Skip to content

ci: publish to npm with trusted publishing - #30

Merged
Jackardios merged 1 commit into
mainfrom
ci/trusted-publishing
Sep 26, 2026
Merged

Jackardios merged 1 commit into
mainfrom
ci/trusted-publishing

Conversation

@Jackardios

Copy link
Copy Markdown
Owner

Releases fail because NPM_TOKEN is no longer valid (#29). This switches publishing to npm trusted publishing (OIDC), so no npm token is needed.

  • The release job runs in this repository instead of the reusable workflow from ryansonshine/ryansonshine@main. Actions are pinned to commit SHAs.
  • The job gets id-token: write. NPM_TOKEN is removed.
  • semantic-release is updated to v25. @semantic-release/npm supports OIDC since v13.1.0.
  • repository.url uses the exact case of the repository (Jackardios). npm compares it case-sensitively.

The trusted publisher is already configured on npmjs.com for Jackardios/css-to-tailwindcss and release.yml.

Checked locally: npm ci, build and tests pass. semantic-release --dry-run with the current config finds the next version 1.0.6 (#27, #24).

- run the release job in this repository instead of the reusable workflow from ryansonshine/ryansonshine@main,
  with actions pinned to commit SHAs
- authenticate to npm with OIDC (`id-token: write`) instead of `NPM_TOKEN`
- update semantic-release to v25: OIDC publishing is supported by @semantic-release/npm since v13.1.0
- use the exact case of the GitHub repository in `repository.url`, npm compares it case-sensitively
@Jackardios
Jackardios merged commit 4e25e0e into main Sep 26, 2026
2 checks passed
@github-actions

Copy link
Copy Markdown

🎉 This PR is included in version 1.0.6 🎉

The release is available on:

Your semantic-release bot 📦🚀

@Jackardios
Jackardios deleted the ci/trusted-publishing branch September 27, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant