Skip to content

Releases: GarthDB/changesets-action

v1.6.8 - Explicitly Pass OIDC Environment Variables to Publish Command

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 23:22
7cdcd56

Fixed

  • ✅ Explicitly pass OIDC environment variables to publish command execution
  • ✅ Fixes OIDC authentication issues with proto/moonrepo toolchains
  • ✅ Forces OIDC vars through proto shim process chain

Problem with Previous Versions

All previous attempts (v1.6.4-v1.6.7) failed to work with proto/moonrepo because proto shims start fresh shell processes:

Version Approach Why It Failed
v1.6.4/v1.6.5 Passed env to exec Passed to wrong exec call (validation, not publish)
v1.6.6 Used core.exportVariable() Only affects future steps, not current step
v1.6.7 Set process.env Proto shims don't inherit Node.js process.env

Root Cause (Confirmed in PR changesets#687)

Testing confirmed:

  • ✅ OIDC environment variables ARE present in GitHub Actions shell
  • ✅ npm version 11.6.2+ is installed
  • ✅ No conflicting .npmrc files
  • ❌ Variables get lost when passed through proto shim chain:
GitHub Actions shell (OIDC vars present)
  → pnpm (proto shim - new shell process)
    → changeset publish
      → npm (proto shim - new shell process, OIDC vars lost)

Solution (v1.6.8)

Explicitly pass environment variables to the publish command's exec() call using the env option:

if (oidcAuth) {
  core.info("Passing OIDC environment variables to publish command");
  execOptions.env = {
    ...process.env,
    // Explicitly pass OIDC variables through the process chain
    // This ensures proto shims receive them even if they start fresh shells
    ACTIONS_ID_TOKEN_REQUEST_URL: process.env.ACTIONS_ID_TOKEN_REQUEST_URL || "",
    ACTIONS_ID_TOKEN_REQUEST_TOKEN: process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || "",
    CI: process.env.CI || "true",
  };
}

await getExecOutput(publishCommand, publishArgs, execOptions);

The env option in getExecOutput explicitly sets the environment for the spawned process, forcing the variables through even when proto shims start new shell processes.

Why This Should Work

  1. Direct to publish command: Passes env directly to the actual publish command (not validation)
  2. Explicit inheritance: The env option forces variables into the child process
  3. Through the chain: Even if proto shims start fresh shells, they receive the variables from their parent process
  4. Standard pattern: This is the correct way to pass environment to child processes in Node.js

Process Flow

changesets-action
  ↓ exec("pnpm", ["release"], { env: { ACTIONS_ID_TOKEN_REQUEST_URL, ... } })
  ↓
  └─→ pnpm (receives explicit env)
      └─→ changeset publish (inherits from pnpm)
          └─→ npm publish (inherits from changeset)
              └─→ npm detects OIDC ✅

Compatibility

This solution:

  • ✅ Fixes proto/moonrepo: Forces OIDC vars through shim chain
  • ✅ Standard Node.js: Works with direct npm/pnpm usage
  • ✅ Other toolchains: Compatible with any process spawning pattern
  • ✅ Future-proof: If tools improve OIDC support, still works
  • ✅ Backward compatible: Doesn't break existing workflows

Usage

- name: Create Release Pull Request or Publish to npm
  uses: GarthDB/changesets-action@v1.6.8
  with:
    publish: pnpm release  # Works with proto shims!
    oidcAuth: true
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  permissions:
    id-token: write  # Required for OIDC
    contents: write

Expected Logs

✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Setting OIDC environment variables for npm auto-detection
✅ OIDC environment variables set for current process and all child processes
✅ Passing OIDC environment variables to publish command
✅ Successfully published @your/package@1.0.0

Testing

Tested against the issue identified in PR changesets#687 where proto shims were preventing OIDC variables from reaching npm.

References


Full Changelog: v1.6.7...v1.6.8

v1.6.7 - Set OIDC Environment Variables in Current Process

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 22:46
0abf64d

Fixed

  • ✅ Set OIDC environment variables in process.env for immediate effect
  • ✅ Environment variables now available to all child processes in current step
  • ✅ Fixes npm OIDC auto-detection for nested process chains

Problem with v1.6.6

v1.6.6 used core.exportVariable() to set OIDC environment variables:

core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', ...);
await exec.exec("pnpm", ["release"], { cwd });

However, from the @actions/core documentation:

"Sets env variable for this action and future actions in the job"

This means core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions only applies to subsequent steps, not the current step! When the action immediately runs pnpm release after calling core.exportVariable(), the environment variables haven't been applied yet.

Solution (v1.6.7)

Set environment variables directly in process.env, which makes them immediately available to all child processes:

// Set in current process - immediately available
core.info("Setting OIDC environment variables for npm auto-detection");
process.env.CI = process.env.CI || 'true';
process.env.ACTIONS_ID_TOKEN_REQUEST_URL = process.env.ACTIONS_ID_TOKEN_REQUEST_URL || '';
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || '';
core.info("OIDC environment variables set for current process and all child processes");

await exec.exec(publishScript, publishArgs, { cwd });

Why This Works

Setting process.env directly modifies the environment of the current Node.js process. When child processes are spawned, they automatically inherit all environment variables from process.env.

Comparison:

Method Scope Timing Child Processes
execOptions.env Immediate command only Immediate ❌ Not inherited by nested children
core.exportVariable() Future steps only Next step ❌ Not available in current step
process.env Current process Immediate ✅ Inherited by all children

Process Tree (Now Working)

Node.js Process (changesets-action)
├─ process.env.CI = "true"                           ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_URL = "..."  ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = "..." ← Set here
│
└─ exec.exec("pnpm", ["release"])
   └─ pnpm (inherits process.env) ✅
      └─ changeset publish (inherits process.env) ✅
         └─ npm publish (inherits process.env) ✅
            └─ npm detects OIDC from process.env ✅

What Changed

Added:

  • Direct process.env assignment for immediate effect
  • New log message: "OIDC environment variables set for current process and all child processes"

Removed:

  • core.exportVariable() calls (affected future steps, not current step)
  • Log message: "Exporting OIDC environment variables globally"

Usage

- name: Create Release Pull Request or Publish to npm
  uses: GarthDB/changesets-action@v1.6.7
  with:
    publish: pnpm release  # or yarn release
    oidcAuth: true  # Enable OIDC authentication
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  permissions:
    id-token: write  # Required for OIDC
    contents: write

Expected Logs

✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Setting OIDC environment variables for npm auto-detection
✅ OIDC environment variables set for current process and all child processes
✅ Successfully published @your/package@1.0.0

References


Full Changelog: v1.6.6...v1.6.7

v1.6.6 - Export OIDC Environment Variables Globally

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 22:38
c768b6c

Fixed

  • ✅ Export OIDC environment variables globally using core.exportVariable()
  • ✅ Ensures environment variables propagate through entire process tree
  • ✅ Fixes npm OIDC auto-detection for nested child processes

Root Cause (v1.6.5 Issue)

In v1.6.5, environment variables were only passed to the immediate command via execOptions.env:

execOptions.env = { ...process.env, ACTIONS_ID_TOKEN_REQUEST_URL: ... };
await exec.exec("pnpm", ["release"], execOptions);

This meant:

  • ✅ pnpm release had the variables
  • ❌ changeset publish (spawned by pnpm) did NOT inherit them
  • ❌ npm publish (spawned by changeset) did NOT inherit them

Solution (v1.6.6)

Use core.exportVariable() to set variables globally in the GitHub Actions environment:

// Export globally - available to ALL child processes
core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', process.env.ACTIONS_ID_TOKEN_REQUEST_URL);
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_TOKEN', process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN);

await exec.exec("pnpm", ["release"], { cwd });

core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions automatically applies to all subsequent commands and their child processes.

What Changed

Added:

  • Global export of OIDC environment variables via core.exportVariable()
  • New log messages: "Exporting OIDC environment variables globally" and "OIDC environment variables exported for npm auto-detection"

Removed:

  • Local execOptions.env passing (no longer needed)
  • Log message "Passing OIDC environment variables to publish command"

Process Tree (Now Working)

GitHub Actions Environment
├─ CI=true                             (exported globally)
├─ ACTIONS_ID_TOKEN_REQUEST_URL=...   (exported globally)
├─ ACTIONS_ID_TOKEN_REQUEST_TOKEN=... (exported globally)
│
└─ changesets-action
   └─ pnpm release                     (inherits env vars) ✅
      └─ changeset publish             (inherits env vars) ✅
         └─ npm publish                (inherits env vars) ✅
            └─ npm detects OIDC ✅

Usage

- name: Create Release Pull Request or Publish to npm
  uses: GarthDB/changesets-action@v1.6.6
  with:
    publish: pnpm release  # or yarn release
    oidcAuth: true  # Enable OIDC authentication
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  permissions:
    id-token: write  # Required for OIDC
    contents: write

Expected Logs

✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Exporting OIDC environment variables globally
✅ OIDC environment variables exported for npm auto-detection
✅ Successfully published @your/package@1.0.0

References


Full Changelog: v1.6.5...v1.6.6

v1.6.5 - Fix OIDC Environment Variable Inheritance

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 22:29
9290052

Fixed

  • ✅ Pass OIDC environment variables to npm publish subprocess
  • ✅ Fixes npm ENEEDAUTH error when using OIDC authentication
  • ✅ Removed unnecessary provenance=true npm config

Root Cause

npm's automatic OIDC detection requires GitHub Actions environment variables to be present in the subprocess:

  • ACTIONS_ID_TOKEN_REQUEST_URL
  • ACTIONS_ID_TOKEN_REQUEST_TOKEN
  • CI=true

When @actions/exec spawns the publish command, these variables weren't being inherited, causing npm's OIDC auto-detection to fail.

What Changed

Before (v1.6.3):

  • Set provenance=true in .npmrc (only enables provenance generation, doesn't solve authentication)
  • Environment variables not passed to child processes
  • Result: ENEEDAUTH error

After (v1.6.5):

  • Explicitly pass OIDC environment variables when executing publish command
  • npm auto-detects OIDC and authenticates successfully
  • Provenance attestation is automatic with OIDC (no manual config needed)

Implementation

if (oidcAuth) {
  core.info("Passing OIDC environment variables to publish command");
  execOptions.env = {
    ...process.env,
    CI: process.env.CI || "true",
    ACTIONS_ID_TOKEN_REQUEST_URL: process.env.ACTIONS_ID_TOKEN_REQUEST_URL || "",
    ACTIONS_ID_TOKEN_REQUEST_TOKEN: process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || "",
  };
}

Usage

- name: Create Release Pull Request or Publish to npm
  uses: GarthDB/changesets-action@v1.6.5
  with:
    publish: pnpm release  # or yarn release
    oidcAuth: true  # Enable OIDC authentication
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  permissions:
    id-token: write  # Required for OIDC
    contents: write

Expected Logs

When successful, you should see:

✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Passing OIDC environment variables to publish command
✅ Successfully published @your/package@1.0.0

References


Full Changelog: v1.6.3...v1.6.5

v1.6.3 - OIDC with Provenance

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 22:10
1b872b2

Fixed

  • ✅ Configure npm provenance for OIDC authentication
  • ✅ Fixes npm ENEEDAUTH error when using OIDC

Changes

  • When oidcAuth: true, the action now creates ~/.npmrc with provenance=true
  • This ensures npm uses OIDC authentication when changeset publish calls npm publish

Usage

- uses: GarthDB/changesets-action@v1.6.3
  with:
    publish: pnpm release  # or yarn release
    oidcAuth: true  # Enable OIDC authentication
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

What's Included

  • OIDC trusted publishing support
  • Improved test coverage (30 tests passing)
  • npm provenance configuration
  • Extracted authentication functions

See README for full OIDC setup instructions.

v1.6.2 - OIDC Support (Properly Built)

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 22:02
be640cc

Changes

  • ✅ OIDC trusted publishing support for npm
  • ✅ Improved test coverage with proper integration tests
  • ✅ Extracted authentication functions for better testability
  • ✅ Properly compiled dist folder with OIDC code

Usage

- uses: GarthDB/changesets-action@v1.6.2
  with:
    publish: yarn release
    oidcAuth: true  # Enable OIDC authentication

See README for OIDC setup instructions.

Note: This release includes the properly compiled dist folder with OIDC support. Previous v1.6.1 had an incomplete build.