Skip to content

Use npm trusted publishing for releases - #33

Merged
bjacobso merged 4 commits into
mainfrom
chore/npm-trusted-publishing
Sep 25, 2026
Merged

bjacobso merged 4 commits into
mainfrom
chore/npm-trusted-publishing

Conversation

@bjacobso

Copy link
Copy Markdown
Owner

Summary

  • Remove npm token injection and setup-node's token-backed registry configuration from release jobs. npm 11.5.1+ can exchange the job's GitHub OIDC identity for a short-lived publish credential.
  • Update package and website docs now that all seven public packages are available from npm.
  • Refresh the release runbook for trusted publishing and future package bootstrap.

Before merge

Configure npm trusted publishers for each of the seven public packages: GitHub owner bjacobso, repository triplex, workflow release.yml, environment npm-publish, with direct npm publish allowed. Keep the approval protection on that environment.

Verification

  • pnpm format:check
  • pnpm docs:check
  • Public registry lookups for all seven package versions
  • Clean external npm consumer installed core, SQLite, CLI, and Effect; core export and CLI help worked

After merging, dispatch a next canary and approve the protected environment to verify OIDC. Retire the bootstrap token only after that succeeds.

@bjacobso
bjacobso merged commit 0fb1d0c into main Sep 25, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant