Conversation
Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and publishes with the job's own token instead of a personal token. package.json gains the repository field that provenance validation requires. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Coverage report
Test suite run success720 tests passing in 36 suites. Report generated by 🧪jest coverage report action from 43f0338 |
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
✅ BUILD PASSED - All security checks passed |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
GitHub Packages currently promotes prereleases under the latest dist-tag.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Migrates package releases to OIDC trusted publishing and improves GitHub Packages authentication.
Changes:
- Replaces token-based npm authentication with OIDC.
- Uses Node 24 and release-aware npm dist-tags.
- Adds repository metadata for provenance validation.
| File | Description |
|---|---|
package.json |
Adds repository metadata. |
.github/workflows/release.yml |
Introduces trusted publishing workflows. |
.github/workflows/npm-publish.yml |
Removes the legacy token-based workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| - name: Update npm | ||
| run: npm install -g npm@latest | ||
| - name: Release | ||
| run: npm publish |

Problem
npm-publish.ymlpublishes@contentstack/delivery-sdkto npm with a long-livedNPM_TOKEN.The SE1 publishing policy requires OIDC trusted publishing instead: no token, a
release.ymlworkflow that runs when a release is published, Node 24.The GitHub Packages job also authenticates with a personal token (
PKG_TOKEN) and lacks thepackages: writepermission.Fix
npm-publish.ymlis renamed torelease.yml. What changes inside it:release: createdrelease: publishedNPM_TOKENid-token: write, no tokennpm publish --tag latest --access publicnpm publish --access public; pre-releases go to thebetadist-tag, releases tolatestPKG_TOKEN(personal token), nopackages: writegithub.tokenwithpackages: writepersist-credentials: falsecheckout@v4,setup-node@v4@v7package.jsonrepositoryfieldVerification
Node 22 and Node 24: install, build, tests and
npm packall pass.