Skip to content

chore(release): publish to npm with trusted publishing - #73

Open
cs-raj wants to merge 1 commit into
developmentfrom
feat/DX-27614
Open

cs-raj wants to merge 1 commit into
developmentfrom
feat/DX-27614

Conversation

@cs-raj

@cs-raj cs-raj commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Problem

release.yml publishes @contentstack/webhook-listener to npm with a long-lived NPM_TOKEN.

The SE1 publishing policy requires OIDC trusted publishing instead: no token, a release.yml workflow that runs when a release is published, Node 24.

Fix

release.yml is rewritten in place. What changes inside it:

Before After
Trigger release: created release: published
npm auth NPM_TOKEN OIDC — id-token: write, no token
npm publish npm publish --tag latest --access public npm publish --access public; pre-releases go to the beta dist-tag, releases to latest
Node / npm 22.x / npm 10 24 / latest npm
Build npm run build-ts unchanged
Checkout release tag, credentials persisted release tag, persist-credentials: false
Actions checkout@v4, setup-node@v4 @v7

Verification

Node 22 and Node 24: install, build and npm pack all pass.

Publish on release:published so the npm trusted publisher keyed on release.yml
can be used, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on
Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the
release tag without persisted credentials, keep the explicit build-ts step.
GitHub pre-releases go to the beta dist-tag.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 09:30
@cs-raj cs-raj self-assigned this Oct 1, 2026
@snyk-io

snyk-io Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The nonexistent actions/checkout@v7 and actions/setup-node@v7 references prevent the workflow from running.

Review effort: Balanced
Findings: None

What changed in this PR

Migrates npm releases from token authentication to OIDC trusted publishing.

Changes:

  • Publishes on release publication using Node 24 and OIDC.
  • Routes prereleases to beta and stable releases to latest.
  • Disables persisted checkout credentials.
File Description
.github/​workflows/​release.yml Updates the npm publishing workflow.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants