diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 2a984ab8..a90d1632 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -54,19 +54,11 @@ jobs: node-version: 26 registry-url: "https://registry.npmjs.org" - # Canary - - name: "Deprecate previous canary" - if: github.event_name == 'push' && needs.release.outputs.release_created != 'true' - continue-on-error: true - run: | - PACKAGE_NAME=$(jq -r ".name" package.json) - PREVIOUS_VERSION=$(npm view "$PACKAGE_NAME" dist-tags.canary 2>/dev/null || true) - if [ -n "$PREVIOUS_VERSION" ]; then - npm deprecate "$PACKAGE_NAME@$PREVIOUS_VERSION" "Replaced by newer canary version" - fi - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + - name: "Install npm with OIDC dist-tag support" + run: npm install --global npm@11.21.0 + # npm deprecate does not support OIDC. Publishing advances the tag instead. + # Canary - name: "Publish canary" if: github.event_name == 'push' && needs.release.outputs.release_created != 'true' run: | @@ -77,19 +69,6 @@ jobs: npm publish --tag canary # Pull request - - name: "Deprecate previous PR prerelease" - if: github.event_name == 'pull_request' && github.event.action != 'closed' - continue-on-error: true - run: | - PACKAGE_NAME=$(jq -r ".name" package.json) - TAG="pr-${{ github.event.number }}" - PREVIOUS_VERSION=$(npm view "$PACKAGE_NAME" dist-tags."$TAG" 2>/dev/null || true) - if [ -n "$PREVIOUS_VERSION" ]; then - npm deprecate "$PACKAGE_NAME@$PREVIOUS_VERSION" "Replaced by newer prerelease version" - fi - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - - name: "Publish PR prerelease" if: github.event_name == 'pull_request' && github.event.action != 'closed' run: | @@ -99,16 +78,12 @@ jobs: npm version "${CURRENT_VERSION}-pr.${{ github.event.number }}.${SHORT_SHA}" --no-git-tag-version npm publish --tag pr-${{ github.event.number }} - - name: "Clean up PR prerelease" + - name: "Remove closed PR tag" if: github.event_name == 'pull_request' && github.event.action == 'closed' - continue-on-error: true run: | PACKAGE_NAME=$(jq -r ".name" package.json) TAG="pr-${{ github.event.number }}" - VERSION=$(npm view "$PACKAGE_NAME" dist-tags."$TAG" 2>/dev/null || echo "") + VERSION=$(npm view "$PACKAGE_NAME" "dist-tags.$TAG") if [ -n "$VERSION" ]; then - npm deprecate "$PACKAGE_NAME@$VERSION" "PR ${{ github.event.number }} was closed" npm dist-tag rm "$PACKAGE_NAME" "$TAG" fi - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 10c1c842..a7994606 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -94,6 +94,18 @@ This repository uses [Release Please](https://github.com/googleapis/release-plea If you don't see a pending PR, there are no changes to publish from `main`. +### npm authentication + +The `publish.yml` workflow uses npm trusted publishing (OIDC) for publishing +`prismic` and removing closed PR tags. Enable **Allow npm dist-tag** for the +`prismicio/cli` trusted publisher in the package's npm settings. Tag operations +require npm 11.21.0 or later; the prerelease job installs that version explicitly. + +The workflow does not use `NPM_TOKEN`. Publishing updates the `canary` or `pr-N` +tag, and closing a PR removes its tag. Superseded versions remain installable and +are no longer automatically deprecated because `npm deprecate` does not support +OIDC. + [^1]: This package is maintained by the DevX team. Prismic employees can ask for help or a review in the [#team-devx](https://prismic-team.slack.com/archives/C014VAACCQL) Slack channel. [^2]: Prismic employees are highly encouraged to discuss changes with the DevX team in the [#team-devx](https://prismic-team.slack.com/archives/C014VAACCQL) Slack channel before starting.