Skip to content

chore(release): publish to npm with trusted publishing - #93

Open
cs-raj wants to merge 1 commit into
developmentfrom
feat/DX-27614
Open

cs-raj wants to merge 1 commit into
developmentfrom
feat/DX-27614

Conversation

@cs-raj

@cs-raj cs-raj commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Problem

release.yml on development still publishes @contentstack/datasync-mongodb-sdk on every push to master with a long-lived NPM_TOKEN through JS-DevTools/npm-publish@v3, then tags, creates the GitHub release and attaches the tarball with archived actions (the master copy is release-triggered, same token).

The SE1 publishing policy requires OIDC trusted publishing instead: no token, a release.yml workflow that runs when a release is published, Node 24.

Fix

release.yml is rewritten in place. What changes inside it:

Before After
Trigger push to master release: published — creating the GitHub release is what publishes
npm auth NPM_TOKEN via JS-DevTools/npm-publish@v3 OIDC — id-token: write, no token, plain npm publish
npm publish action default npm publish --access public; pre-releases go to the beta dist-tag, releases to latest
Tag + release creation Klemensas/action-autotag, actions/create-release@v1 (archived) removed — the release is the trigger
Release asset actions/upload-release-asset@v1 (archived) inside the publish job separate upload-release-asset job, runs after a successful publish: npm pack + gh release upload --clobber with the job token
Install npm install (+ npm install npm-pack) npm ci
Node / npm 22.x / npm 10 24 / latest npm
Checkout implicit, credentials persisted the release tag, persist-credentials: false
Actions checkout@v4, setup-node@v4 @v7

Verification

Node 22 and Node 24: install, build, unit tests and npm pack all pass.

Publish on release:published from release.yml instead of on every push to
master, so the npm trusted publisher can be keyed on the filename and a person
creating the GitHub release is what publishes; drop the NPM_TOKEN passed to
JS-DevTools/npm-publish in favour of id-token: write (OIDC), run on Node 24 with
npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag
without persisted credentials. The auto-tag and create-release steps go away
with the trigger; the tarball is attached to the release from a separate job
with gh release upload instead of the archived upload-release-asset action.
GitHub pre-releases go to the beta dist-tag.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 07:25
@cs-raj cs-raj self-assigned this Oct 5, 2026
@snyk-io

snyk-io Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

✅ Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
✅ Open Source Security 0 0 0 0 0 issues
✅ Licenses 0 0 0 0 0 issues
✅ Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The workflow must verify that the release tag matches the package version before publishing.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Reworks npm releases to use GitHub OIDC trusted publishing.

Changes:

  • Publishes on GitHub release events using Node 24.
  • Routes prereleases to beta and stable releases to latest.
  • Uploads the packed package as a release asset.
File Description
.github/​workflows/​release.yml Replaces token-based publishing and archived actions with OIDC publishing and gh asset upload.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +25 to +26
- name: Release
run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }}

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants