Files
cereale/.github
Claude 730e5902a5 🔎 ci: make the dry run prove trusted publishing engaged
npm calls oidc() before every dryRun branch in publish.js, so `npm publish
--dry-run` performs the real token exchange and the existing step is already a
trusted-publishing smoke test — it just could not be read.

The exchange is non-throwing by design, so at the default log level a working
OIDC exchange and a silent fallback to NPM_TOKEN look exactly the same. Raising
that one step to verbose surfaces `oidc Successfully retrieved and set token`,
which turns "did trusted publishing actually work?" into something a dry run
answers without publishing anything.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SAcqrz3FcadkYr3xG32CjK
2026-08-20 16:16:19 +00:00
..