Releases: GarthDB/changesets-action
Release list
v1.6.8 - Explicitly Pass OIDC Environment Variables to Publish Command
Fixed
- ✅ Explicitly pass OIDC environment variables to publish command execution
- ✅ Fixes OIDC authentication issues with proto/moonrepo toolchains
- ✅ Forces OIDC vars through proto shim process chain
Problem with Previous Versions
All previous attempts (v1.6.4-v1.6.7) failed to work with proto/moonrepo because proto shims start fresh shell processes:
| Version | Approach | Why It Failed |
|---|---|---|
| v1.6.4/v1.6.5 | Passed env to exec |
Passed to wrong exec call (validation, not publish) |
| v1.6.6 | Used core.exportVariable() |
Only affects future steps, not current step |
| v1.6.7 | Set process.env |
Proto shims don't inherit Node.js process.env |
Root Cause (Confirmed in PR changesets#687)
Testing confirmed:
- ✅ OIDC environment variables ARE present in GitHub Actions shell
- ✅ npm version 11.6.2+ is installed
- ✅ No conflicting
.npmrcfiles - ❌ Variables get lost when passed through proto shim chain:
GitHub Actions shell (OIDC vars present)
→ pnpm (proto shim - new shell process)
→ changeset publish
→ npm (proto shim - new shell process, OIDC vars lost)
Solution (v1.6.8)
Explicitly pass environment variables to the publish command's exec() call using the env option:
if (oidcAuth) {
core.info("Passing OIDC environment variables to publish command");
execOptions.env = {
...process.env,
// Explicitly pass OIDC variables through the process chain
// This ensures proto shims receive them even if they start fresh shells
ACTIONS_ID_TOKEN_REQUEST_URL: process.env.ACTIONS_ID_TOKEN_REQUEST_URL || "",
ACTIONS_ID_TOKEN_REQUEST_TOKEN: process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || "",
CI: process.env.CI || "true",
};
}
await getExecOutput(publishCommand, publishArgs, execOptions);The env option in getExecOutput explicitly sets the environment for the spawned process, forcing the variables through even when proto shims start new shell processes.
Why This Should Work
- Direct to publish command: Passes env directly to the actual publish command (not validation)
- Explicit inheritance: The
envoption forces variables into the child process - Through the chain: Even if proto shims start fresh shells, they receive the variables from their parent process
- Standard pattern: This is the correct way to pass environment to child processes in Node.js
Process Flow
changesets-action
↓ exec("pnpm", ["release"], { env: { ACTIONS_ID_TOKEN_REQUEST_URL, ... } })
↓
└─→ pnpm (receives explicit env)
└─→ changeset publish (inherits from pnpm)
└─→ npm publish (inherits from changeset)
└─→ npm detects OIDC ✅
Compatibility
This solution:
- ✅ Fixes proto/moonrepo: Forces OIDC vars through shim chain
- ✅ Standard Node.js: Works with direct npm/pnpm usage
- ✅ Other toolchains: Compatible with any process spawning pattern
- ✅ Future-proof: If tools improve OIDC support, still works
- ✅ Backward compatible: Doesn't break existing workflows
Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.8
with:
publish: pnpm release # Works with proto shims!
oidcAuth: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Setting OIDC environment variables for npm auto-detection
✅ OIDC environment variables set for current process and all child processes
✅ Passing OIDC environment variables to publish command
✅ Successfully published @your/package@1.0.0
Testing
Tested against the issue identified in PR changesets#687 where proto shims were preventing OIDC variables from reaching npm.
References
- PR changesets#687: Confirmed OIDC vars present but lost through proto shims
- npm Trusted Publishing
- @actions/exec documentation
- proto/moonrepo
Full Changelog: v1.6.7...v1.6.8
v1.6.7 - Set OIDC Environment Variables in Current Process
Fixed
- ✅ Set OIDC environment variables in
process.envfor immediate effect - ✅ Environment variables now available to all child processes in current step
- ✅ Fixes npm OIDC auto-detection for nested process chains
Problem with v1.6.6
v1.6.6 used core.exportVariable() to set OIDC environment variables:
core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', ...);
await exec.exec("pnpm", ["release"], { cwd });However, from the @actions/core documentation:
"Sets env variable for this action and future actions in the job"
This means core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions only applies to subsequent steps, not the current step! When the action immediately runs pnpm release after calling core.exportVariable(), the environment variables haven't been applied yet.
Solution (v1.6.7)
Set environment variables directly in process.env, which makes them immediately available to all child processes:
// Set in current process - immediately available
core.info("Setting OIDC environment variables for npm auto-detection");
process.env.CI = process.env.CI || 'true';
process.env.ACTIONS_ID_TOKEN_REQUEST_URL = process.env.ACTIONS_ID_TOKEN_REQUEST_URL || '';
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || '';
core.info("OIDC environment variables set for current process and all child processes");
await exec.exec(publishScript, publishArgs, { cwd });Why This Works
Setting process.env directly modifies the environment of the current Node.js process. When child processes are spawned, they automatically inherit all environment variables from process.env.
Comparison:
| Method | Scope | Timing | Child Processes |
|---|---|---|---|
execOptions.env |
Immediate command only | Immediate | ❌ Not inherited by nested children |
core.exportVariable() |
Future steps only | Next step | ❌ Not available in current step |
process.env |
Current process | Immediate | ✅ Inherited by all children |
Process Tree (Now Working)
Node.js Process (changesets-action)
├─ process.env.CI = "true" ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_URL = "..." ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = "..." ← Set here
│
└─ exec.exec("pnpm", ["release"])
└─ pnpm (inherits process.env) ✅
└─ changeset publish (inherits process.env) ✅
└─ npm publish (inherits process.env) ✅
└─ npm detects OIDC from process.env ✅
What Changed
Added:
- Direct
process.envassignment for immediate effect - New log message: "OIDC environment variables set for current process and all child processes"
Removed:
core.exportVariable()calls (affected future steps, not current step)- Log message: "Exporting OIDC environment variables globally"
Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.7
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Setting OIDC environment variables for npm auto-detection
✅ OIDC environment variables set for current process and all child processes
✅ Successfully published @your/package@1.0.0
References
- @actions/core - exportVariable - "Sets env variable for this action and future actions in the job"
- Node.js process.env - Environment variables inherited by child processes
- npm Trusted Publishing
Full Changelog: v1.6.6...v1.6.7
v1.6.6 - Export OIDC Environment Variables Globally
Fixed
- ✅ Export OIDC environment variables globally using
core.exportVariable() - ✅ Ensures environment variables propagate through entire process tree
- ✅ Fixes npm OIDC auto-detection for nested child processes
Root Cause (v1.6.5 Issue)
In v1.6.5, environment variables were only passed to the immediate command via execOptions.env:
execOptions.env = { ...process.env, ACTIONS_ID_TOKEN_REQUEST_URL: ... };
await exec.exec("pnpm", ["release"], execOptions);This meant:
- ✅
pnpm releasehad the variables - ❌
changeset publish(spawned by pnpm) did NOT inherit them - ❌
npm publish(spawned by changeset) did NOT inherit them
Solution (v1.6.6)
Use core.exportVariable() to set variables globally in the GitHub Actions environment:
// Export globally - available to ALL child processes
core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', process.env.ACTIONS_ID_TOKEN_REQUEST_URL);
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_TOKEN', process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN);
await exec.exec("pnpm", ["release"], { cwd });core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions automatically applies to all subsequent commands and their child processes.
What Changed
Added:
- Global export of OIDC environment variables via
core.exportVariable() - New log messages: "Exporting OIDC environment variables globally" and "OIDC environment variables exported for npm auto-detection"
Removed:
- Local
execOptions.envpassing (no longer needed) - Log message "Passing OIDC environment variables to publish command"
Process Tree (Now Working)
GitHub Actions Environment
├─ CI=true (exported globally)
├─ ACTIONS_ID_TOKEN_REQUEST_URL=... (exported globally)
├─ ACTIONS_ID_TOKEN_REQUEST_TOKEN=... (exported globally)
│
└─ changesets-action
└─ pnpm release (inherits env vars) ✅
└─ changeset publish (inherits env vars) ✅
└─ npm publish (inherits env vars) ✅
└─ npm detects OIDC ✅
Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.6
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Exporting OIDC environment variables globally
✅ OIDC environment variables exported for npm auto-detection
✅ Successfully published @your/package@1.0.0
References
Full Changelog: v1.6.5...v1.6.6
v1.6.5 - Fix OIDC Environment Variable Inheritance
Fixed
- ✅ Pass OIDC environment variables to npm publish subprocess
- ✅ Fixes npm ENEEDAUTH error when using OIDC authentication
- ✅ Removed unnecessary
provenance=truenpm config
Root Cause
npm's automatic OIDC detection requires GitHub Actions environment variables to be present in the subprocess:
ACTIONS_ID_TOKEN_REQUEST_URLACTIONS_ID_TOKEN_REQUEST_TOKENCI=true
When @actions/exec spawns the publish command, these variables weren't being inherited, causing npm's OIDC auto-detection to fail.
What Changed
Before (v1.6.3):
- Set
provenance=truein.npmrc(only enables provenance generation, doesn't solve authentication) - Environment variables not passed to child processes
- Result:
ENEEDAUTHerror
After (v1.6.5):
- Explicitly pass OIDC environment variables when executing publish command
- npm auto-detects OIDC and authenticates successfully
- Provenance attestation is automatic with OIDC (no manual config needed)
Implementation
if (oidcAuth) {
core.info("Passing OIDC environment variables to publish command");
execOptions.env = {
...process.env,
CI: process.env.CI || "true",
ACTIONS_ID_TOKEN_REQUEST_URL: process.env.ACTIONS_ID_TOKEN_REQUEST_URL || "",
ACTIONS_ID_TOKEN_REQUEST_TOKEN: process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || "",
};
}Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.5
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
When successful, you should see:
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Passing OIDC environment variables to publish command
✅ Successfully published @your/package@1.0.0
References
Full Changelog: v1.6.3...v1.6.5
v1.6.3 - OIDC with Provenance
Fixed
- ✅ Configure npm provenance for OIDC authentication
- ✅ Fixes npm ENEEDAUTH error when using OIDC
Changes
- When
oidcAuth: true, the action now creates~/.npmrcwithprovenance=true - This ensures npm uses OIDC authentication when changeset publish calls npm publish
Usage
- uses: GarthDB/changesets-action@v1.6.3
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}What's Included
- OIDC trusted publishing support
- Improved test coverage (30 tests passing)
- npm provenance configuration
- Extracted authentication functions
See README for full OIDC setup instructions.
v1.6.2 - OIDC Support (Properly Built)
Changes
- ✅ OIDC trusted publishing support for npm
- ✅ Improved test coverage with proper integration tests
- ✅ Extracted authentication functions for better testability
- ✅ Properly compiled dist folder with OIDC code
Usage
- uses: GarthDB/changesets-action@v1.6.2
with:
publish: yarn release
oidcAuth: true # Enable OIDC authenticationSee README for OIDC setup instructions.
Note: This release includes the properly compiled dist folder with OIDC support. Previous v1.6.1 had an incomplete build.