Repository navigation
Publish to the MCP registry on a release too - #26
Merged
Merged
Conversation
npm publish now works from a release, so the reason this one was held back is gone, and OIDC turned out to be enough for the registry: 0.2.25 went out through login github-oidc with no token at all. The read:org PAT is only needed by the local publish. The two workflows start on the same release rather than one after the other. The npm poll already in this one is what makes that safe, and it is needed either way: npm accepts a tarball a while before it can be read back, so even a sequential run would have to wait.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Finishes the release chain started in #24 and #25. A release now covers both registries with no manual step.
publish-mcp.ymlwas held back with aTEMP:comment because npm publish ran frommake publish. That is no longer true, so thereleasetrigger goes back on.workflow_dispatchstays.The registry side needs no secret. 0.2.25 published through
mcp-publisher login github-oidcwith no token, so theread:orgPAT in the README applies only to the localmake publish-mcp.On the ordering
The two workflows start on the same release and run in parallel.
publish-mcp.ymlalready polls npm for up to 10 minutes before publishing, which is what makes that safe.That wait is needed regardless. npm's publish is asynchronous now: the 0.2.25 run finished with
+ @mockzilla/mcp@0.2.25andYour package is being processed and may take a few minutes to become available, andnpm viewstill returned 0.2.24 for a while after. A sequential chain would have to wait for the same thing.Unchanged
make publish-allstill works for a release by hand.