Conversation
Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The GitHub Packages job gains the packages: write permission it was missing and keeps publishing with the job's own token. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
|
Coverage report for commit: 94b794b Summary - Lines: 82.77% | Methods: 95.77% | Branches: 65.89%
🤖 comment via lucassabreu/comment-coverage-clover |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Both jobs reference unavailable v7 action versions and will fail before publishing.
Review effort: Balanced
Findings: None
What changed in this PR
Replaces token-based npm publishing with OIDC trusted publishing and repairs GitHub Packages permissions.
Changes:
- Publishes release tags using Node 24 and OIDC.
- Adds GitHub Packages write permission and prerelease tagging.
| File | Description |
|---|---|
.github/workflows/release.yml |
Adds npm and GitHub Packages release jobs. |
.github/workflows/npm-publish.yml |
Removes the token-based workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Problem
npm-publish.ymlpublishes@contentstack/managementto npm with a long-livedNPM_TOKEN.The SE1 publishing policy requires OIDC trusted publishing instead: no token, a
release.ymlworkflow that runs when a release is published, Node 24.The GitHub Packages job is also failing today (
E403) because it lacks thepackages: writepermission.Fix
npm-publish.ymlis renamed torelease.yml. What changes inside it:release: createdrelease: publishedNPM_TOKENid-token: write, no tokennpm publishnpm publish --access public; pre-releases go to thebetadist-tag, releases tolatestsecrets.GITHUB_TOKEN, nopackages: writegithub.token(same token) withpackages: writepersist-credentials: falsecheckout@v4,setup-node@v4@v7Verification
Node 22 and Node 24: install, build, unit tests and
npm packall pass.