Skip to content

Publish npm packages via trusted publishing (OIDC) - #283

Merged
chkp-nirm merged 1 commit into
mainfrom
fix/release-npm-trusted-publishing
Oct 4, 2026
Merged

chkp-nirm merged 1 commit into
mainfrom
fix/release-npm-trusted-publishing

Conversation

@chkp-nirm

Copy link
Copy Markdown
Collaborator

Node 22 bundles npm 10.9.x, which cannot use npm trusted publishing, so the publish step fell back to NPM_TOKEN and every package failed with E404.

  • Install npm 11.21.0 (trusted publishing requires >= 11.5.1)
  • Stop passing NPM_TOKEN; changesets/action uses OIDC when no token is set
  • Drop continue-on-error on the publish step: with createGithubReleases false the action pushes no tags, so it only masked publish failures

Node 22 bundles npm 10.9.x, which cannot use npm trusted publishing, so
the publish step fell back to NPM_TOKEN and every package failed with E404.

- Install npm 11.21.0 (trusted publishing requires >= 11.5.1)
- Stop passing NPM_TOKEN; changesets/action uses OIDC when no token is set
- Drop continue-on-error on the publish step: with createGithubReleases
  false the action pushes no tags, so it only masked publish failures

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

@chkp-ilyaro chkp-ilyaro left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@chkp-nirm
chkp-nirm merged commit 431514c into main Oct 4, 2026
1 of 2 checks passed
@chkp-nirm
chkp-nirm deleted the fix/release-npm-trusted-publishing branch October 4, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants