Skip to content

fix(release): the npm job says what it presented and why the registry refused; the documents describe the first release - #96

Merged
krzysztof-smartdataengines merged 1 commit into
mainfrom
fix/npm-trusted-publishing-diagnostics
Sep 27, 2026
Merged

krzysztof-smartdataengines merged 1 commit into
mainfrom
fix/npm-trusted-publishing-diagnostics

Conversation

@krzysztof-smartdataengines

Copy link
Copy Markdown
Contributor

Summary

The first release through the workflow is out: smart-data-engine-sdk 0.1.0rc1 on PyPI (with
attestations) and @smart-data-engines/sde 0.1.0-rc.1 on npm (with provenance). This PR makes the npm
job say why the registry refused it, if it ever does again, and brings the documents in line with a
release that exists.

Why the publishing job needs to say more

typescript-v0.1.0-rc.1 was refused twice at the trusted-publishing exchange. The log said only
ENEEDAUTH. npm's OIDC helper never throws: it records why the exchange produced no token at verbose
level, in its debug log, on a runner that is gone when the job ends.

The cause turned out to be outside the workflow. The package had no trust configuration at all:
npm trust list answered "No trust configurations found", although the website had appeared to save
it twice. npm trust github … --allow-publish --yes, run in an interactive session with 2FA, created
the configuration, and a re-run of the same job published. Finding that took an owner's terminal,
because the refusal carried nothing a reader could act on.

What changed

  • release.yml, publishing job:
    • What the registry will be asked to trust. The job requests an ID token with npm's audience
      and prints its claims: repository, repository_owner, workflow_ref, job_workflow_ref,
      environment, ref, event_name and runner_environment. These are what npm compares with the
      trusted publisher. The token itself is decoded and never printed.
    • After a failed npm publish, the job prints the oidc lines of npm's debug log. They carry
      the registry's message, and no credential.
  • test_release.py: the claims step asks for npm's audience, prints the four claims that matter
    and never prints the token, and the failure path greps the debug log.
  • Documents. Seven documents said something that was true until today:
    • README.md and examples/weather/README.md called the starter unreleased;
    • docs/weather-starter.md also called it unreleased, and its install commands now come from the
      registries, pinned, with the artefact path kept as the alternative;
    • docs/implementations.md said npm install installs nothing, and promised that the first npm
      publish would come from CI. It could not: npm configures trusted publishing only on an existing
      package;
    • docs/publishing.md §1 said nothing was published under the scope, §5 said the workflow had
      never run, and §5.5 now records what happened and says to read the trust configuration back
      before tagging;
    • CHANGELOG.md gets the publication date.

Tests

  • The new test goes red when the oidc lines are no longer printed, when the token is echoed, or
    when the environment claim is dropped. A control, a comment edit, survives. The claims decoder
    was run on a synthetic JWT with the same fields.
  • check_contexts.py still passes: no checkout in the publishing job, id-token behind the
    environment, and every action pinned.
  • make check on the head 55908c1, with both live engines:
    • ruff and mypy clean, and Python 2101 passed and 10 skipped (the orderbook slice).
    • TypeScript: 997 passed, and two tests exceeded vitest's default 5 s timeout:
      frozen-verification.live.test.ts and the first runWeather test in weather.test.ts. This PR
      changes no TypeScript. The load average was 5.8 on four threads, from other sessions'
      batteries. In isolation the second test takes 0.9 s cold and 0.2 s warm; its cold cost now
      includes the first import('pg') added in fix(starter): refuse before writing what it can name, and let the fleet skip a run that never wrote #91. The TypeScript half of make check run again
      on the same head passed 999 of 999.

🤖 Generated with Claude Code

… the documents describe the first release

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@krzysztof-smartdataengines
krzysztof-smartdataengines merged commit 587ff14 into main Sep 27, 2026
14 checks passed
@krzysztof-smartdataengines
krzysztof-smartdataengines deleted the fix/npm-trusted-publishing-diagnostics branch September 27, 2026 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant