Repository navigation
build(release): publish to npm via Trusted Publishing (OIDC) with semantic-release 25 - #2
Open
SahinurDEV wants to merge 1 commit into
Open
SahinurDEV wants to merge 1 commit into
SahinurDEV wants to merge 1 commit into
Conversation
…ease 25 - semantic-release ^24.1.0 -> ^25.0.9 (brings @semantic-release/npm 13.2.0 with OIDC trusted publishing and bundled npm 11.21.0, and @semantic-release/github 12.0.10 which fixes the fail-step 'Variable $owner of type String! was provided invalid value' crash) - README: document the token-less release setup
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this does
This PR switches the Release workflow's npm publishing to npm Trusted Publishing (OIDC), so the expired/invalid
NPM_TOKENsecret that broke run 37893945394 is no longer needed.semantic-release^24.1.0→^25.0.9. The lockfile now resolves:@semantic-release/npm13.2.0. It first tries a GitHub Actions OIDC → npm token exchange and only falls back toNPM_TOKENif that fails. It ships npm 11.21.0; Trusted Publishing needs ≥ 11.5.1.@semantic-release/github12.0.10. This fixes thefail-step crashVariable $owner of type String! was provided invalid value(a bug in 11.0.6).@semantic-release/changelog6.0.3 and@semantic-release/git10.0.1 stay as they are; their peer dependencysemantic-release >=20.1.0is satisfied.publishConfig.provenance: true, because that would break manualnpm publishfrom a laptop.The only lockfile changes are in the semantic-release dependency tree. No runtime or build dependency changed version.
Relation to #1: this PR is independent of #1 and replaces it. Both edit
package.json/package-lock.json, so merge this one and close #1.Workflow file: works as is, optional hardening patch below
My token can't push changes to
.github/workflows/*(it lacks theworkflowOAuth scope), so this PR does not changerelease.yml. None of the patch is required:permissions: id-token: write;node-version: 22.xresolves to Node ≥ 22.14, which semantic-release 25 needs;NPM_TOKEN, so a leftover secret does no harm.The recommended follow-up below (apply it from the web editor or a token that has the
workflowscope):NPM_TOKENfrom the job;release.yml patch
Verification (local, not on CI)
npm ciworks (no lockfile drift).npm run lint,typecheck,test:coverage(26 files, 250 tests, 100% coverage) andbuildall pass.npm ciprints onlyEBADENGINEwarnings, for release tooling that needs Node ≥ 22.14. Install still succeeds, so the CI matrix's 18/20 jobs should keep passing (this PR's CI run will confirm).@semantic-release/npmverifyConditionswith noNPM_TOKEN:Verifying OIDC context for publishing from GitHub Actionsand attempts the OIDC exchange first.NPM_TOKEN.One-time owner steps on npmjs.com
SahinurDEVForgeDatarelease.yml(filename only, no path)npm stage publishonly, which semantic-release's plainnpm publishcan't use.feat:/fix:/perf:) is about to land onmain. This PR's ownbuild:commit does not trigger a release. If the configuration expires, delete it and create it again.NPM_TOKENrepo secret (Settings → Secrets and variables → Actions).