Skip to content

ci: install npm >=11.5.1 so pnpm can do OIDC trusted publishing (#18) #22

ci: install npm >=11.5.1 so pnpm can do OIDC trusted publishing (#18)

ci: install npm >=11.5.1 so pnpm can do OIDC trusted publishing (#18) #22

Workflow file for this run

name: Release
on:
push:
branches:
- main
concurrency: ${{ github.workflow }}-${{ github.ref }}
jobs:
release:
name: Release
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
id-token: write
steps:
- name: Checkout Repo
uses: actions/checkout@v4
- name: Install pnpm
uses: pnpm/action-setup@v4
with:
version: 10.14.0
- name: Setup Node.js 22.x
uses: actions/setup-node@v4
with:
node-version: 22
cache: 'pnpm'
registry-url: 'https://registry.npmjs.org'
# `changeset publish` runs `pnpm publish`, and pnpm delegates the npm
# OIDC trusted-publishing token exchange to the npm CLI — which must be
# >= 11.5.1. Node 22 ships npm 10.x, so without this the publish goes out
# unauthenticated and the registry returns E404.
- name: Upgrade npm for OIDC trusted publishing
run: npm install -g npm@latest
- name: Install Dependencies
run: pnpm install --frozen-lockfile
- name: Create Release Pull Request or Publish to npm
id: changesets
uses: changesets/action@v1
with:
publish: pnpm changeset publish
env:
GITHUB_TOKEN: ${{ secrets.GH_TOKEN || secrets.GITHUB_TOKEN }}
NPM_CONFIG_PROVENANCE: true