Skip to content

ci: use OIDC for prerelease tag cleanup - #392

Draft
michelchau wants to merge 1 commit into
mainfrom
codex/oidc-prerelease-cleanup
Draft

michelchau wants to merge 1 commit into
mainfrom
codex/oidc-prerelease-cleanup

Conversation

@michelchau

Copy link
Copy Markdown

The publish workflow's prerelease deprecation steps use NPM_TOKEN and return npm 403 errors, while OIDC publishing succeeds. This change removes the workflow's dependency on that token. npm does not support OIDC for npm deprecate, so superseded canary and PR versions will remain installable without being automatically marked deprecated.

The prerelease job installs npm 11.21.0, which supports OIDC for npm dist-tag. Closing a PR removes its pr-N tag through OIDC. A missing tag is a no-op; registry lookup or tag-removal errors fail the cleanup job. Publishing continues to advance the canary and PR tags as before.

Before merging: enable Allow npm dist-tag for the prismicio/cli / publish.yml trusted publisher in the prismic package's npm settings. This permission is independent of publishing and is disabled by default. The requirement and the deprecation behavior are documented in CONTRIBUTING.md.

References: failing cleanup run, npm OIDC tag support.

Validation:

  • actionlint 1.7.12, repository lint, TypeScript checks, and formatting checks passed.
  • Executed the cleanup script with a mocked npm command: existing tag, missing tag, lookup failure, and removal failure all behaved as expected.
  • The integration suite stopped in global setup because E2E_PRISMIC_EMAIL is unavailable locally; it also requires E2E_PRISMIC_PASSWORD.
  • Live OIDC tag removal requires GitHub Actions and the npm permission above; it was not exercised locally.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant