diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index c63e70c..9628dda 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -38,7 +38,17 @@ jobs: exit 1 fi - # No token: id-token above lets the CLI exchange a short-lived OIDC - # credential with npm. Provenance is generated automatically for a public - # package from a public repo, so --provenance is not needed either. + # OIDC (id-token above) is the preferred credential and needs no secret. + # But trusted publishing is configured per package on npmjs.com, and a + # package that has never been published cannot have it configured — so + # OIDC alone cannot do the FIRST publish. Confirmed on ai-forms: the + # provenance statement was signed and logged to sigstore, then the PUT + # returned E404 "could not be found or you do not have permission", + # which reads like a missing package rather than a missing credential. + # + # NPM_TOKEN covers only that first publish. Once this package exists and + # a trusted publisher is configured, npm prefers OIDC and the secret can + # be deleted. - run: npm publish + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}