From 5a68f2d0996c34ce204cfb0a3f5ecf933fa21387 Mon Sep 17 00:00:00 2001 From: Aymeric Rabot Date: Fri, 11 Sep 2026 13:03:40 -0400 Subject: [PATCH] ci(release): drop registry-url so npm uses OIDC trusted publishing The 1.0.0 run failed publishing core with E404. actions/setup-node with registry-url writes an .npmrc whose token falls back to the placeholder XXXXX-XXXXX-XXXXX-XXXXX when NODE_AUTH_TOKEN is unset; npm sent that fake token instead of exchanging the Actions OIDC token, and the registry answered 404. Without registry-url no .npmrc is written and npm 11 falls through to trusted publishing. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/release.yml | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index b18f92f5a1..8e6f8ecd17 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -77,10 +77,14 @@ jobs: with: bun-version: 1.3.14 + # No registry-url here: with it, actions/setup-node writes an .npmrc whose + # auth token falls back to the placeholder XXXXX-XXXXX-XXXXX-XXXXX, npm + # sends that fake token, the registry answers 404, and the OIDC trusted + # publishing exchange never runs. npm publishes to registry.npmjs.org by + # default and each publish step passes --access public explicitly. - uses: actions/setup-node@v4 with: node-version: 22 - registry-url: "https://registry.npmjs.org" # npm refuses direct publishing with 2FA-bypass tokens (EOTP, see # https://gh.io/npm-gat-bypass2fa-deprecation), so no NODE_AUTH_TOKEN is set