From ccd47f8d8eb7514c62ceb0899b607ee299546737 Mon Sep 17 00:00:00 2001 From: Anto Subash Date: Thu, 21 May 2026 14:21:49 +0200 Subject: [PATCH 1/2] ci(release): switch npm publish to OIDC Trusted Publishing The NPM_TOKEN secret (granular access token, 30-day default expiry) expired between v0.0.13 and the v0.0.14 attempt, surfacing as 404 PUT errors on all three @simple-module-py/* publishes. Rotating again just restarts the clock. Switch the publish-npm matrix to OIDC, matching the PyPI side: each job mints a short-lived id-token, exchanges it with npm, and publishes without a long-lived secret. Drops the manual .npmrc auth step and the NPM_TOKEN env on the publish step, and pins npm to the latest CLI since Node 24's bundled npm may lag behind the 11.5.1 minimum for OIDC. Requires Trusted Publisher config on each package's npm settings page (org=antosubash, repo=simple_module_python, workflow=release.yml, environment=npm) before the next release run. --- .github/workflows/release.yml | 17 +++++++---------- 1 file changed, 7 insertions(+), 10 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index ac2dbcfb..a002e2a3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -149,6 +149,8 @@ jobs: publish-npm: needs: build runs-on: ubuntu-latest + permissions: + id-token: write # mint OIDC token for npm Trusted Publishing strategy: fail-fast: false matrix: @@ -162,20 +164,15 @@ jobs: - uses: actions/setup-node@v6 with: node-version: ${{ env.NODE_VERSION }} - - name: Configure npm auth - # Write the registry line ourselves so _authToken reads from NPM_TOKEN - # (setup-node's registry-url would hard-code NODE_AUTH_TOKEN instead). - # The backslash escapes the $ so the literal ${NPM_TOKEN} lands in - # .npmrc and is expanded by npm at publish time. - run: echo "//registry.npmjs.org/:_authToken=\${NPM_TOKEN}" > ~/.npmrc + registry-url: 'https://registry.npmjs.org' + - name: Upgrade npm to OIDC-capable version + # Trusted Publishing needs npm >= 11.5.1; Node 24's bundled npm may + # lag. Pin explicitly so publish can't silently fall back to anon. + run: npm install -g npm@latest - name: Publish tarball shell: bash - env: - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} run: | shopt -s nullglob - # `npm pack` on a scoped package writes --.tgz with - # the leading @ stripped and '/' replaced by '-'. files=( dist-npm/simple-module-py-${{ matrix.package }}-*.tgz ) if [ ${#files[@]} -eq 0 ]; then echo "::error::no tarball for @simple-module-py/${{ matrix.package }} in dist-npm/" From 927c9bf7110056b78be422a4c311a609fddf2d04 Mon Sep 17 00:00:00 2001 From: Anto Subash Date: Thu, 21 May 2026 14:33:46 +0200 Subject: [PATCH 2/2] ci(release): apply review feedback to OIDC migration MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Drop `npm install -g npm@latest` — Node 24.15.0 already ships npm 11.12.1 (well above the 11.5.1 floor for Trusted Publishing); the step was ~5-15s of waste per matrix job, and the comment claim that "Node 24's bundled npm may lag" was empirically wrong. - Add `contents: read` to publish-npm's job-level permissions block. Job-level permissions replace (not merge with) workflow-level perms, so the previous block silently set `contents: none` — fine today, but a footgun for any future cache:/checkout: step. - Mirror least-privilege on publish-pypi for symmetry: same OIDC scope, drops the inherited `contents: write` it never needed. - Fix stale top-level comment that still claimed "npm uses NPM_TOKEN". --- .github/workflows/release.yml | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a002e2a3..ec8e11a3 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -15,7 +15,7 @@ on: permissions: contents: write - id-token: write # required for PyPI Trusted Publishing (OIDC); npm uses NPM_TOKEN + id-token: write # OIDC for PyPI and npm Trusted Publishing env: NODE_VERSION: "24" @@ -104,6 +104,8 @@ jobs: publish-pypi: needs: build runs-on: ubuntu-latest + permissions: + id-token: write # mint OIDC token for PyPI Trusted Publishing strategy: fail-fast: false matrix: @@ -150,7 +152,8 @@ jobs: needs: build runs-on: ubuntu-latest permissions: - id-token: write # mint OIDC token for npm Trusted Publishing + contents: read # explicit so future cache:/checkout: steps don't 403 + id-token: write # mint OIDC token for npm Trusted Publishing strategy: fail-fast: false matrix: @@ -165,10 +168,6 @@ jobs: with: node-version: ${{ env.NODE_VERSION }} registry-url: 'https://registry.npmjs.org' - - name: Upgrade npm to OIDC-capable version - # Trusted Publishing needs npm >= 11.5.1; Node 24's bundled npm may - # lag. Pin explicitly so publish can't silently fall back to anon. - run: npm install -g npm@latest - name: Publish tarball shell: bash run: |