🔎 ci: make the dry run prove trusted publishing engaged

npm calls oidc() before every dryRun branch in publish.js, so `npm publish
--dry-run` performs the real token exchange and the existing step is already a
trusted-publishing smoke test — it just could not be read.

The exchange is non-throwing by design, so at the default log level a working
OIDC exchange and a silent fallback to NPM_TOKEN look exactly the same. Raising
that one step to verbose surfaces `oidc Successfully retrieved and set token`,
which turns "did trusted publishing actually work?" into something a dry run
answers without publishing anything.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
This commit is contained in:
Claude
2026-08-20 16:16:19 +00:00
parent f56d2811cb
commit 730e5902a5
+10
View File
@@ -105,6 +105,16 @@ jobs:
run: npm run verify
- name: Show exactly what would ship
# `npm publish --dry-run` performs the OIDC token exchange before it short-circuits
# (publish.js calls oidc() ahead of every dryRun branch), so this step is also the
# trusted-publishing smoke test — a dry run proves the exchange without publishing.
#
# verbose, because npm's OIDC step is non-throwing: at the default log level a
# successful exchange and a silent fallback to token auth look identical. Success
# prints `oidc Successfully retrieved and set token`; if that line is missing,
# trusted publishing did not engage. (The reasons it skips are logged at silly.)
env:
NPM_CONFIG_LOGLEVEL: verbose
run: npm publish --dry-run
- name: Publish