chore(ci): adopt npm Trusted Publishers (OIDC) for release workflow (#207) (#208)

Replace long-lived GETSHITDONEREDUXNPMTOKEN secret with short-lived
OIDC tokens via npm Trusted Publishers. Remove NODE_AUTH_TOKEN env
blocks from rc and finalize jobs; add npm install -g npm@latest steps
to guarantee CLI >= 11.5.1 required for OIDC exchange. Trusted
Publisher already configured on npmjs.com for this workflow/environment.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-05-24 01:23:25 -04:00
committed by GitHub
parent b00cae7699
commit fa4bba478b

View File

@@ -197,12 +197,13 @@ jobs:
- name: Verify tarball ships sdk/dist/cli.js (bug #2647)
run: bash scripts/verify-tarball-sdk-dist.sh
- name: Ensure npm supports trusted publishing
run: npm install -g npm@latest
- name: Dry-run publish validation
run: |
npm publish --dry-run --tag next
cd sdk && npm publish --dry-run --tag next
env:
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
- name: Tag and push
if: ${{ !inputs.dry_run }}
@@ -225,15 +226,13 @@ jobs:
- name: Publish to npm (next)
if: ${{ !inputs.dry_run }}
# --provenance is automatic under OIDC trusted publishing
run: npm publish --provenance --access public --tag next
env:
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
- name: Publish SDK to npm (next)
if: ${{ !inputs.dry_run }}
# --provenance is automatic under OIDC trusted publishing
run: cd sdk && npm publish --provenance --access public --tag next
env:
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
- name: Create GitHub pre-release
if: ${{ !inputs.dry_run }}
@@ -345,12 +344,13 @@ jobs:
- name: Verify tarball ships sdk/dist/cli.js (bug #2647)
run: bash scripts/verify-tarball-sdk-dist.sh
- name: Ensure npm supports trusted publishing
run: npm install -g npm@latest
- name: Dry-run publish validation
run: |
npm publish --dry-run
cd sdk && npm publish --dry-run
env:
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
- name: Create PR to merge release back to main
if: ${{ !inputs.dry_run }}
@@ -403,15 +403,13 @@ jobs:
- name: Publish to npm (latest)
if: ${{ !inputs.dry_run }}
# --provenance is automatic under OIDC trusted publishing
run: npm publish --provenance --access public
env:
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
- name: Publish SDK to npm (latest)
if: ${{ !inputs.dry_run }}
# --provenance is automatic under OIDC trusted publishing
run: cd sdk && npm publish --provenance --access public
env:
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
- name: Create GitHub Release
if: ${{ !inputs.dry_run }}
@@ -428,7 +426,6 @@ jobs:
if: ${{ !inputs.dry_run }}
env:
VERSION: ${{ inputs.version }}
NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }}
run: |
# Point next to the stable release so @next never returns something
# older than @latest. This prevents stale pre-release installs.