Repository navigation
Conversation
Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The existing guard that publishes only v-prefixed tags is kept. The GitHub Packages job gains the packages: write permission it was missing and publishes with the job's own token instead of a personal token. Co-Authored-By: Claude Fable 5.1 <[email protected]>
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The nonexistent checkout@v7 and setup-node@v7 versions prevent both publishing jobs from running.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Migrates package publishing to OIDC trusted publishing and GitHub-provided credentials.
Changes:
- Publishes releases using Node 24 and npm OIDC.
- Adds prerelease/latest npm tags and GitHub Packages permissions.
- Renames the publishing workflow.
| File | Description |
|---|---|
.github/workflows/release.yml |
Adds the revised release publishing workflow. |
.github/workflows/npm-publish.yml |
Removes the token-based publishing workflow. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| release: | ||
| types: [published] |
The build-test job runs with the default read-only token, so the coverage report, sticky comment and test reporter fail with "Missing checks: write" even though the tests pass (red on every pull request since 2026-09-24). Grant the job just what those steps need, pin the coverage action to the commit the v2 tag resolves to today, and exempt the pinned file from Talisman's hex-string check. Co-Authored-By: Claude Fable 5.1 <[email protected]>
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
Coverage report
Test suite run success430 tests passing in 22 suites. Report generated by 🧪jest coverage report action from 16776d0 |
Coverage report
Test suite run success430 tests passing in 22 suites. Report generated by 🧪jest coverage report action from 16776d0 |


Problem
npm-publish.ymlpublishes@contentstack/utilsto npm with a long-livedNPM_TOKEN.The SE1 publishing policy requires OIDC trusted publishing instead: no token, a
release.ymlworkflow that runs when a release is published, Node 24.The GitHub Packages job also authenticates with a personal token (
GIT_TOKEN) and lacks thepackages: writepermission.Fix
npm-publish.ymlis renamed torelease.yml. The existing guard that publishes onlyv-prefixed tags is kept. What changes inside it:release: createdrelease: publishedNPM_TOKENid-token: write, no tokennpm publishnpm publish --access public; pre-releases go to thebetadist-tag, releases tolatestGIT_TOKEN(personal token), nopackages: writegithub.tokenwithpackages: writepersist-credentials: falsecheckout@v4,setup-node@v4@v7Verification
Node 22 and Node 24: install, build, tests and
npm packall pass.Also in this PR
ci.yml'sbuild-testjob getschecks: writeandpull-requests: writeso its coverage report and test reporter can post again — they have failed on every PR since 24 Sept with the default read-only token, while the tests themselves pass. The coverage action is pinned to the commitv2resolves to today, and that file is exempted from Talisman's hex-string check in.talismanrc.