Skip to content

fix(ci): drop registry-url — placeholder token preempts OIDC publish - #8

Merged
just-shane merged 1 commit into
mainfrom
fix/publish-oidc-registry-url
Aug 11, 2026
Merged

just-shane merged 1 commit into
mainfrom
fix/publish-oidc-registry-url

Conversation

@just-shane

Copy link
Copy Markdown
Contributor

Same fix that unblocked capitoltrace-ui@0.1.1: registry-url makes setup-node write an .npmrc wired to a placeholder NODE_AUTH_TOKEN, and npm sends that garbage token instead of doing the OIDC exchange → masked E404 at publish. Dropping it lets trusted publishing engage (verified working, provenance attached, on the ui release).

🤖 Generated with Claude Code

…OIDC

Proven on capitoltrace-ui's first trusted publish: registry-url makes
setup-node write an .npmrc wired to a placeholder NODE_AUTH_TOKEN and npm
sends that garbage token instead of performing the OIDC exchange, failing
with a masked E404. Without registry-url, npm defaults to
registry.npmjs.org and trusted publishing engages (ui 0.1.1 published
with provenance on exactly this configuration).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@just-shane
just-shane merged commit 62e7b6a into main Aug 11, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant