ci: use OIDC for nightly npm publish (drop NPMJS_TOKEN)#1048
Open
ci: use OIDC for nightly npm publish (drop NPMJS_TOKEN)#1048
Conversation
Remove NODE_AUTH_TOKEN from the nightly job so npm/pnpm use the same trusted publishing path as tag releases. NPMJS_TOKEN is no longer required for nightly when GitHub Actions OIDC is configured for this workflow. Made-with: Cursor
❌ Deploy Preview for nuxt-storybook failed. Why did it fail? →
|
commit: |
Collaborator
|
Thanks! I tried that in #1047, but it's still not working. Any idea? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Nightly releases already run in the same workflow file as tag releases and have
id-token: write. With trusted publishing configured for this repo +release.yml, npm/pnpm can authenticate via GitHub OIDC withoutNODE_AUTH_TOKEN.Change
NODE_AUTH_TOKEN: secrets.NPMJS_TOKENfrom the Nightly release step so behavior matches the tagreleasejob (OIDC-only publish).Why
After merge
mainrunspnpm nightly-releasesuccessfully. IfNPMJS_TOKENis unused elsewhere, the secret can be removed from repo settings.Made with Cursor