Skip to content

ci: publish @sanring/cli with npm trusted publishing - #47

Merged
jack755051 merged 1 commit into
mainfrom
fix/npm-trusted-publishing
Sep 27, 2026
Merged

jack755051 merged 1 commit into
mainfrom
fix/npm-trusted-publishing

Conversation

@jack755051

Copy link
Copy Markdown
Contributor

Summary

  • Release no longer uses NPM_TOKEN. Token publish is hitting EOTP even with Bypass 2FA checked.
  • Job now has id-token: write so npm can authenticate with GitHub OIDC.
  • Pre-create a token-free .npmrc so changesets/action does not write the token file that forces OTP.

After this lands, add a Trusted Publisher on @sanring/cli (see PR comment / chat) and re-run Release. It will publish 0.27.0.

Test plan

  • npm package Settings → Trusted Publisher matches sanringtech / ui / release.yml
  • Allowed actions include npm publish
  • Release workflow publishes @sanring/cli@0.27.0

Made with Cursor

Token publish keeps asking for OTP. GitHub Actions can publish
@sanring/cli with id-token instead of NPM_TOKEN.

Co-authored-by: Cursor <cursoragent@cursor.com>
@jack755051
jack755051 merged commit d7a9bd9 into main Sep 27, 2026
4 of 5 checks passed
@jack755051
jack755051 deleted the fix/npm-trusted-publishing branch September 27, 2026 11:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant