ci: publish to npm via trusted publishing (OIDC) - #466
jason-lafferty-cko wants to merge 2 commits into
Conversation
The release job authenticated with a long-lived NODE_AUTH_TOKEN secret, which npm no longer accepts; the 5.5.0 release failed with a 404 on PUT. The package already has a trusted publisher configured for checkout/checkout-sdk-node, build-release.yml, environment production. - bind the job to the production environment and grant id-token: write - drop NODE_AUTH_TOKEN and publish with --provenance - move to actions/checkout@v4 and setup-node@v4 on Node 22 (v2/v3 run on deprecated Node 20) and upgrade npm to >= 11.5.1
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 1 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
🔵 Advisory review: Sound, but needs your judgementThis PR needs a human approval. The code itself reads as correct; whether it should land depends on context I don't have. The diff correctly migrates npm publish from a long-lived token to OIDC trusted publishing, with all the necessary permissions, environment binding, and npm upgrade in place. The change is technically sound, but going live depends on the npm trusted publisher configuration matching exactly (package name, repo, workflow, environment). For you to decide
This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02 |
🔴 Risk Classification: MAJORApproval route: AI Review + Human Approval Required Classification reasons
Operational gates
Files analysed: 1 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
|
On the advisory points:
|
|



Why
The 5.5.0 release failed in build-release run 36687599619 with
404 Not Found - PUT https://registry.npmjs.org/checkout-sdk-node. That is how npm reports a rejected publish token. The job was still authenticating with the long-livedNODE_AUTH_TOKENsecret, which npm no longer accepts.The package already has a trusted publisher configured on npmjs.com for
checkout/checkout-sdk-node, workflowbuild-release.yml, environmentproduction. The workflow just never moved over to it.What
deployjob to theproductionenvironment and grantid-token: write(pluscontents: writefor the GitHub release step).NODE_AUTH_TOKENand publish withnpm publish --provenance --access public. npm exchanges the GitHub OIDC token with the registry itself.>= 11.5.1, which trusted publishing requires.actions/checkout@v4andactions/setup-node@v4on Node 22. The old pins run on Node 20, which the runners now warn is deprecated.Before merging
productionenvironment must exist on this repo so the OIDC claim matches the trusted publisher.After merging
Re-run the failed 5.5.0 release, or push a package.json change, and confirm 5.5.0 lands on npm with a provenance badge. Once it does, the
NODE_AUTH_TOKENrepo secret can be deleted.🤖 Generated with Claude Code