-
Notifications
You must be signed in to change notification settings - Fork 1
ci: npm publish via OIDC Trusted Publishing (no token) #25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major
🧩 Analysis chain
🌐 Web query:
What is the minimum npm CLI version required for npm Trusted Publishing with GitHub Actions OIDC, and are there any known caveats for npm 11.x on Node 22?💡 Result:
The minimum npm CLI version required for npm Trusted Publishing with GitHub Actions OIDC is 11.5.1 [1][2][3]. Regarding Node 22 and npm 11.x, there are no inherent incompatibilities between them; rather, the caveat is that Node 22 does not ship with the required npm version (it includes an older npm 10.x version by default) [4]. Consequently, attempting to use Trusted Publishing directly on a default Node 22 environment will fail, often resulting in a misleading "404" error during the publish step [5][4]. To use Trusted Publishing while remaining on Node 22, you must explicitly upgrade the npm CLI within your workflow before running the publish command [5][6][4]: - run: npm install -g npm@latest Alternatively, you can switch to Node 24, which is bundled with a sufficiently recent version of the npm CLI [5][3][4]. Ensure your workflow also includes the required permissions: permissions: id-token: write contents: read Finally, note that Trusted Publishing is only supported on supported cloud providers (such as GitHub-hosted runners) and does not support self-hosted runners [1][6]. Ensure all configuration fields—such as the repository, workflow filename, and environment name—match exactly, as these are case-sensitive and mismatches may also cause authentication failures [1][3][6][4].
Citations:
Pin npm to a deterministic version instead of
latest.Line 32 makes release behavior drift over time; a new npm release can break publishing unexpectedly. The minimum version required for OIDC Trusted Publishing is
11.5.1—pin to this or a validated patch version on that line rather than chasinglatest.Suggested change
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 32-32: ad-hoc installation of packages (adhoc-packages): installs a package outside of a lockfile
(adhoc-packages)
🤖 Prompt for AI Agents
Source: Linters/SAST tools