Skip to content

Add npm-trusted-publishing skill 🤖🤖🤖 - #4560

Open
MarkAlex1234 wants to merge 1 commit into
github:mainfrom
MarkAlex1234:add-npm-trusted-publishing-skill
Open

MarkAlex1234 wants to merge 1 commit into
github:mainfrom
MarkAlex1234:add-npm-trusted-publishing-skill

Conversation

@MarkAlex1234

Copy link
Copy Markdown

Adds npm-trusted-publishing, a skill for moving GitHub Actions npm releases from NPM_TOKEN to npm trusted publishing (OIDC), and for diagnosing a half-finished migration.

Why it adds uplift over the model's defaults. The common failure modes aren't obvious, and models regularly get them wrong:

  • npm falls back to a configured token, so a leftover NODE_AUTH_TOKEN keeps the old token in use.
  • Node 22 ships npm 10, but 11.5.1 or newer is required.
  • A reusable workflow must name the caller's file on the trusted publisher.
  • Adding a permissions block drops every scope you don't list.
  • id-token: write must never go on a job reachable from pull_request_target or issue_comment.
  • ENEEDAUTH, 404 PUT and E422 repository.url each mean something specific.

The deadline makes this timely: npm stops direct publishing with 2FA-bypass tokens in January 2027.

The skill is self-contained (a checklist, security rules, an error table and an example workflow). It mentions go-tokenless once, as an optional way to automate the edits.

npm run skill:validate passes, and npm start regenerated docs/README.skills.md.

Disclosure: I maintain go-tokenless. An AI agent prepared this PR.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: 👀 Ready for review

Risk tier: merge-risk:high — Privileged execution, automation, or review-policy change
Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.

Why this tier
  • Label needs-review:HIGH flags a high contributor-risk signal

Automated checks

Check Status Details
Line endings ✅ Passed Passed · logs
Spelling ✅ Passed Passed · logs
Generated README consistency ✅ Passed Passed · logs
Skill validation ✅ Passed Passed · logs
Skill lint (vally) ✅ Passed Passed · logs
Risk scan ✅ Passed Passed · logs
Contributor reputation ✅ Passed Passed · logs
Duplicate resource scan ✅ Passed Passed · logs
PR quality signal ⏭️ Skipped Skipped by its workflow · logs

Review

  • Approvals: 0/2
  • Assigned reviewer: not assigned yet — comment /request-review to ask for one
  • Review target date: not set
  • Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission
  • The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for f3bcf50 · gate run · This comment is maintained automatically — see submission gate docs.

@github-actions github-actions Bot added new-submission PR adds at least one new contribution skills PR touches skills labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🔒 PR Risk Scan Results

Scanned 1 changed file(s).

Severity Count
🔴 High 0
🟠 Medium 2
ℹ️ Info 0
Severity Rule File Line Match
🟠 package-exec-command skills/npm-trusted-publishing/SKILL.md 70 - `npx go-tokenless` prints a read-only diff of the workflow and `package.json` changes, plus the `npm trust` commands.
🟠 package-exec-command skills/npm-trusted-publishing/SKILL.md 71 - `npx go-tokenless apply` writes the changes.

This is an automated soft-gate report. Findings indicate review targets and do not block merge by themselves.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🔴 Contributor Reputation Check: HIGH risk

Check Risk
Profile HIGH
Credential audit NONE

Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.

@github-actions github-actions Bot added the needs-review:HIGH Contributor reputation check flagged HIGH risk label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

🔍 Vally Lint Results

✅ All checks passed

Scope Checked
Skills 1
Agents 0
Total 1
Severity Count
❌ Errors 0
⚠️ Warnings 0
ℹ️ Advisories 0

Summary

Level Finding
ℹ️ ✅ npm-trusted-publishing (2/2 checks passed)
ℹ️ ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
ℹ️ ✓ spec-compliance: All spec checks passed.
ℹ️ ✓ [valid-refs] All file references across 1 skill(s) are valid.
ℹ️ ✓ valid-refs: All file references resolve to existing files within the skill directory.
ℹ️ 1 skill(s) linted, 1 passed
Full linter output
### Linting skills/npm-trusted-publishing
✅ npm-trusted-publishing (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

1 skill(s) linted, 1 passed

@github-actions github-actions Bot added merge-risk:high ready-for-review Submission passed intake validation and is ready for maintainer review awaiting-automation and removed merge-risk:medium awaiting-automation ready-for-review Submission passed intake validation and is ready for maintainer review labels Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk:high needs-review:HIGH Contributor reputation check flagged HIGH risk new-submission PR adds at least one new contribution ready-for-review Submission passed intake validation and is ready for maintainer review skills PR touches skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant