Skip to content

ci: publish with NPM_TOKEN again - #312

Merged
ralyodio merged 1 commit into
mainfrom
ci/npm-token-final
Aug 6, 2026
Merged

ci: publish with NPM_TOKEN again#312
ralyodio merged 1 commit into
mainfrom
ci/npm-token-final

Conversation

@ralyodio

@ralyodio ralyodio commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Back to the stored-token path, which demonstrably works — v0.24.2 published this way with a provenance attestation.

What the two OIDC attempts established

attempt error meaning
#309 (v0.24.3 release) E404 on PUT no credential; npm never attempted the exchange
#311 (dispatch, registry-url removed) ENEEDAUTH npm found no credential and refused to try

The second attempt was worth making: it found a genuine bug in this workflow — setup-node's registry-url writes //registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}, which under OIDC resolves to an empty credential and stops npm attempting the exchange (actions/setup-node#1551). But fixing it only moved the error, so the npmjs.com registration remains unconfirmed — and nothing in this repo can check or set it.

The trap, now written down

registry-url is required for token auth and fatal for OIDC. That asymmetry is the whole trick, and it's now documented in the header and at the step it applies to, so a future switch starts by deleting the right line.

Also

Noted, deliberately not fixed here

Every publish logs "bin[moshcode]" script name bin/moshcode.mjs was invalid and removed. It sounds fatal and isn't — npm strips the ./ prefix from the bin values, and both 0.24.0 and 0.24.2 published with working bins (verified against the registry). Dropping the ./ in package.json would silence it, but that would change package.json after v0.24.3 was tagged, and publishing content that differs from its tag is what #308 went out of its way to avoid.

Next

Main is at 0.24.3 and unpublished, so a dispatch finishes it — no new release needed.

🤖 Generated with Claude Code

Two OIDC attempts, two failures with npm reporting no credential at all. The
second one was worth it — it found a real bug in this file, where setup-node's
`registry-url` left an empty auth token that stopped npm attempting the
exchange — but fixing that only moved the error from E404 to ENEEDAUTH. The
npmjs.com registration remains unconfirmed, and it is not something this
repository can check or set.

So: back to the path that demonstrably works. v0.24.2 published this way, with
a provenance attestation.

Carrying forward what the attempts taught, in the header and at the step:
`registry-url` is required for token auth and fatal for OIDC. That asymmetry is
the whole trap, and it is now written down next to the line it applies to.

Keeps node 24 from #311 — unrelated to auth, and the tests pass on it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

92 finding(s)

HIGH/CRITICAL: 50 | MEDIUM: 42

Severity Rule Location
HIGH manifest-typosquat apps/pwa/package.json:19
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH secret-generic-credential apps/pwa/test/apikey-bearer-scheme.test.mjs:30
HIGH secret-generic-credential apps/pwa/test/apikey-mask.test.mjs:38
HIGH secret-generic-credential apps/pwa/test/apikey-reveal.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/approvals-context.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/approvals-credits.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/approvals-notify.test.mjs:26
HIGH secret-generic-credential apps/pwa/test/approvals-resolve-race.test.mjs:20
HIGH secret-generic-credential apps/pwa/test/auth-form-email.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/auth-form-email.test.mjs:33
HIGH secret-generic-credential apps/pwa/test/auth-page-error.test.mjs:36
HIGH secret-generic-credential apps/pwa/test/cli-device-token.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/cli-pages-balance.test.mjs:32
HIGH secret-generic-credential apps/pwa/test/cli-token.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/credits-pack.test.mjs:51
HIGH secret-generic-credential apps/pwa/test/credits-webhook-event-match.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/credits-webhook.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/csrf-input-escaping.test.mjs:31
HIGH secret-generic-credential apps/pwa/test/csrf-input-escaping.test.mjs:101
HIGH secret-generic-credential apps/pwa/test/logout-csrf.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/moshpit-api-key.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-bulk-claim.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-claim-full-name.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/moshpit-crawlable.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-ending-page.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-pins.test.mjs:22
HIGH secret-generic-credential apps/pwa/test/moshpit-pit-page.test.mjs:33
HIGH secret-generic-credential apps/pwa/test/moshpit-records-page.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-records.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-registry.test.mjs:20
HIGH secret-generic-credential apps/pwa/test/moshpit-related-endings.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-sales.test.mjs:16
HIGH secret-generic-credential apps/pwa/test/moshpit-search.test.mjs:74
HIGH secret-generic-credential apps/pwa/test/moshpit-terms.test.mjs:19
HIGH secret-generic-credential apps/pwa/test/moshpit-tlds-pagination.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/passkey-register-duplicate.test.mjs:38
HIGH secret-generic-credential apps/pwa/test/require-auth-next.test.mjs:31
HIGH secret-generic-credential apps/pwa/test/require-auth-next.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/sessions-output-seq.test.mjs:30
HIGH secret-generic-credential apps/pwa/test/sessions-paste.test.mjs:24
HIGH secret-generic-credential apps/pwa/test/sessions-stream-replay.test.mjs:34
HIGH secret-generic-credential apps/pwa/test/sessions.test.mjs:24
HIGH secret-generic-credential apps/pwa/test/signature.test.mjs:6
HIGH secret-generic-credential test/auth.test.mjs:13
HIGH secret-generic-credential test/auth.test.mjs:63
HIGH secret-generic-credential test/console-cookie-malformed.test.mjs:15
HIGH secret-generic-credential test/console.test.mjs:12
HIGH secret-generic-credential test/mirror.test.mjs:37
HIGH secret-generic-credential test/mirror.test.mjs:77

…and 42 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 4b41c08 into main Aug 6, 2026
4 checks passed
@ralyodio
ralyodio deleted the ci/npm-token-final branch August 6, 2026 05:42
@ralyodio ralyodio mentioned this pull request Aug 6, 2026
ralyodio added a commit that referenced this pull request Aug 6, 2026
Bump to v0.25.0, releasing machine-readable account status via moshcode whoami --json (#302), plus the bin path cleanup (#313) and publish workflow changes (#311, #312).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant