🔎 ci: make the dry run prove trusted publishing engaged
npm calls oidc() before every dryRun branch in publish.js, so `npm publish --dry-run` performs the real token exchange and the existing step is already a trusted-publishing smoke test — it just could not be read. The exchange is non-throwing by design, so at the default log level a working OIDC exchange and a silent fallback to NPM_TOKEN look exactly the same. Raising that one step to verbose surfaces `oidc Successfully retrieved and set token`, which turns "did trusted publishing actually work?" into something a dry run answers without publishing anything. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
This commit is contained in:
@@ -105,6 +105,16 @@ jobs:
|
|||||||
run: npm run verify
|
run: npm run verify
|
||||||
|
|
||||||
- name: Show exactly what would ship
|
- name: Show exactly what would ship
|
||||||
|
# `npm publish --dry-run` performs the OIDC token exchange before it short-circuits
|
||||||
|
# (publish.js calls oidc() ahead of every dryRun branch), so this step is also the
|
||||||
|
# trusted-publishing smoke test — a dry run proves the exchange without publishing.
|
||||||
|
#
|
||||||
|
# verbose, because npm's OIDC step is non-throwing: at the default log level a
|
||||||
|
# successful exchange and a silent fallback to token auth look identical. Success
|
||||||
|
# prints `oidc Successfully retrieved and set token`; if that line is missing,
|
||||||
|
# trusted publishing did not engage. (The reasons it skips are logged at silly.)
|
||||||
|
env:
|
||||||
|
NPM_CONFIG_LOGLEVEL: verbose
|
||||||
run: npm publish --dry-run
|
run: npm publish --dry-run
|
||||||
|
|
||||||
- name: Publish
|
- name: Publish
|
||||||
|
|||||||
Reference in New Issue
Block a user