Skip to content

Let OIDC supply the npm credential - #3

Merged
mwagena merged 1 commit into
1.xfrom
f/mw/fix-oidc-auth
Sep 9, 2026
Merged

mwagena merged 1 commit into
1.xfrom
f/mw/fix-oidc-auth

Conversation

@mwagena

@mwagena mwagena commented Sep 9, 2026

Copy link
Copy Markdown
Member

The v1.1.3 publish run failed with E404 Not Found - PUT https://registry.npmjs.org/@concept7%2fkite, which is how the registry answers an unauthorized publish.

Cause: setup-node's registry-url input writes /home/runner/work/_temp/.npmrc containing //registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN} and exports NODE_AUTH_TOKEN as its literal placeholder XXXXX-XXXXX-XXXXX-XXXXX when no secret is provided. npm found a configured credential, sent the placeholder, and never attempted the OIDC exchange with the trusted publisher.

Removing registry-url leaves no auth configured, which is the condition for npm to fall back to trusted publishing. The publishConfig.registry in package.json already targets npmjs, so nothing else needs it.

Nothing was published from v1.1.3, so that version is still free — but this needs a fresh tag to test, since the failed tag points at the commit without this fix.

Test path

After merge, tag v1.1.4 on 1.x and confirm the publish job succeeds, the version resolves on npmjs, and the release carries a provenance attestation.

🤖 Generated with Claude Code

setup-node's registry-url writes an .npmrc pinning _authToken to
NODE_AUTH_TOKEN and exports the literal XXXXX-XXXXX-XXXXX-XXXXX placeholder
when no secret is set. npm then sends that placeholder rather than falling
back to the trusted publisher, and the registry rejects the PUT as a 404.
Without registry-url no auth is configured, so the OIDC exchange runs.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@mwagena mwagena self-assigned this Sep 9, 2026
@mwagena
mwagena merged commit fcb5931 into 1.x Sep 9, 2026
1 check passed
@mwagena
mwagena deleted the f/mw/fix-oidc-auth branch September 9, 2026 13:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant