Skip to content

ci: add npm publish workflow - #2

Merged
F88 merged 1 commit into
mainfrom
ci/npm-publish-workflow
Jul 23, 2026
Merged

F88 merged 1 commit into
mainfrom
ci/npm-publish-workflow

Conversation

@F88

@F88 F88 commented Jul 23, 2026

Copy link
Copy Markdown
Owner

Summary

Add .github/workflows/publish-package-to-npmjs.yml, which publishes the package to npmjs.com:

  • Triggers: GitHub Release published, or manual workflow_dispatch
  • build job gates the publish: npm ci → typecheck → format check → lint → tests
  • publish-to-npm job publishes via Trusted Publishing (OIDC, id-token: write) with --provenance --access public; no tokens are stored

Merging this is inert on its own: nothing runs until a Release is published (or the workflow is dispatched manually), and npm publish remains blocked by the prepublishOnly guard in package.json until release preparation replaces it with the build script. The npmjs side additionally requires registering this repo + workflow filename as a trusted publisher before the first publish can succeed.

🤖 Generated with Claude Code

Publish to npmjs.com via Trusted Publishing (OIDC) with provenance,
triggered by a published GitHub Release or manually via
workflow_dispatch. A build job (typecheck, format check, lint,
tests) gates the publish job.

Publishing stays blocked by the prepublishOnly guard in
package.json until the release preparation replaces it with the
build script.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings July 23, 2026 05:10
@F88 F88 added the enhancement New feature or request label Jul 23, 2026
@F88
F88 merged commit b49f090 into main Jul 23, 2026
7 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a new GitHub Actions workflow to publish the package to npmjs.com using npm Trusted Publishing (OIDC) on GitHub Release publication or manual dispatch, with a build/test gate before publishing.

Changes:

  • Introduces publish-package-to-npmjs.yml with release.published and workflow_dispatch triggers.
  • Adds a build job to run install + typecheck/format/lint/tests before publishing.
  • Adds a publish-to-npm job that builds and publishes with --provenance --access public using id-token: write.
Comments suppressed due to low confidence (1)

.github/workflows/publish-package-to-npmjs.yml:46

  • actions/setup-node is pinned to v6 in the publish job, but the repo’s CI workflow uses actions/setup-node@v7. Aligning on one major version reduces drift and avoids unexpected behavioral differences between CI and release publishing.
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v6
        with:
          node-version: '22.x'
          registry-url: 'https://registry.npmjs.org'

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment on lines +23 to +27
- uses: actions/checkout@v7
- uses: actions/setup-node@v6
with:
node-version: '22.x'
cache: 'npm'
Comment on lines +48 to +52
# Trusted publishing requires npm 11.5.1 or later
# https://docs.npmjs.com/trusted-publishers
- name: Update npm
run: npm install -g npm@latest

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants