ci: OIDC cannot do the first publish — keep a token for it - #6
Merged
Conversation
Same fix as ai-forms, before hitting the same failure. Trusted publishing is configured per package on npmjs.com and cannot be configured for a package that has never been published, so the token-free workflow fails on the first release with E404 on the PUT. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Same fix as ai-forms#15, applied here before hitting the same failure.
#3 moved publishing to OIDC trusted publishing with no token. That is the right destination, but trusted publishing is configured per package on npmjs.com, and a package that has never been published cannot have a trusted publisher configured. So OIDC alone cannot perform a first release.
Confirmed empirically on ai-forms tag
v0.1.1:Provenance signing works; the publish was simply unauthenticated, and npm answers 404 rather than 401 for that case on a non-existent package.
Restores
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}while keepingid-token: write. After the first release, configure a trusted publisher and delete the secret — npm prefers OIDC once one exists.🤖 Generated with Claude Code