v1.6.7 - Set OIDC Environment Variables in Current Process
Fixed
- ✅ Set OIDC environment variables in
process.envfor immediate effect - ✅ Environment variables now available to all child processes in current step
- ✅ Fixes npm OIDC auto-detection for nested process chains
Problem with v1.6.6
v1.6.6 used core.exportVariable() to set OIDC environment variables:
core.exportVariable('CI', 'true');
core.exportVariable('ACTIONS_ID_TOKEN_REQUEST_URL', ...);
await exec.exec("pnpm", ["release"], { cwd });However, from the @actions/core documentation:
"Sets env variable for this action and future actions in the job"
This means core.exportVariable() writes to $GITHUB_ENV, which GitHub Actions only applies to subsequent steps, not the current step! When the action immediately runs pnpm release after calling core.exportVariable(), the environment variables haven't been applied yet.
Solution (v1.6.7)
Set environment variables directly in process.env, which makes them immediately available to all child processes:
// Set in current process - immediately available
core.info("Setting OIDC environment variables for npm auto-detection");
process.env.CI = process.env.CI || 'true';
process.env.ACTIONS_ID_TOKEN_REQUEST_URL = process.env.ACTIONS_ID_TOKEN_REQUEST_URL || '';
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN || '';
core.info("OIDC environment variables set for current process and all child processes");
await exec.exec(publishScript, publishArgs, { cwd });Why This Works
Setting process.env directly modifies the environment of the current Node.js process. When child processes are spawned, they automatically inherit all environment variables from process.env.
Comparison:
| Method | Scope | Timing | Child Processes |
|---|---|---|---|
execOptions.env |
Immediate command only | Immediate | ❌ Not inherited by nested children |
core.exportVariable() |
Future steps only | Next step | ❌ Not available in current step |
process.env |
Current process | Immediate | ✅ Inherited by all children |
Process Tree (Now Working)
Node.js Process (changesets-action)
├─ process.env.CI = "true" ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_URL = "..." ← Set here
├─ process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = "..." ← Set here
│
└─ exec.exec("pnpm", ["release"])
└─ pnpm (inherits process.env) ✅
└─ changeset publish (inherits process.env) ✅
└─ npm publish (inherits process.env) ✅
└─ npm detects OIDC from process.env ✅
What Changed
Added:
- Direct
process.envassignment for immediate effect - New log message: "OIDC environment variables set for current process and all child processes"
Removed:
core.exportVariable()calls (affected future steps, not current step)- Log message: "Exporting OIDC environment variables globally"
Usage
- name: Create Release Pull Request or Publish to npm
uses: GarthDB/changesets-action@v1.6.7
with:
publish: pnpm release # or yarn release
oidcAuth: true # Enable OIDC authentication
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
permissions:
id-token: write # Required for OIDC
contents: writeExpected Logs
✅ Using npm OIDC trusted publishing
✅ OIDC environment validated successfully
✅ Setting OIDC environment variables for npm auto-detection
✅ OIDC environment variables set for current process and all child processes
✅ Successfully published @your/package@1.0.0
References
- @actions/core - exportVariable - "Sets env variable for this action and future actions in the job"
- Node.js process.env - Environment variables inherited by child processes
- npm Trusted Publishing
Full Changelog: v1.6.6...v1.6.7