Skip to content

ci: publish the npm package with the NPM_TOKEN secret - #43

Merged
nolindnaidoo merged 1 commit into
mainfrom
ci/npm-token
Oct 5, 2026
Merged

nolindnaidoo merged 1 commit into
mainfrom
ci/npm-token

Conversation

@nolindnaidoo

Copy link
Copy Markdown
Owner

The release workflow's npm step used trusted publishing, which was never configured on npm, so it has failed on every run. This switches it to the NPM_TOKEN repository secret, the token the family's packages are published with, and adds a check that the secret is set.

Workflow and guide only. Nothing that ships changes.

The release workflow published to npm by trusted publishing, which was
never set up on npm for this package. The step failed every time it
ran, and every version so far was published with a token outside the
workflow. The release of this version reached the Marketplace and Open
VSX and stopped at npm for that reason.

The npm job now authenticates with the NPM_TOKEN secret, the token the
whole family is published with, and checks it is set before doing
anything that cannot be undone.
@nolindnaidoo
nolindnaidoo merged commit 118e945 into main Oct 5, 2026
32 checks passed
@nolindnaidoo
nolindnaidoo deleted the ci/npm-token branch October 5, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant