Repository navigation
Add npm-trusted-publishing skill 🤖🤖🤖 - #4560
Open
MarkAlex1234 wants to merge 1 commit into
Open
MarkAlex1234 wants to merge 1 commit into
MarkAlex1234 wants to merge 1 commit into
Conversation
Contributor
🚦 Submission status: 👀 Ready for reviewRisk tier: Why this tier
Automated checks
Review
Commands
Updated for |
Contributor
🔒 PR Risk Scan ResultsScanned 1 changed file(s).
|
Contributor
|
🔴 Contributor Reputation Check: HIGH risk
Maintainers: please review this contributor before merging. |
Contributor
🔍 Vally Lint Results✅ All checks passed
Summary
Full linter output |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds npm-trusted-publishing, a skill for moving GitHub Actions npm releases from
NPM_TOKENto npm trusted publishing (OIDC), and for diagnosing a half-finished migration.Why it adds uplift over the model's defaults. The common failure modes aren't obvious, and models regularly get them wrong:
NODE_AUTH_TOKENkeeps the old token in use.permissionsblock drops every scope you don't list.id-token: writemust never go on a job reachable frompull_request_targetorissue_comment.ENEEDAUTH,404 PUTandE422 repository.urleach mean something specific.The deadline makes this timely: npm stops direct publishing with 2FA-bypass tokens in January 2027.
The skill is self-contained (a checklist, security rules, an error table and an example workflow). It mentions go-tokenless once, as an optional way to automate the edits.
npm run skill:validatepasses, andnpm startregenerateddocs/README.skills.md.Disclosure: I maintain go-tokenless. An AI agent prepared this PR.