diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index eb9022e34..91aa5b12f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -197,12 +197,13 @@ jobs: - name: Verify tarball ships sdk/dist/cli.js (bug #2647) run: bash scripts/verify-tarball-sdk-dist.sh + - name: Ensure npm supports trusted publishing + run: npm install -g npm@latest + - name: Dry-run publish validation run: | npm publish --dry-run --tag next cd sdk && npm publish --dry-run --tag next - env: - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} - name: Tag and push if: ${{ !inputs.dry_run }} @@ -225,15 +226,13 @@ jobs: - name: Publish to npm (next) if: ${{ !inputs.dry_run }} + # --provenance is automatic under OIDC trusted publishing run: npm publish --provenance --access public --tag next - env: - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} - name: Publish SDK to npm (next) if: ${{ !inputs.dry_run }} + # --provenance is automatic under OIDC trusted publishing run: cd sdk && npm publish --provenance --access public --tag next - env: - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} - name: Create GitHub pre-release if: ${{ !inputs.dry_run }} @@ -345,12 +344,13 @@ jobs: - name: Verify tarball ships sdk/dist/cli.js (bug #2647) run: bash scripts/verify-tarball-sdk-dist.sh + - name: Ensure npm supports trusted publishing + run: npm install -g npm@latest + - name: Dry-run publish validation run: | npm publish --dry-run cd sdk && npm publish --dry-run - env: - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} - name: Create PR to merge release back to main if: ${{ !inputs.dry_run }} @@ -403,15 +403,13 @@ jobs: - name: Publish to npm (latest) if: ${{ !inputs.dry_run }} + # --provenance is automatic under OIDC trusted publishing run: npm publish --provenance --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} - name: Publish SDK to npm (latest) if: ${{ !inputs.dry_run }} + # --provenance is automatic under OIDC trusted publishing run: cd sdk && npm publish --provenance --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} - name: Create GitHub Release if: ${{ !inputs.dry_run }} @@ -428,7 +426,6 @@ jobs: if: ${{ !inputs.dry_run }} env: VERSION: ${{ inputs.version }} - NODE_AUTH_TOKEN: ${{ secrets.GETSHITDONEREDUXNPMTOKEN }} run: | # Point next to the stable release so @next never returns something # older than @latest. This prevents stale pre-release installs.