Skip to content

fix(release): publish to npm with NPM_TOKEN until npm accepts immutable OIDC subjects - #76

Merged
taraxvoid merged 1 commit into
mainfrom
ci/npm-token-stopgap
Sep 30, 2026
Merged

taraxvoid merged 1 commit into
mainfrom
ci/npm-token-stopgap

Conversation

@taraxvoid

Copy link
Copy Markdown
Owner

Trusted publishing fails with 403 OIDC permission denied because this repo issues GitHub's immutable OIDC subject claims (repo:taraxvoid@<id>/voidflow@<id>:...), forced on for repos created or renamed after 2026-07-15 and not switchable. npm's token exchange rejects that format: npm/cli#9969.

  • Both publish steps now set NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}. Provenance still works via id-token: write.
  • Removes the temporary OIDC claim debug step from ci(release): manual npm republish + OIDC debug #75. The workflow_dispatch manual republish stays.
  • Comments explain how to revert to pure OIDC once npm fixes it (delete the secret and the NODE_AUTH_TOKEN lines; the trusted publisher entries are already configured).

Before merging / republishing

  1. Create a granular npm access token (read/write, scoped to @taraxvoid/voidflow and voidflow, bypass-2FA for automation).
  2. Add it as NPM_TOKEN on the npm GitHub environment (Settings > Environments > npm > Environment secrets).
  3. After merge, run Release Please manually (Actions > Run workflow) with tag v0.7.0 to publish it.

🤖 Generated with Claude Code

…le OIDC subjects

Trusted publishing fails with 403 because this repo issues GitHub's
immutable OIDC subject claims (forced for repos created/renamed after
2026-07-15) and npm's token exchange rejects them (npm/cli#9969). Use a
granular token via NODE_AUTH_TOKEN for now; provenance still works. Also
removes the temporary OIDC claim debug step.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@taraxvoid
taraxvoid merged commit 87a407b into main Sep 30, 2026
1 check passed
@taraxvoid
taraxvoid deleted the ci/npm-token-stopgap branch September 30, 2026 01:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant