From 95e4f92429c2d8921bfd2b7ae1a0b2e3a455a39e Mon Sep 17 00:00:00 2001 From: Ayush Agarwal Date: Mon, 24 Aug 2026 13:29:39 +0530 Subject: [PATCH] ci(release): switch chimely to npm Trusted Publishing (OIDC), drop NPM_TOKEN The publish job already grants id-token: write (used for provenance). Remove the NPM_TOKEN env from the changesets publish step so pnpm authenticates via OIDC trusted publishing instead of a long-lived token. pnpm 11.5.2 (this repo's pinned packageManager) includes the OIDC precedence fix (pnpm#11495): the OIDC-derived token overrides any static _authToken, so leaving NPM_TOKEN set would silently downgrade the publish back to legacy token auth (no trusted-publisher metadata / provenance). Dropping it forces the OIDC path. Each @chimely/* package (client, react) has a trusted publisher registered on npmjs.com for repo dodopayments/chimely + workflow release.yml. Provenance stays visibility-gated (repo is public, so on). Mirrors dodopayments/dualmark#91. --- .github/workflows/release.yml | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 184d86e..915e523 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -14,8 +14,9 @@ # npm; the same v* tag push publishes the Docker image (see ci.yml docker job). # # Prerequisites (repo settings, one-time, human): -# - NPM_TOKEN secret: an npm automation token with publish rights to the -# @chimely scope, and the @chimely scope must grant that token access. +# - npm Trusted Publishing (OIDC), no NPM_TOKEN: each @chimely/* package has +# a trusted publisher on npmjs.com for repo dodopayments/chimely + workflow +# release.yml. The publish job's id-token: write authenticates the publish. # - "Allow GitHub Actions to create and approve pull requests" enabled. # The `version` job opens the Version Packages PR. The `publish` job does # NOT need this (no pull-requests permission), so the publish path is @@ -93,5 +94,11 @@ jobs: createGithubReleases: false env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} + # No NPM_TOKEN: npm Trusted Publishing (OIDC) authenticates the + # publish via the job's id-token: write. pnpm >= the #11495 fix + # (this repo pins pnpm 11.5.2) lets the OIDC-derived token override + # any static _authToken, so a token here would only downgrade the + # publish back to legacy token auth (no trusted-publisher metadata). + # Each @chimely/* package has a trusted publisher registered on + # npmjs.com for repo dodopayments/chimely + workflow release.yml. NPM_CONFIG_PROVENANCE: ${{ steps.vis.outputs.provenance }}