Skip to content

ci: publish to npm via trusted publishing (OIDC) - #37

Draft
shirish87 wants to merge 1 commit into
mainfrom
claude/project-thread-vtv03a
Draft

shirish87 wants to merge 1 commit into
mainfrom
claude/project-thread-vtv03a

Conversation

@shirish87

Copy link
Copy Markdown
Owner

Before: The Publish npm job authenticated with a long-lived NPM_PUBLISH_TOKEN secret, which npm now rejects (main run #202 failed with E404 on PUT).

After: The job publishes with npm trusted publishing (OIDC), so no stored npm token is needed.

Changes the publish job to request id-token: write, upgrade npm to >= 11.5.1, and run pnpm publish --provenance without NODE_AUTH_TOKEN. Each published package also gets a repository field, which npm checks against the trusted publisher.

How: Before this works, each @dot-slash/* package needs a trusted publisher configured on npmjs.com (Settings > Trusted Publisher: GitHub Actions, repo shirish87/browserstack-client, workflow main.yml, environment BrowserStackEnv). Not run end to end; verify by re-running the workflow on main after merging. 7.2.0 was never published, so no version bump is needed.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WUdwzfDSUhTEqqEWDhi6tB


Generated by Claude Code

Replace the long-lived NPM_PUBLISH_TOKEN with npm trusted publishing:
id-token permission, npm >= 11.5.1, --provenance, and a repository field
on each published package (required to match the trusted publisher).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WUdwzfDSUhTEqqEWDhi6tB
@shirish87
shirish87 deployed to BrowserStackEnv October 5, 2026 03:22 — with GitHub Actions Active
@shirish87
shirish87 deployed to BrowserStackEnv October 5, 2026 03:25 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
BrowserStackEnv — d6a42ea4 Deployed Oct 5, 2026 by shirish87 via Test CLI (windows-2025) #203
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants