From 75c18949dd9d9de194dc8c88003a1fdb7a4e0517 Mon Sep 17 00:00:00 2001 From: raj pandey Date: Thu, 1 Oct 2026 12:45:49 +0530 Subject: [PATCH] chore(release): publish to npm with trusted publishing Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and keeps publishing with the job's own token. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/npm-publish.yml | 34 --------------------- .github/workflows/release.yml | 49 +++++++++++++++++++++++++++++++ 2 files changed, 49 insertions(+), 34 deletions(-) delete mode 100644 .github/workflows/npm-publish.yml create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/npm-publish.yml b/.github/workflows/npm-publish.yml deleted file mode 100644 index ccff067..0000000 --- a/.github/workflows/npm-publish.yml +++ /dev/null @@ -1,34 +0,0 @@ -# This workflow will publish a package to GitHub Packages when a release is created -# For more information see: https://help.github.com/actions/language-and-framework-guides/publishing-nodejs-packages - -name: Publish package to NPM repository -on: - release: - types: [created] - -jobs: - publish-npm: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://registry.npmjs.org' - - run: npm ci - - run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - publish-git: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://npm.pkg.github.com' - scope: '@contentstack' - - run: npm ci - - run: npm publish - env: - NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..87c4900 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,49 @@ +name: Publish package to npmjs registry +on: + release: + types: [published] + +jobs: + publish-npm: + runs-on: ubuntu-latest + permissions: + contents: read + id-token: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://registry.npmjs.org/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }} + + publish-github: + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://npm.pkg.github.com/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish + env: + NODE_AUTH_TOKEN: ${{ github.token }}