KnownFix 0.3.7: cited npm Trusted Publishing recovery
KnownFix 0.3.7
KnownFix 0.3.7 adds a documented recovery for npm Trusted Publishing jobs that emit misleading ENEEDAUTH or E404 output when the intended OIDC path does not activate.
Added
- New paid fix:
npm-trusted-publishing-eneedauth. - Free diagnosis preview covering npm and Node minimums, hosted-runner requirements, ID-token permission, and exact publisher mapping.
- Authoritative citations and
dateModifiedstructured data on sourced fix pages. - HTTPS-only citation validation in the release verifier and backend tests.
Updated
- npm Publishing Recovery Pack now contains six complete recoveries.
- The first-publish granular-token recovery no longer mentions revoked Classic Automation tokens.
- Paid bundle assembly now includes reference configurations and source citations.
- MCP, OpenAPI, inventory, and discovery metadata report version
0.3.7and 37 stocked fixes.
Verification
- Backend: 88 Deno tests passing plus
deno check. - Storefront: generated-site verifier passes with 37 fixes, 11 free samples, and five recovery packs.
- Desktop and mobile browser checks confirm citations, checkout controls, and the paid-body boundary.
- Live production: 18/18 E2E groups pass across Pages, backend, MCP, signed offers, both payment-proof paths, Base mainnet reads, request privacy, and cited fix pages.
- Distribution: npm and the official MCP Registry both read back
0.3.7as current.
Sources: