Skip to content

Switch to npm releasing (OIDC trusted publishing); drop GH-release fallback #5

Description

@terraboops

Context

The release pipeline currently uses GitHub Releases as the artifact channel because the @bitcomplete npm org access hasn't been sorted yet (scope is owned by husscode / fran.bitcomplete; terraboops needs to be added). Two temporary measures are in place:

  • release.yml skips the npm publish step when the NPM_TOKEN secret is absent (logs a notice) and always cuts a GitHub Release with bundle.iife.global.js + sha256.
  • pin's bump-mdx-bundle.yaml prefers npm but falls back to downloading the latest GitHub Release asset while @bitcomplete/mdx-components 404s on the registry.

Plan

  1. Get terraboops publish access to the @bitcomplete npm scope.
  2. First publish needs a token: mint a granular automation token, add as NPM_TOKEN repo secret → publishing turns on automatically (no workflow change needed).
  3. Switch to OIDC trusted publishing: configure the trusted publisher on npmjs.com (repo bitcomplete/bc-mdx-components, workflow release.yml), then drop NODE_AUTH_TOKEN / the NPM_TOKEN secret from the workflow. The workflow already requests id-token: write and publishes with --provenance.
  4. Remove the temporary measures:
    • release.yml: delete the "Check npm token availability" step and the gate on the publish step (publish unconditionally).
    • pin bump-mdx-bundle.yaml: delete the GitHub-Release fallback branch in the fetch step (npm only).
    • Optionally keep attaching the bundle to GitHub Releases for humans — harmless either way.

Done when

  • A version bump on main publishes @bitcomplete/mdx-components to npm via OIDC with provenance, no long-lived secrets.
  • pin's bump workflow pulls exclusively from npm.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions