Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 6 additions & 31 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -54,19 +54,11 @@ jobs:
node-version: 26
registry-url: "https://registry.npmjs.org"

# Canary
- name: "Deprecate previous canary"
if: github.event_name == 'push' && needs.release.outputs.release_created != 'true'
continue-on-error: true
run: |
PACKAGE_NAME=$(jq -r ".name" package.json)
PREVIOUS_VERSION=$(npm view "$PACKAGE_NAME" dist-tags.canary 2>/dev/null || true)
if [ -n "$PREVIOUS_VERSION" ]; then
npm deprecate "$PACKAGE_NAME@$PREVIOUS_VERSION" "Replaced by newer canary version"
fi
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: "Install npm with OIDC dist-tag support"
run: npm install --global npm@11.21.0

# npm deprecate does not support OIDC. Publishing advances the tag instead.
# Canary
- name: "Publish canary"
if: github.event_name == 'push' && needs.release.outputs.release_created != 'true'
run: |
Expand All @@ -77,19 +69,6 @@ jobs:
npm publish --tag canary

# Pull request
- name: "Deprecate previous PR prerelease"
if: github.event_name == 'pull_request' && github.event.action != 'closed'
continue-on-error: true
run: |
PACKAGE_NAME=$(jq -r ".name" package.json)
TAG="pr-${{ github.event.number }}"
PREVIOUS_VERSION=$(npm view "$PACKAGE_NAME" dist-tags."$TAG" 2>/dev/null || true)
if [ -n "$PREVIOUS_VERSION" ]; then
npm deprecate "$PACKAGE_NAME@$PREVIOUS_VERSION" "Replaced by newer prerelease version"
fi
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}

- name: "Publish PR prerelease"
if: github.event_name == 'pull_request' && github.event.action != 'closed'
run: |
Expand All @@ -99,16 +78,12 @@ jobs:
npm version "${CURRENT_VERSION}-pr.${{ github.event.number }}.${SHORT_SHA}" --no-git-tag-version
npm publish --tag pr-${{ github.event.number }}

- name: "Clean up PR prerelease"
- name: "Remove closed PR tag"
if: github.event_name == 'pull_request' && github.event.action == 'closed'
continue-on-error: true
run: |
PACKAGE_NAME=$(jq -r ".name" package.json)
TAG="pr-${{ github.event.number }}"
VERSION=$(npm view "$PACKAGE_NAME" dist-tags."$TAG" 2>/dev/null || echo "")
VERSION=$(npm view "$PACKAGE_NAME" "dist-tags.$TAG")
if [ -n "$VERSION" ]; then
npm deprecate "$PACKAGE_NAME@$VERSION" "PR ${{ github.event.number }} was closed"
npm dist-tag rm "$PACKAGE_NAME" "$TAG"
fi
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
12 changes: 12 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -94,6 +94,18 @@ This repository uses [Release Please](https://github.com/googleapis/release-plea

If you don't see a pending PR, there are no changes to publish from `main`.

### npm authentication

The `publish.yml` workflow uses npm trusted publishing (OIDC) for publishing
`prismic` and removing closed PR tags. Enable **Allow npm dist-tag** for the
`prismicio/cli` trusted publisher in the package's npm settings. Tag operations
require npm 11.21.0 or later; the prerelease job installs that version explicitly.

The workflow does not use `NPM_TOKEN`. Publishing updates the `canary` or `pr-N`
tag, and closing a PR removes its tag. Superseded versions remain installable and
are no longer automatically deprecated because `npm deprecate` does not support
OIDC.

[^1]: This package is maintained by the DevX team. Prismic employees can ask for help or a review in the [#team-devx](https://prismic-team.slack.com/archives/C014VAACCQL) Slack channel.

[^2]: Prismic employees are highly encouraged to discuss changes with the DevX team in the [#team-devx](https://prismic-team.slack.com/archives/C014VAACCQL) Slack channel before starting.
Expand Down
Loading