Skip to content

Actually authenticate the npm publish over OIDC - #25

Merged
jbn2336mz merged 1 commit into
mainfrom
fix-oidc-publish
Sep 17, 2026
Merged

jbn2336mz merged 1 commit into
mainfrom
fix-oidc-publish

Conversation

@jbn2336mz

Copy link
Copy Markdown
Member

The v0.2.25 run reached npm publish and failed with:

npm error code E404
npm error 404 Not Found - PUT https://registry.npmjs.org/@mockzilla%2fmcp - Not found

E404 on a PUT is how npm answers a credential it does not accept: it hides whether the package exists. Everything before it worked, including the new AWS role and the docs build.

Two causes, both in the same step:

  • registry-url on setup-node. It writes an .npmrc containing _authToken=XXXXX-XXXXX-XXXXX-XXXXX, the placeholder it uses when no NODE_AUTH_TOKEN is set. npm finds a token configured and publishes with it instead of falling back to Trusted Publishing. Dropped: the default registry is already registry.npmjs.org.
  • npm was 10.9.8. corepack prepare npm@latest --activate printed Preparing npm@latest for immediate activation... and the next line of the same step printed 10.9.8. Trusted Publishing needs 11.5.1. Now installed outright, with a sort -V check that fails the job instead of letting an unauthenticated publish 404 later.

The signed provenance line in the failed log is not evidence that OIDC auth worked. --provenance has been in npm since 9.5 and signs before the PUT.

No version bump: 0.2.25 never reached npm, so it is still the version to ship.

v0.2.25's run got as far as npm publish and took an E404 on the PUT,
which is how the registry answers a credential it does not accept.

Two causes, both in the same step. setup-node's registry-url writes an
.npmrc holding _authToken=XXXXX-XXXXX-XXXXX-XXXXX, its placeholder when
no NODE_AUTH_TOKEN is set, and npm publishes with that rather than
falling back to Trusted Publishing. And npm was still 10.9.8: corepack
prepare --activate reported success and changed nothing, so the OIDC
path did not exist in that npm at all. The signed provenance statement
in the log is not evidence either way, since --provenance has worked
since npm 9.5.

So: no registry-url, and install npm outright with a version check that
fails the job. A 404 from the registry says nothing about its cause, and
this one cost a release to read.
@jbn2336mz
jbn2336mz merged commit 8f57f44 into main Sep 17, 2026
3 checks passed
@jbn2336mz
jbn2336mz deleted the fix-oidc-publish branch September 17, 2026 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant