Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 10 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,9 @@
# npm; the same v* tag push publishes the Docker image (see ci.yml docker job).
#
# Prerequisites (repo settings, one-time, human):
# - NPM_TOKEN secret: an npm automation token with publish rights to the
# @chimely scope, and the @chimely scope must grant that token access.
# - npm Trusted Publishing (OIDC), no NPM_TOKEN: each @chimely/* package has
# a trusted publisher on npmjs.com for repo dodopayments/chimely + workflow
# release.yml. The publish job's id-token: write authenticates the publish.
# - "Allow GitHub Actions to create and approve pull requests" enabled.
# The `version` job opens the Version Packages PR. The `publish` job does
# NOT need this (no pull-requests permission), so the publish path is
Expand Down Expand Up @@ -93,5 +94,11 @@ jobs:
createGithubReleases: false
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
# No NPM_TOKEN: npm Trusted Publishing (OIDC) authenticates the
# publish via the job's id-token: write. pnpm >= the #11495 fix
# (this repo pins pnpm 11.5.2) lets the OIDC-derived token override
# any static _authToken, so a token here would only downgrade the
# publish back to legacy token auth (no trusted-publisher metadata).
# Each @chimely/* package has a trusted publisher registered on
# npmjs.com for repo dodopayments/chimely + workflow release.yml.
Comment on lines +97 to +103

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Keep authentication comment invariant-focused

This block narrates and argues for the implementation rather than documenting the enduring requirement, obscuring the key constraint that NPM_TOKEN must remain unset for OIDC publishing.

Suggested change
# No NPM_TOKEN: npm Trusted Publishing (OIDC) authenticates the
# publish via the job's id-token: write. pnpm >= the #11495 fix
# (this repo pins pnpm 11.5.2) lets the OIDC-derived token override
# any static _authToken, so a token here would only downgrade the
# publish back to legacy token auth (no trusted-publisher metadata).
# Each @chimely/* package has a trusted publisher registered on
# npmjs.com for repo dodopayments/chimely + workflow release.yml.
# NPM_TOKEN must remain unset so npm Trusted Publishing uses the
# job's OIDC credentials.

Context Used: CLAUDE.md (source)

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

NPM_CONFIG_PROVENANCE: ${{ steps.vis.outputs.provenance }}
Loading