Actually authenticate the npm publish over OIDC - #25
Merged
Merged
Conversation
v0.2.25's run got as far as npm publish and took an E404 on the PUT, which is how the registry answers a credential it does not accept. Two causes, both in the same step. setup-node's registry-url writes an .npmrc holding _authToken=XXXXX-XXXXX-XXXXX-XXXXX, its placeholder when no NODE_AUTH_TOKEN is set, and npm publishes with that rather than falling back to Trusted Publishing. And npm was still 10.9.8: corepack prepare --activate reported success and changed nothing, so the OIDC path did not exist in that npm at all. The signed provenance statement in the log is not evidence either way, since --provenance has worked since npm 9.5. So: no registry-url, and install npm outright with a version check that fails the job. A 404 from the registry says nothing about its cause, and this one cost a release to read.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The v0.2.25 run reached
npm publishand failed with:E404 on a PUT is how npm answers a credential it does not accept: it hides whether the package exists. Everything before it worked, including the new AWS role and the docs build.
Two causes, both in the same step:
registry-urlon setup-node. It writes an.npmrccontaining_authToken=XXXXX-XXXXX-XXXXX-XXXXX, the placeholder it uses when noNODE_AUTH_TOKENis set. npm finds a token configured and publishes with it instead of falling back to Trusted Publishing. Dropped: the default registry is already registry.npmjs.org.corepack prepare npm@latest --activateprintedPreparing npm@latest for immediate activation...and the next line of the same step printed10.9.8. Trusted Publishing needs 11.5.1. Now installed outright, with asort -Vcheck that fails the job instead of letting an unauthenticated publish 404 later.The signed provenance line in the failed log is not evidence that OIDC auth worked.
--provenancehas been in npm since 9.5 and signs before the PUT.No version bump: 0.2.25 never reached npm, so it is still the version to ship.