From 730e5902a5c3f7b9216be1c43428c1c12328a26a Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 20 Aug 2026 16:16:19 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=8E=20ci:=20make=20the=20dry=20run=20p?= =?UTF-8?q?rove=20trusted=20publishing=20engaged?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit npm calls oidc() before every dryRun branch in publish.js, so `npm publish --dry-run` performs the real token exchange and the existing step is already a trusted-publishing smoke test — it just could not be read. The exchange is non-throwing by design, so at the default log level a working OIDC exchange and a silent fallback to NPM_TOKEN look exactly the same. Raising that one step to verbose surfaces `oidc Successfully retrieved and set token`, which turns "did trusted publishing actually work?" into something a dry run answers without publishing anything. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK --- .github/workflows/release.yml | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index cf80fe4..1b0812c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -105,6 +105,16 @@ jobs: run: npm run verify - name: Show exactly what would ship + # `npm publish --dry-run` performs the OIDC token exchange before it short-circuits + # (publish.js calls oidc() ahead of every dryRun branch), so this step is also the + # trusted-publishing smoke test — a dry run proves the exchange without publishing. + # + # verbose, because npm's OIDC step is non-throwing: at the default log level a + # successful exchange and a silent fallback to token auth look identical. Success + # prints `oidc Successfully retrieved and set token`; if that line is missing, + # trusted publishing did not engage. (The reasons it skips are logged at silly.) + env: + NPM_CONFIG_LOGLEVEL: verbose run: npm publish --dry-run - name: Publish