ci: migrate npm releases to trusted publishing - #35
Merged
Merged
Conversation
… fix/npm-trusted-publishing
Changepacks@dependency-check-updates/cli@0.3.0 - bridge/node/package.jsonMaybe you forgot to write the following files to the latest version |
owjs3901
marked this pull request as ready for review
October 1, 2026 05:57
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The npm release job fails while N-API publishes a platform package with
NPM_TOKEN. Switch the CLI and all four native packages to GitHub OIDC trusted publishing with npm 11 and Node.js 24.Bun packs every package before any publication; npm then publishes those exact verified tarballs. Verification rejects unresolved workspace protocols, local paths/archives, inconsistent native package versions, and missing binaries or entry points. N-API preparation disables automatic publication and GitHub release creation. Native packages publish before the CLI, and exact-version checks allow retries after partial publication. The publishing job runs only on pushes to
main; changepacks draft finalization remains gated on downstream success.Windows CI exposed a Bun workspace lookup failure through 8.3 temp-path aliases such as
RUNNER~1. The packing script now canonicalizes package directories with native realpath. The regression installs the fixture through its real path and calls packing with the original, potentially aliased path.Validation at
39890e4:bun run testpassed on Windows with an actual 8.3TEMPpath: 1,058 Rust tests and 3 Node tests.bun run lintandgit diff --checkpassed.workspace:^becomes^1.2.3, rejectsfile:and bare relative dependencies, then installs both tarballs offline and executes the CLI.Configured and verified a GitHub Actions trusted publisher for each package with owner
dev-five-git, repositorydependency-check-updates, workflow filenameCI.yml, no environment, and directnpm publishallowed:@dependency-check-updates/cli@dependency-check-updates/cli-darwin-arm64@dependency-check-updates/cli-darwin-x64@dependency-check-updates/cli-linux-x64-gnu@dependency-check-updates/cli-win32-x64-msvcAll five registry connections were saved and verified on npm. Node Publish in main run 36822262872 successfully published all five 0.3.0 packages through OIDC. Downloaded registry tarballs passed integrity, dependency, file, and provenance checks, including the CI.yml source commit. Installing from the registry ran the CLI as 0.3.0; npm audit signatures verified signatures and attestations. The obsolete repository NPM_TOKEN secret has been removed. Follow-up PR #36 makes GitHub asset uploads safe to retry after encountering existing Python wheel assets. See
docs/npm-publishing.mdfor setup and token retirement after the first successful OIDC release. PyPI and crates.io publishing remain separate and unchanged.