Repository navigation
OIDC workflow update - #581
Conversation
Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and keeps publishing with the job's own token. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
chore(release): publish to npm with trusted publishing
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
|
Coverage report for commit: 69e0c6f Summary - Lines: 82.77% | Methods: 95.77% | Branches: 65.89%
🤖 comment via lucassabreu/comment-coverage-clover |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The referenced actions/checkout@v7 and actions/setup-node@v7 versions are unavailable and prevent both jobs from running.
Review effort: Balanced
Findings: None
What changed in this PR
Updates package publishing to use npm OIDC trusted publishing and modern release handling.
Changes:
- Adds separate npmjs and GitHub Packages publishing jobs.
- Uses release tags and supports beta distribution tags.
- Replaces the token-based publishing workflow.
| File | Description |
|---|---|
.github/workflows/release.yml |
Adds OIDC-based npm and GitHub Packages publishing. |
.github/workflows/npm-publish.yml |
Removes the previous token-based workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
No description provided.