Skip to content

chore: publish via npm OIDC trusted publishing - #52

Merged
xiaoyijun merged 2 commits into
masterfrom
xiaoyijun-chore-trusted-publishing
Aug 31, 2026
Merged

xiaoyijun merged 2 commits into
masterfrom
xiaoyijun-chore-trusted-publishing

Conversation

@xiaoyijun

@xiaoyijun xiaoyijun commented Aug 31, 2026 •

Copy link
Copy Markdown
Contributor

Motivation

The v1.0.0-beta.1 publish failed with E404 on PUT /mcp-auth — npm's disguised authorization error: the NPM_AUTOMATION_TOKEN secret has expired (last successful publish was in January; npm's token policy now favors short-lived credentials). Instead of minting another token that will expire again, switch to npm trusted publishing (OIDC): npmjs.com trusts this repository's publish.yml workflow directly, and no token is stored, rotated, or leaked.

Changes

  • publish.yml: drop the NODE_AUTH_TOKEN env from the publish step — with a trusted publisher configured on npmjs.com, pnpm publish authenticates through the workflow's OIDC token (id-token: write was already granted for provenance).
  • Publish on Node 24: pnpm publish delegates the actual publish to the npm CLI, and npm's trusted publishing requires npm >= 11.5.1 — Node 24 bundles npm 11.19.x, while Node 22 still ships npm 10.9.x (pnpm has no built-in OIDC in the 10.x line; that landed in pnpm 11).
  • Bump pnpm 10.8.0 → 10.34.5 (latest 10.x) in the three workflows and in packageManager/devEngines — a toolchain refresh riding along; the OIDC exchange itself happens in the delegated npm CLI.

Verified locally on pnpm 10.34.5: install (frozen lockfile), pnpm -r build, pnpm -r lint, 103/103 tests.

Deployment notes (after merge)

  1. On npmjs.com → mcp-auth → Settings, add a Trusted Publisher: GitHub Actions, organization mcp-auth, repository js, workflow publish.yml, environment blank.
  2. Re-point the v1.0.0-beta.1 tag at the merge commit and push it — the tag push triggers publish.yml, which then publishes via OIDC to the latest dist-tag.
  3. The now-unused NPM_AUTOMATION_TOKEN repository secret can be deleted.

🤖 Generated with Claude Code

Swap the token-based publish (the NPM_AUTOMATION_TOKEN expired and npm
now favors short-lived tokens) for OIDC trusted publishing: npmjs.com
trusts this repository's publish.yml workflow directly, so no npm token
is stored or rotated. Requires pnpm >= 10.20 — bump the toolchain to
the latest 10.x (10.34.5) everywhere it is pinned.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@codecov

codecov Bot commented Aug 31, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Comment thread .github/workflows/publish.yml Outdated
pnpm publish delegates the actual publish to the npm CLI, and npm's
trusted publishing requires npm >= 11.5.1: Node 22 still bundles npm
10.x, Node 24 bundles a compatible npm.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@xiaoyijun
xiaoyijun merged commit 51503b9 into master Aug 31, 2026
5 checks passed
@xiaoyijun
xiaoyijun deleted the xiaoyijun-chore-trusted-publishing branch August 31, 2026 08:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants