Skip to content

chore(publish): OIDC-only tokenless npm publish#20

Merged
drewstone merged 1 commit into
mainfrom
chore/publish-oidc-only
Jun 2, 2026
Merged

chore(publish): OIDC-only tokenless npm publish#20
drewstone merged 1 commit into
mainfrom
chore/publish-oidc-only

Conversation

@drewstone
Copy link
Copy Markdown
Contributor

Mirrors the agent-eval/agent-runtime OIDC fix; supersedes #18 (which added provenance to the dead pnpm token path — pnpm doesn't mint the OIDC credential). npm install -g npm@latest + npm publish --provenance, drop NPM_TOKEN + setup-node registry-url. No workspace deps → npm publish safe. One-time prereq: npmjs Trusted Publisher (org tangle-network, repo agent-knowledge, workflow publish.yml).

Supersedes #18's provenance-on-token-path: pnpm signs provenance but doesn't
mint the OIDC credential, and the NPM_TOKEN is dead. npm install -g npm@latest
+ npm publish --provenance, drop NPM_TOKEN + setup-node registry-url. No
workspace deps so npm publish is safe. Needs the npmjs Trusted Publisher
(org tangle-network, repo agent-knowledge, workflow publish.yml) configured once.
@drewstone drewstone merged commit b45fe70 into main Jun 2, 2026
@drewstone drewstone deleted the chore/publish-oidc-only branch June 2, 2026 12:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant