v1.6.6 - Export OIDC Environment Variables Globally
Fixed
- ✅ Export OIDC environment variables globally using
core.exportVariable() - ✅ Ensures environment variables propagate through entire process tree
- ✅ Fixes npm OIDC auto-detection for nested child processes
Root Cause (v1.6.5 Issue)
In v1.6.5, environment variables were only passed to the immediate command via execOptions.env:
execOptions.env = { ...process.env, ACTIONS_ID_TOKEN_REQUEST_URL: ... };
await exec.exec("pnpm", ["release"], execOptions);This meant:
- ✅
pnpm releasehad the variables - ❌
changeset publish(spawned by pnpm) did NOT inherit them - ❌
npm publish(spawned by changeset) did NOT inherit them
Solution (v1.6.6)
Use core.exportVariable() to set variables globally in the GitHub Actions environment:
// Export globally - available to ALL child processes
core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', process.env.ACTIONS_ID_TOKEN_REQUEST_URL);
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_TOKEN', process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN);
await exec.exec("pnpm", ["release"], { cwd });core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions automatically applies to all subsequent commands and their child processes.
What Changed
Added:
- Global export of OIDC environment variables via
core.exportVariable() - New log messages: "Exporting OIDC environment variables globally" and "OIDC environment variables exported for npm auto-detection"
Removed:
- Local
execOptions.envpassing (no longer needed) - Log message "Passing OIDC environment variables to publish command"
Process Tree (Now Working)
GitHub Actions Environment
├─ CI=true (exported globally)
├─ ACTIONS_ID_TOKEN_REQUEST_URL=... (exported globally)
├─ ACTIONS_ID_TOKEN_REQUEST_TOKEN=... (exported globally)
│
└─ changesets-action
└─ pnpm release (inherits env vars) ✅
└─ changeset publish (inherits env vars) ✅
└─ npm publish (inherits env vars) ✅
└─ npm detects OIDC ✅
Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.6
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Exporting OIDC environment variables globally
✅ OIDC environment variables exported for npm auto-detection
✅ Successfully published @your/package@1.0.0
References
Full Changelog: v1.6.5...v1.6.6