From 6ba03568130caa1feb85514ac3984b35e9ad99f0 Mon Sep 17 00:00:00 2001 From: raj pandey Date: Thu, 1 Oct 2026 13:49:35 +0530 Subject: [PATCH 1/2] chore(release): publish to npm with trusted publishing Publish on release:published from release.yml so the npm trusted publisher can be keyed on the filename, drop NODE_AUTH_TOKEN in favour of id-token: write (OIDC), run on Node 24 with npm@latest (trusted publishing needs npm >= 11.5.1), check out the release tag without persisted credentials. GitHub pre-releases go to the beta dist-tag. The existing guard that publishes only v-prefixed tags is kept. The GitHub Packages job gains the packages: write permission it was missing and publishes with the job's own token instead of a personal token. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/npm-publish.yml | 40 ------------------------ .github/workflows/release.yml | 51 +++++++++++++++++++++++++++++++ 2 files changed, 51 insertions(+), 40 deletions(-) delete mode 100644 .github/workflows/npm-publish.yml create mode 100644 .github/workflows/release.yml diff --git a/.github/workflows/npm-publish.yml b/.github/workflows/npm-publish.yml deleted file mode 100644 index 3f8b11c..0000000 --- a/.github/workflows/npm-publish.yml +++ /dev/null @@ -1,40 +0,0 @@ -# This workflow publishes packages when a GitHub Release is created for a version tag. -# For more information see: https://help.github.com/actions/language-and-framework-guides/publishing-nodejs-packages - -name: Publish package to NPM repository -on: - release: - types: [created] - -jobs: - publish-npm: - if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - with: - ref: ${{ github.event.release.tag_name }} - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://registry.npmjs.org' - - run: npm ci - - run: npm publish - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - publish-git: - if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - with: - ref: ${{ github.event.release.tag_name }} - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://npm.pkg.github.com' - scope: '@contentstack' - - run: npm ci - - run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.GIT_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..cd933f4 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,51 @@ +name: Publish package to npmjs registry +on: + release: + types: [published] + +jobs: + publish-npm: + if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} + runs-on: ubuntu-latest + permissions: + contents: read + id-token: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://registry.npmjs.org/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }} + + publish-github: + if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://npm.pkg.github.com/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish + env: + NODE_AUTH_TOKEN: ${{ github.token }} From 16776d09838782a1cbcdea2d3a11786b2eaa4721 Mon Sep 17 00:00:00 2001 From: raj pandey Date: Thu, 1 Oct 2026 14:03:15 +0530 Subject: [PATCH 2/2] fix(ci): grant the coverage report checks and pull-request write The build-test job runs with the default read-only token, so the coverage report, sticky comment and test reporter fail with "Missing checks: write" even though the tests pass (red on every pull request since 2026-09-24). Grant the job just what those steps need, pin the coverage action to the commit the v2 tag resolves to today, and exempt the pinned file from Talisman's hex-string check. Co-Authored-By: Claude Fable 5.1 --- .github/workflows/ci.yml | 6 +++++- .talismanrc | 2 ++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ac17520..d742ce6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -9,9 +9,13 @@ on: jobs: build-test: runs-on: ubuntu-latest + permissions: + contents: read + checks: write + pull-requests: write steps: - uses: actions/checkout@v3 - - uses: ArtiomTr/jest-coverage-report-action@v2 + - uses: ArtiomTr/jest-coverage-report-action@7f750dd50f5585533321eb7ebc482b936b49a5d4 # v2 id: coverage-utils-js with: output: comment, report-markdown diff --git a/.talismanrc b/.talismanrc index 40570f0..f4811d0 100644 --- a/.talismanrc +++ b/.talismanrc @@ -4,3 +4,5 @@ fileignoreconfig: - filecontent - filename: package-lock.json checksum: 8e62821551e64c0fbd23ce2951b44e41561196f0d38b6a2da7de1f6921b48865 + - filename: .github/workflows/ci.yml + checksum: 14991153c5531029f3ac14dbce6fab70aa4b654d445a3514083d446bfadc8813