Repository navigation
v1.6.5 - Fix OIDC Environment Variable Inheritance
Fixed
- ✅ Pass OIDC environment variables to npm publish subprocess
- ✅ Fixes npm ENEEDAUTH error when using OIDC authentication
- ✅ Removed unnecessary
provenance=truenpm config
Root Cause
npm's automatic OIDC detection requires GitHub Actions environment variables to be present in the subprocess:
ACTIONS_ID_TOKEN_REQUEST_URLACTIONS_ID_TOKEN_REQUEST_TOKENCI=true
When @actions/exec spawns the publish command, these variables weren't being inherited, causing npm's OIDC auto-detection to fail.
What Changed
Before (v1.6.3):
- Set
provenance=truein.npmrc(only enables provenance generation, doesn't solve authentication) - Environment variables not passed to child processes
- Result:
ENEEDAUTHerror
After (v1.6.5):
- Explicitly pass OIDC environment variables when executing publish command
- npm auto-detects OIDC and authenticates successfully
- Provenance attestation is automatic with OIDC (no manual config needed)
Implementation
if (oidcAuth) {
core.info("Passing OIDC environment variables to publish command");
execOptions.env = {
...process.env,
CI: process.env.CI || "true",
ACTIONS_ID_TOKEN_REQUEST_URL: process.env.ACTIONS_ID_TOKEN_REQUEST_URL || "",
ACTIONS_ID_TOKEN_REQUEST_TOKEN: process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || "",
};
}Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.5
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
When successful, you should see:
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Passing OIDC environment variables to publish command
✅ Successfully published @your/package@1.0.0
References
Full Changelog: v1.6.3...v1.6.5