Skip to content

ci: npm trusted publishing (OIDC) + framework 0.5.0 - #22

Merged
CharanMN7 merged 3 commits into
mainfrom
ci/npm-trusted-publishing
Sep 25, 2026
Merged

CharanMN7 merged 3 commits into
mainfrom
ci/npm-trusted-publishing

Conversation

@CharanMN7

Copy link
Copy Markdown
Contributor

Adds tag-triggered OIDC release workflow; no npm token stored. Bumps @inkform/framework to 0.5.0.

CharanMN7 and others added 3 commits August 30, 2026 16:53
Releases for @inkform/framework and @inkform/cli were a manual `npm publish`
from a maintainer's laptop. This replaces that with a tag-driven workflow.

Authentication is npm Trusted Publishing: GitHub mints a short-lived OIDC
token scoped to this exact workflow file, and npm accepts it because each
package's trusted-publisher settings name this repo and this filename. No
NPM_TOKEN is stored in the repository, and every release carries a provenance
attestation automatically.

Push `framework-v<version>` or `cli-v<version>` to release that package. The
job re-runs the full ci.yml gate against the tagged commit (a green PR check
is not proof the tag is green), refuses a tag whose version disagrees with
package.json, and refuses a version already on npm rather than surfacing
npm's bare 403. workflow_dispatch rehearses the whole thing in dry-run.

Hardening notes, since the repo is public:
- No pull_request trigger. A workflow holding id-token: write must never run
  fork-supplied code.
- permissions are contents:read + id-token:write, nothing more.
- Every ${{ }} value is passed through env: and read as a shell variable.
  GitHub splices expansions in as raw text before bash parses the file, so an
  inline expansion in a run block is a script-injection sink.
- The job runs in an `npm-publish` environment, so adding required reviewers
  there gates every publish on a human approval independently of npm.

setup-node ships npm 10 with Node 22; trusted publishing needs >= 11.5.1, so
the workflow upgrades npm explicitly — removing that step yields a confusing
ENEEDAUTH.

PUBLISHING.md is rewritten for this flow; it had gone stale claiming
@inkform/framework had never been published.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012XWzjtTYZRNgD1YVM6pJ8u
df21f0b ("Unify secondary top nav styling and add mobile scroll hints")
dropped `"./reactions"` from the exports map while adding the two nav
entries. Nothing else in that commit touches reactions, and the commit
message doesn't mention it — it was collateral, not a decision.

The effect is a documented public export that resolves to nothing:

- `src/reactions.tsx` is unchanged and still ships inside the tarball
  (`files: ["src"]`), it's just unreachable.
- `packages/framework/README.md` lists `./reactions` among the
  bring-your-own-backend widgets, and that README ships in the tarball too.
- `examples/inkform-docs` — the dogfooded docs site — documents
  `import { Reactions } from '@inkform/framework/reactions'` in both
  guides/interactive.mdx and reference/framework-api.mdx.

So the published docs instruct an import the published package can't
satisfy. Restored in its original position between ./analytics-script and
the widget group it belongs to.

This also keeps the next release purely additive: every export present in
0.4.0 is present now, with ./markdown, ./page-actions, ./secondary-top-nav
and ./scrollable-top-nav added.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012XWzjtTYZRNgD1YVM6pJ8u
npm's latest is 0.4.0, published 2026-07-22. Everything merged since — the
Markdown-per-URL routes, the structural MDX-to-Markdown converter, page
actions, the expanded AI tool menu, the unified secondary nav — has had no
path to npm, because main still declared 0.4.0. Same version number,
different code: `npm publish` returns 403 against an immutable version.

Bumps packages/framework to 0.5.0 and writes the CHANGELOG entry. Purely
additive over 0.4.0 — with ./reactions restored in the previous commit, every
export present in 0.4.0 is still present.

Also fixes the dependency range that made scaffolding hand users stale code.
Every template and example declared "@inkform/framework": "^0.3.0". For a 0.x
package that range is >=0.3.0 <0.4.0, so it stopped matching the moment the
framework went to 0.4.0. Two consequences, both live today:

- `npx @inkform/cli init` && `npm install` resolved to 0.3.0. New users got a
  framework with no native API reference renderer, no MCP server, no AI
  ask-box and no llms.txt — all of which shipped in 0.4.0. The CLI rewrites a
  scaffolded project's name and version but never touched this range.
- Inside the monorepo the local packages/framework no longer satisfied what
  the workspaces asked for, so npm fetched a real 0.3.0 from the registry
  into all six workspaces' own node_modules, shadowing the live source. Those
  entries were in the lockfile; removing them accounts for the 139 deleted
  lines here.

That second one is what scripts/prune-workspace-shadows.mjs has been deleting
on every postinstall since it was written. Its header blamed npm for
"occasionally" materializing physical copies; the cause was this range all
along, so the note is corrected to point at the real trigger. The script
stays — the failure mode is silent and confusing — but it now prunes nothing.

Ranges move to ^0.5.0. archive/templates/* is deliberately left at ^0.3.0:
those are archived, don't build, and take security bumps only.

PUBLISHING.md gains the ordering caveat this creates — templates declare a
real npm range and the CLI scaffolds from GitHub main without pinning a ref,
so between merging a release PR and the tag publishing, a scaffold asks for a
version npm doesn't have yet.

Verified on this tree: npm ci, lint, typecheck, test (96/96), build, and
npm audit --audit-level=high all pass; the prune script now reports nothing;
every workspace resolves @inkform/framework to packages/framework at 0.5.0;
npm pack --dry-run produces inkform-framework-0.5.0.tgz, 88 files.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012XWzjtTYZRNgD1YVM6pJ8u
@vercel

vercel Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
framework-inkform-docs Ready Ready Preview Sep 25, 2026 9:01am UTC
pokeapi Ready Ready Preview Sep 25, 2026 9:01am UTC

Request Review

@CharanMN7 CharanMN7 self-assigned this Sep 25, 2026
@CharanMN7
CharanMN7 merged commit 09d8fd9 into main Sep 25, 2026
3 of 4 checks passed

This branch was successfully deployed

2 active deployments
Preview – pokeapi — e86a3d65 Deployed Sep 25, 2026 by vercel[bot]
Preview – framework-inkform-docs — e86a3d65 Deployed Sep 25, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant