Skip to content

Add trusted npm publishing workflow - #645

Merged
millenbop merged 1 commit into
mainfrom
npm-trusted-publishing
Sep 29, 2026
Merged

millenbop merged 1 commit into
mainfrom
npm-trusted-publishing

Conversation

@millenbop

Copy link
Copy Markdown
Member

Motivation

Move npm releases to Trusted Publishing so packages can be published through GitHub Actions using short-lived OIDC credentials instead of personal npm accounts or long-lived tokens.

Have you read the Contributing Guidelines?

Yes.

Contribution

Adds a manually triggered npm publishing workflow that:

  • Publishes a specified release tag using OIDC.
  • Verifies the tag matches the version in package.json.
  • Verifies the tagged commit is on main.
  • Publishes prereleases with the next npm tag and stable releases with latest.
  • Prevents alpha releases from being published.
  • Runs the test suite before publishing.
  • Publishes with npm provenance.

Test Plan

  • Parsed publish.yml successfully as YAML.
  • Ran git diff --check.
  • Validated the release logic against v5.0.0-beta.6.
  • Confirmed it resolves version 5.0.0-beta.6 to the npm tag next.
  • Confirmed the release tag points to the expected commit on main.

The publishing job cannot be exercised until this workflow is merged and registered as the package’s npm Trusted Publisher.

@meta-cla meta-cla Bot added the cla signed label Sep 29, 2026
@millenbop
millenbop merged commit 519977e into main Sep 29, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants