From 07a7fa699d983eca3d918917f5c260c01b67f074 Mon Sep 17 00:00:00 2001 From: raj pandey Date: Thu, 1 Oct 2026 15:00:03 +0530 Subject: [PATCH] chore(release): publish to npm with trusted publishing Publish on release:published so the npm trusted publisher keyed on release.yml can be used, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials, keep the explicit build-ts step. GitHub pre-releases go to the beta dist-tag. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/release.yml | 27 +++++++++++++++------------ 1 file changed, 15 insertions(+), 12 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 29069c9..c3d59ad 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,24 +1,27 @@ -# This workflow will publish a package to GitHub Packages when a release is created -# For more information see: https://help.github.com/actions/language-and-framework-guides/publishing-nodejs-packages - -name: Publish package to NPM repository +name: Publish package to npmjs registry on: release: - types: [created] + types: [published] jobs: publish-npm: runs-on: ubuntu-latest + permissions: + contents: read + id-token: write steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ref: ${{ github.event.release.tag_name }} - - uses: actions/setup-node@v4 + persist-credentials: false + - uses: actions/setup-node@v7 with: - node-version: "22.x" - registry-url: "https://registry.npmjs.org" + node-version: 24 + registry-url: https://registry.npmjs.org/ + cache: 'npm' - run: npm ci - run: npm run build-ts - - run: npm publish --tag latest --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }}