Skip to content

Commit 43f0338

Browse files
cs-rajclaude
andcommitted
chore(release): publish to npm with trusted publishing
Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and publishes with the job's own token instead of a personal token. package.json gains the repository field that provenance validation requires. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1 parent 1b8fb20 commit 43f0338

3 files changed

Lines changed: 54 additions & 35 deletions

File tree

‎.github/workflows/npm-publish.yml‎

Lines changed: 0 additions & 34 deletions
This file was deleted.

‎.github/workflows/release.yml‎

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
name: Publish package to npmjs registry
2+
on:
3+
release:
4+
types: [published]
5+
6+
jobs:
7+
publish-npm:
8+
runs-on: ubuntu-latest
9+
permissions:
10+
contents: read
11+
id-token: write
12+
steps:
13+
- uses: actions/checkout@v7
14+
with:
15+
ref: ${{ github.event.release.tag_name }}
16+
persist-credentials: false
17+
- uses: actions/setup-node@v7
18+
with:
19+
node-version: 24
20+
registry-url: https://registry.npmjs.org/
21+
cache: 'npm'
22+
- run: npm ci
23+
- name: Update npm
24+
run: npm install -g npm@latest
25+
- name: Release
26+
run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }}
27+
28+
publish-github:
29+
runs-on: ubuntu-latest
30+
permissions:
31+
contents: read
32+
packages: write
33+
steps:
34+
- uses: actions/checkout@v7
35+
with:
36+
ref: ${{ github.event.release.tag_name }}
37+
persist-credentials: false
38+
- uses: actions/setup-node@v7
39+
with:
40+
node-version: 24
41+
registry-url: https://npm.pkg.github.com/
42+
cache: 'npm'
43+
- run: npm ci
44+
- name: Update npm
45+
run: npm install -g npm@latest
46+
- name: Release
47+
run: npm publish
48+
env:
49+
NODE_AUTH_TOKEN: ${{ github.token }}

‎package.json‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,5 +85,9 @@
8585
"typescript": "~5.7.3",
8686
"ts-node": "^10.9.2"
8787
},
88-
"homepage": "https://github.com/contentstack/contentstack-typescript"
88+
"homepage": "https://github.com/contentstack/contentstack-typescript",
89+
"repository": {
90+
"type": "git",
91+
"url": "git+https://github.com/contentstack/contentstack-typescript.git"
92+
}
8993
}

0 commit comments

Comments
 (0)