From 43f0338c19daca1764abffff9b977cac9606efa6 Mon Sep 17 00:00:00 2001 From: raj pandey Date: Thu, 1 Oct 2026 14:12:07 +0530 Subject: [PATCH] chore(release): publish to npm with trusted publishing Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and publishes with the job's own token instead of a personal token. package.json gains the repository field that provenance validation requires. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/npm-publish.yml | 34 --------------------- .github/workflows/release.yml | 49 +++++++++++++++++++++++++++++++ package.json | 6 +++- 3 files changed, 54 insertions(+), 35 deletions(-) delete mode 100644 .github/workflows/npm-publish.yml create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/npm-publish.yml b/.github/workflows/npm-publish.yml deleted file mode 100644 index db75ea79..00000000 --- a/.github/workflows/npm-publish.yml +++ /dev/null @@ -1,34 +0,0 @@ -# This workflow will publish a package to GitHub Packages when a release is created -# For more information see: https://help.github.com/actions/language-and-framework-guides/publishing-nodejs-packages - -name: Publish package to NPM repository -on: - release: - types: [created] - -jobs: - publish-npm: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://registry.npmjs.org' - - run: npm ci - - run: npm publish --tag latest --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - publish-git: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://npm.pkg.github.com' - scope: '@contentstack' - - run: npm ci - - run: npm publish --tag latest - env: - NODE_AUTH_TOKEN: ${{ secrets.PKG_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 00000000..87c49000 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,49 @@ +name: Publish package to npmjs registry +on: + release: + types: [published] + +jobs: + publish-npm: + runs-on: ubuntu-latest + permissions: + contents: read + id-token: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://registry.npmjs.org/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }} + + publish-github: + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://npm.pkg.github.com/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish + env: + NODE_AUTH_TOKEN: ${{ github.token }} diff --git a/package.json b/package.json index fdece848..0f026b0b 100644 --- a/package.json +++ b/package.json @@ -85,5 +85,9 @@ "typescript": "~5.7.3", "ts-node": "^10.9.2" }, - "homepage": "https://github.com/contentstack/contentstack-typescript" + "homepage": "https://github.com/contentstack/contentstack-typescript", + "repository": { + "type": "git", + "url": "git+https://github.com/contentstack/contentstack-typescript.git" + } }