Skip to content

ci: publish to npm via OIDC trusted publishing - #4

Merged
alejoamiras merged 1 commit into
mainfrom
ad/npm-trusted-publishing
Oct 1, 2026
Merged

alejoamiras merged 1 commit into
mainfrom
ad/npm-trusted-publishing

Conversation

@ludamad

@ludamad ludamad commented Sep 30, 2026

Copy link
Copy Markdown

Replace the NPM_TOKEN secret with npm trusted publishing: grant the workflow id-token: write and upgrade to npm 11 (OIDC needs >= 11.5.1, Node 22 bundles npm 10).

The OIDC token only authorizes npm publish, so re-runs of an already published version no longer move dist-tags; the stable job warns with the npm dist-tag add command when the tag points elsewhere.

Replace the NPM_TOKEN secret with npm trusted publishing: grant the
workflow id-token: write and upgrade to npm 11 (OIDC needs >= 11.5.1,
Node 22 bundles npm 10).

The OIDC token only authorizes npm publish, so re-runs of an already
published version no longer move dist-tags; the stable job warns with
the npm dist-tag add command when the tag points elsewhere.
@alejoamiras
alejoamiras self-requested a review October 1, 2026 15:11
@alejoamiras
alejoamiras merged commit 433bb26 into main Oct 1, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants