Update the release process for trusted publishing - #160
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 920a0656c3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| env: | ||
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |
There was a problem hiding this comment.
Isolate OIDC publishing from the install step
With NPM_TOKEN removed here, publishing now relies on the job-wide id-token: write permission for npm trusted publishing. In this workflow, yarn install --immutable runs before changesets/action, so on a merged release PR where the package.json versions are not published yet, any dependency lifecycle script executed during install can request the same OIDC token and run npm publish from this trusted workflow before the intended release step. Please split publishing into a separate job/phase that gets id-token: write only after dependencies/build artifacts are prepared, or otherwise prevent install-time scripts from having publish-capable OIDC access.
Useful? React with 👍 / 👎.
No description provided.