chore: publish via npm OIDC trusted publishing - #52
Merged
Merged
Conversation
Swap the token-based publish (the NPM_AUTOMATION_TOKEN expired and npm now favors short-lived tokens) for OIDC trusted publishing: npmjs.com trusts this repository's publish.yml workflow directly, so no npm token is stored or rotated. Requires pnpm >= 10.20 — bump the toolchain to the latest 10.x (10.34.5) everywhere it is pinned. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
charIeszhao
reviewed
Aug 31, 2026
pnpm publish delegates the actual publish to the npm CLI, and npm's trusted publishing requires npm >= 11.5.1: Node 22 still bundles npm 10.x, Node 24 bundles a compatible npm. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
charIeszhao
approved these changes
Aug 31, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
The
v1.0.0-beta.1publish failed withE404onPUT /mcp-auth— npm's disguised authorization error: theNPM_AUTOMATION_TOKENsecret has expired (last successful publish was in January; npm's token policy now favors short-lived credentials). Instead of minting another token that will expire again, switch to npm trusted publishing (OIDC): npmjs.com trusts this repository'spublish.ymlworkflow directly, and no token is stored, rotated, or leaked.Changes
publish.yml: drop theNODE_AUTH_TOKENenv from the publish step — with a trusted publisher configured on npmjs.com,pnpm publishauthenticates through the workflow's OIDC token (id-token: writewas already granted for provenance).pnpm publishdelegates the actual publish to the npm CLI, and npm's trusted publishing requires npm >= 11.5.1 — Node 24 bundles npm 11.19.x, while Node 22 still ships npm 10.9.x (pnpm has no built-in OIDC in the 10.x line; that landed in pnpm 11).10.8.0→10.34.5(latest 10.x) in the three workflows and inpackageManager/devEngines— a toolchain refresh riding along; the OIDC exchange itself happens in the delegated npm CLI.Verified locally on pnpm 10.34.5: install (frozen lockfile),
pnpm -r build,pnpm -r lint, 103/103 tests.Deployment notes (after merge)
mcp-auth→ Settings, add a Trusted Publisher: GitHub Actions, organizationmcp-auth, repositoryjs, workflowpublish.yml, environment blank.v1.0.0-beta.1tag at the merge commit and push it — the tag push triggerspublish.yml, which then publishes via OIDC to thelatestdist-tag.NPM_AUTOMATION_TOKENrepository secret can be deleted.🤖 Generated with Claude Code