Skip to content

ci: migrate npm releases to trusted publishing - #35

Merged
owjs3901 merged 5 commits into
mainfrom
fix/npm-trusted-publishing
Oct 1, 2026
Merged

owjs3901 merged 5 commits into
mainfrom
fix/npm-trusted-publishing

Conversation

@owjs3901

@owjs3901 owjs3901 commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

The npm release job fails while N-API publishes a platform package with NPM_TOKEN. Switch the CLI and all four native packages to GitHub OIDC trusted publishing with npm 11 and Node.js 24.

Bun packs every package before any publication; npm then publishes those exact verified tarballs. Verification rejects unresolved workspace protocols, local paths/archives, inconsistent native package versions, and missing binaries or entry points. N-API preparation disables automatic publication and GitHub release creation. Native packages publish before the CLI, and exact-version checks allow retries after partial publication. The publishing job runs only on pushes to main; changepacks draft finalization remains gated on downstream success.

Windows CI exposed a Bun workspace lookup failure through 8.3 temp-path aliases such as RUNNER~1. The packing script now canonicalizes package directories with native realpath. The regression installs the fixture through its real path and calls packing with the original, potentially aliased path.

Validation at 39890e4:

  • bun run test passed on Windows with an actual 8.3 TEMP path: 1,058 Rust tests and 3 Node tests.
  • bun run lint and git diff --check passed.
  • All five release tarballs built from existing 0.3.0 CI binaries passed archive inspection and npm publication dry runs.
  • Packaging verifies workspace:^ becomes ^1.2.3, rejects file: and bare relative dependencies, then installs both tarballs offline and executes the CLI.
  • Independent review found no issues. GitHub CI run 36819317925 succeeded: all 19 executed jobs passed, including the Windows packaging and Python wheel regressions.

Configured and verified a GitHub Actions trusted publisher for each package with owner dev-five-git, repository dependency-check-updates, workflow filename CI.yml, no environment, and direct npm publish allowed:

  • @dependency-check-updates/cli
  • @dependency-check-updates/cli-darwin-arm64
  • @dependency-check-updates/cli-darwin-x64
  • @dependency-check-updates/cli-linux-x64-gnu
  • @dependency-check-updates/cli-win32-x64-msvc

All five registry connections were saved and verified on npm. Node Publish in main run 36822262872 successfully published all five 0.3.0 packages through OIDC. Downloaded registry tarballs passed integrity, dependency, file, and provenance checks, including the CI.yml source commit. Installing from the registry ran the CLI as 0.3.0; npm audit signatures verified signatures and attestations. The obsolete repository NPM_TOKEN secret has been removed. Follow-up PR #36 makes GitHub asset uploads safe to retry after encountering existing Python wheel assets. See docs/npm-publishing.md for setup and token retirement after the first successful OIDC release. PyPI and crates.io publishing remain separate and unchanged.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Changepacks

@dependency-check-updates/cli@0.3.0 - bridge/node/package.json

Maybe you forgot to write the following files to the latest version

@owjs3901
owjs3901 marked this pull request as ready for review October 1, 2026 05:57
@owjs3901
owjs3901 merged commit c123fd5 into main Oct 1, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant