Skip to content

v1.6.7 - Set OIDC Environment Variables in Current Process

Choose a tag to compare

@GarthDB GarthDB released this 23 Jan 22:46
· 2 commits to main since this release
0abf64d

Fixed

  • ✅ Set OIDC environment variables in process.env for immediate effect
  • ✅ Environment variables now available to all child processes in current step
  • ✅ Fixes npm OIDC auto-detection for nested process chains

Problem with v1.6.6

v1.6.6 used core.exportVariable() to set OIDC environment variables:

core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', ...);
await exec.exec("pnpm", ["release"], { cwd });

However, from the @actions/core documentation:

"Sets env variable for this action and future actions in the job"

This means core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions only applies to subsequent steps, not the current step! When the action immediately runs pnpm release after calling core.exportVariable(), the environment variables haven't been applied yet.

Solution (v1.6.7)

Set environment variables directly in process.env, which makes them immediately available to all child processes:

// Set in current process - immediately available
core.info("Setting OIDC environment variables for npm auto-detection");
process.env.CI = process.env.CI || 'true';
process.env.ACTIONS_ID_TOKEN_REQUEST_URL = process.env.ACTIONS_ID_TOKEN_REQUEST_URL || '';
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || '';
core.info("OIDC environment variables set for current process and all child processes");

await exec.exec(publishScript, publishArgs, { cwd });

Why This Works

Setting process.env directly modifies the environment of the current Node.js process. When child processes are spawned, they automatically inherit all environment variables from process.env.

Comparison:

Method Scope Timing Child Processes
execOptions.env Immediate command only Immediate ❌ Not inherited by nested children
core.exportVariable() Future steps only Next step ❌ Not available in current step
process.env Current process Immediate ✅ Inherited by all children

Process Tree (Now Working)

Node.js Process (changesets-action)
├─ process.env.CI = "true"                           ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_URL = "..."  ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = "..." ← Set here
│
└─ exec.exec("pnpm", ["release"])
   └─ pnpm (inherits process.env) ✅
      └─ changeset publish (inherits process.env) ✅
         └─ npm publish (inherits process.env) ✅
            └─ npm detects OIDC from process.env ✅

What Changed

Added:

  • Direct process.env assignment for immediate effect
  • New log message: "OIDC environment variables set for current process and all child processes"

Removed:

  • core.exportVariable() calls (affected future steps, not current step)
  • Log message: "Exporting OIDC environment variables globally"

Usage

- name: Create Release Pull Request or Publish to npm
  uses: GarthDB/changesets-action@v1.6.7
  with:
    publish: pnpm release  # or yarn release
    oidcAuth: true  # Enable OIDC authentication
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
  permissions:
    id-token: write  # Required for OIDC
    contents: write

Expected Logs

✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Setting OIDC environment variables for npm auto-detection
✅ OIDC environment variables set for current process and all child processes
✅ Successfully published @your/package@1.0.0

References


Full Changelog: v1.6.6...v1.6.7