Context
The release pipeline currently uses GitHub Releases as the artifact channel because the @bitcomplete npm org access hasn't been sorted yet (scope is owned by husscode / fran.bitcomplete; terraboops needs to be added). Two temporary measures are in place:
release.yml skips the npm publish step when the NPM_TOKEN secret is absent (logs a notice) and always cuts a GitHub Release with bundle.iife.global.js + sha256.
- pin's
bump-mdx-bundle.yaml prefers npm but falls back to downloading the latest GitHub Release asset while @bitcomplete/mdx-components 404s on the registry.
Plan
- Get terraboops publish access to the
@bitcomplete npm scope.
- First publish needs a token: mint a granular automation token, add as
NPM_TOKEN repo secret → publishing turns on automatically (no workflow change needed).
- Switch to OIDC trusted publishing: configure the trusted publisher on npmjs.com (repo
bitcomplete/bc-mdx-components, workflow release.yml), then drop NODE_AUTH_TOKEN / the NPM_TOKEN secret from the workflow. The workflow already requests id-token: write and publishes with --provenance.
- Remove the temporary measures:
release.yml: delete the "Check npm token availability" step and the gate on the publish step (publish unconditionally).
- pin
bump-mdx-bundle.yaml: delete the GitHub-Release fallback branch in the fetch step (npm only).
- Optionally keep attaching the bundle to GitHub Releases for humans — harmless either way.
Done when
- A version bump on main publishes
@bitcomplete/mdx-components to npm via OIDC with provenance, no long-lived secrets.
- pin's bump workflow pulls exclusively from npm.
🤖 Generated with Claude Code
Context
The release pipeline currently uses GitHub Releases as the artifact channel because the
@bitcompletenpm org access hasn't been sorted yet (scope is owned by husscode / fran.bitcomplete; terraboops needs to be added). Two temporary measures are in place:release.ymlskips the npm publish step when theNPM_TOKENsecret is absent (logs a notice) and always cuts a GitHub Release withbundle.iife.global.js+ sha256.bump-mdx-bundle.yamlprefers npm but falls back to downloading the latest GitHub Release asset while@bitcomplete/mdx-components404s on the registry.Plan
@bitcompletenpm scope.NPM_TOKENrepo secret → publishing turns on automatically (no workflow change needed).bitcomplete/bc-mdx-components, workflowrelease.yml), then dropNODE_AUTH_TOKEN/ theNPM_TOKENsecret from the workflow. The workflow already requestsid-token: writeand publishes with--provenance.release.yml: delete the "Check npm token availability" step and the gate on the publish step (publish unconditionally).bump-mdx-bundle.yaml: delete the GitHub-Release fallback branch in the fetch step (npm only).Done when
@bitcomplete/mdx-componentsto npm via OIDC with provenance, no long-lived secrets.🤖 Generated with Claude Code