is passed through env: and read as a shell variable.
GitHub splices expansions in as raw text before bash parses the file, so an
inline expansion in a run block is a script-injection sink.
- The job runs in an `npm-publish` environment, so adding required reviewers
there gates every publish on a human approval independently of npm.
setup-node ships npm 10 with Node 22; trusted publishing needs >= 11.5.1, so
the workflow upgrades npm explicitly — removing that step yields a confusing
ENEEDAUTH.
PUBLISHING.md is rewritten for this flow; it had gone stale claiming
@inkform/framework had never been published.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012XWzjtTYZRNgD1YVM6pJ8u
df21f0b ("Unify secondary top nav styling and add mobile scroll hints") dropped `"./reactions"` from the exports map while adding the two nav entries. Nothing else in that commit touches reactions, and the commit message doesn't mention it — it was collateral, not a decision. The effect is a documented public export that resolves to nothing: - `src/reactions.tsx` is unchanged and still ships inside the tarball (`files: ["src"]`), it's just unreachable. - `packages/framework/README.md` lists `./reactions` among the bring-your-own-backend widgets, and that README ships in the tarball too. - `examples/inkform-docs` — the dogfooded docs site — documents `import { Reactions } from '@inkform/framework/reactions'` in both guides/interactive.mdx and reference/framework-api.mdx. So the published docs instruct an import the published package can't satisfy. Restored in its original position between ./analytics-script and the widget group it belongs to. This also keeps the next release purely additive: every export present in 0.4.0 is present now, with ./markdown, ./page-actions, ./secondary-top-nav and ./scrollable-top-nav added. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012XWzjtTYZRNgD1YVM6pJ8u
npm's latest is 0.4.0, published 2026-07-22. Everything merged since — the Markdown-per-URL routes, the structural MDX-to-Markdown converter, page actions, the expanded AI tool menu, the unified secondary nav — has had no path to npm, because main still declared 0.4.0. Same version number, different code: `npm publish` returns 403 against an immutable version. Bumps packages/framework to 0.5.0 and writes the CHANGELOG entry. Purely additive over 0.4.0 — with ./reactions restored in the previous commit, every export present in 0.4.0 is still present. Also fixes the dependency range that made scaffolding hand users stale code. Every template and example declared "@inkform/framework": "^0.3.0". For a 0.x package that range is >=0.3.0 <0.4.0, so it stopped matching the moment the framework went to 0.4.0. Two consequences, both live today: - `npx @inkform/cli init` && `npm install` resolved to 0.3.0. New users got a framework with no native API reference renderer, no MCP server, no AI ask-box and no llms.txt — all of which shipped in 0.4.0. The CLI rewrites a scaffolded project's name and version but never touched this range. - Inside the monorepo the local packages/framework no longer satisfied what the workspaces asked for, so npm fetched a real 0.3.0 from the registry into all six workspaces' own node_modules, shadowing the live source. Those entries were in the lockfile; removing them accounts for the 139 deleted lines here. That second one is what scripts/prune-workspace-shadows.mjs has been deleting on every postinstall since it was written. Its header blamed npm for "occasionally" materializing physical copies; the cause was this range all along, so the note is corrected to point at the real trigger. The script stays — the failure mode is silent and confusing — but it now prunes nothing. Ranges move to ^0.5.0. archive/templates/* is deliberately left at ^0.3.0: those are archived, don't build, and take security bumps only. PUBLISHING.md gains the ordering caveat this creates — templates declare a real npm range and the CLI scaffolds from GitHub main without pinning a ref, so between merging a release PR and the tag publishing, a scaffold asks for a version npm doesn't have yet. Verified on this tree: npm ci, lint, typecheck, test (96/96), build, and npm audit --audit-level=high all pass; the prune script now reports nothing; every workspace resolves @inkform/framework to packages/framework at 0.5.0; npm pack --dry-run produces inkform-framework-0.5.0.tgz, 88 files. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012XWzjtTYZRNgD1YVM6pJ8u
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds tag-triggered OIDC release workflow; no npm token stored. Bumps @inkform/framework to 0.5.0.