Skip to content

ci: publish with npm trusted publishing instead of NPM_TOKEN - #416

Merged
FRSgit merged 1 commit into
mainfrom
chore/npm-trusted-publishing
Oct 1, 2026
Merged

FRSgit merged 1 commit into
mainfrom
chore/npm-trusted-publishing

Conversation

@FRSgit

@FRSgit FRSgit commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Migrates @frsource/frs-replace from the NPM_TOKEN secret to npm trusted publishing (OIDC), same as is-animated already does (FRSOURCE/is-animated@d71e9c3).

  • id-token: write on the release job; @semantic-release/npm 13 detects the GitHub OIDC environment and publishes with provenance automatically
  • NPM_TOKEN removed from the release step

Status: trusted publishers are configured on npmjs.com for every package, and the toolkit release (run 36886764279) has already published @frsource/release-it-config@1.60.0 and globals-vitest@5.0.3 through OIDC with signed provenance, so this PR is ready to merge.

🤖 Generated with Claude Code

- grant `id-token: write` to the release job so @semantic-release/npm
  can exchange the GitHub OIDC token for a short-lived npm token
- drop the NPM_TOKEN secret from the release step

Requires a trusted publisher (FRSOURCE/frs-replace, ci.yml) configured on
npmjs.com before merging.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@FRSgit
FRSgit merged commit 7502964 into main Oct 1, 2026
1 check passed
@FRSgit
FRSgit deleted the chore/npm-trusted-publishing branch October 1, 2026 16:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant