Skip to content

ci: migrate npm releases to trusted publishing - #4

Merged
MuncleUscles merged 1 commit into
v0.1-devfrom
fix/npm-trusted-publishing
Sep 9, 2026
Merged

MuncleUscles merged 1 commit into
v0.1-devfrom
fix/npm-trusted-publishing

Conversation

@MuncleUscles

@MuncleUscles MuncleUscles commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Problem and outcome

Replace the expiring personal npm publishing token with package-scoped GitHub Actions OIDC for the coordinated core, React, and Vue releases.

Delivery context

Single repository follow-up to v0.1-dev at 5c177fd. No cross-repository dependencies or package API/version changes. Existing v0.1.0-rc.1 tag is unchanged.

Implementation and validation

  • Remove branch-only token checks and all NPM_TOKEN use from publish.yml.
  • Scope OIDC/write permissions to the Publish job; require supported npm and GitHub OIDC environment.
  • Keep tag ownership, matching package versions, existing gitHead, public access, and provenance gates.
  • Allow approximately ten minutes per package for npm publish-time scanning (RC1 upload succeeded but its old 26-second verification window timed out).
  • Document exact npm trust configuration and safe credential retirement.
  • Passed: actionlint, typecheck, build, all 59 tests (including 3 workflow contract tests), pack:check for all 3 tarballs, git diff --check.

Rollout and risks

Save all three npm trusted publisher connections before merging: genlayerlabs/genlayer-transaction-kit, publish.yml, environment Publish, direct npm publish allowed. All three npm connections (core, React, Vue) were saved and verified on 2026-09-09 with these exact values. GitHub build-and-test CI is green.
A dry run or rerun skipping existing versions does not prove OIDC publishing. Verify the next authorized real release before removing the old Publish environment secret, revoking its token, and disallowing bypass tokens. No extra release is authorized or created as an authentication probe.

Full cross-repository E2E is not requested for this workflow-only change. Merged with user authorization after the exact-head landing check. All three npm trusted publisher connections are verified; a real tokenless release and subsequent old-token retirement remain the rollout verification step.

Use package-scoped GitHub OIDC trust in the Publish environment instead of an expiring personal token. Preserve tag ownership and provenance checks, validate npm support, and tolerate publish-time registry scanning. Document staged credential retirement after a real tokenless release.
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 95275020-639c-4320-b736-340c7ae67a70

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@MuncleUscles MuncleUscles self-assigned this Sep 9, 2026
@MuncleUscles
MuncleUscles merged commit 6f64319 into v0.1-dev Sep 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant