Skip to content

ci: publish by trusted publishing again - #309

Merged
ralyodio merged 1 commit into
mainfrom
ci/trusted-publishing-again
Aug 6, 2026
Merged

ci: publish by trusted publishing again#309
ralyodio merged 1 commit into
mainfrom
ci/trusted-publishing-again

Conversation

@ralyodio

@ralyodio ralyodio commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Switches the publish workflow back to trusted publishing (OIDC). npm trades the short-lived token GitHub mints for this specific workflow run for permission to publish, so there is no long-lived credential in the repository at all.

This is the version from 18d9084 restored, plus one addition below.

What is new versus last time

The first attempt failed in a way that named neither OIDC nor trusted publishing:

npm error code E404
npm error 404 Not Found - PUT https://registry.npmjs.org/moshcode
npm error 404  ... could not be found or you do not have permission

With no publisher registered there is no credential in the run at all, and npm reports it as though the package does not exist. The workflow header now spells that out, because working it out cost a release.

Unrelated, already fixed

The E422 that stopped v0.24.1 was a different problem — missing repository in package.json, which provenance is validated against. That landed in #308, and v0.24.2 published successfully with a SLSA attestation. Provenance stays automatic under trusted publishing, so the explicit --provenance flag is gone.

Still required

The publisher must be registered on npmjs.com for the moshcode package, against this file's namepublish.yml:

field value
Organization or user moshcoder
Repository moshcode
Workflow filename publish.yml
Environment (leave empty)
Allowed actions npm publish

Nothing in the repo can verify this — the registry does not expose trusted-publisher config, which I checked. The next release is the proof. A dispatch run cannot test it, because 0.24.2 is already published and the skip guard would stop before the publish.

Verification

  • YAML parses; 11 steps; permissions exactly contents: read + id-token: write
  • zero secrets. references remain
  • --provenance correctly absent from the publish command (comment only)

🤖 Generated with Claude Code

Back to OIDC: npm trades the short-lived token GitHub mints for this specific
workflow run for permission to publish, so there is no long-lived credential
in the repository at all.

This is the version from 18d9084, restored, plus the failure signature we did
not have the first time. When the trusted publisher is not registered there is
no credential in the run, and npm reports that as:

  npm error code E404 ... could not be found or you do not have permission

which names neither OIDC nor trusted publishing and reads as though the
package does not exist. The header now says what it actually means, because
that cost a release to work out.

The E422 that stopped v0.24.1 is unrelated and already fixed: package.json now
carries the `repository` field provenance is checked against.

Still requires the publisher to be registered on npmjs.com against this file's
name, `publish.yml`. Nothing in the repository can verify that — the registry
does not expose it — so the next release is the proof.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

92 finding(s)

HIGH/CRITICAL: 50 | MEDIUM: 42

Severity Rule Location
HIGH manifest-typosquat apps/pwa/package.json:19
HIGH js-ssrf-outbound-request apps/pwa/public/sw.js:45
HIGH secret-generic-credential apps/pwa/test/apikey-bearer-scheme.test.mjs:30
HIGH secret-generic-credential apps/pwa/test/apikey-mask.test.mjs:38
HIGH secret-generic-credential apps/pwa/test/apikey-reveal.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/approvals-context.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/approvals-credits.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/approvals-notify.test.mjs:26
HIGH secret-generic-credential apps/pwa/test/approvals-resolve-race.test.mjs:20
HIGH secret-generic-credential apps/pwa/test/auth-form-email.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/auth-form-email.test.mjs:33
HIGH secret-generic-credential apps/pwa/test/auth-page-error.test.mjs:36
HIGH secret-generic-credential apps/pwa/test/cli-device-token.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/cli-pages-balance.test.mjs:32
HIGH secret-generic-credential apps/pwa/test/cli-token.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/credits-pack.test.mjs:51
HIGH secret-generic-credential apps/pwa/test/credits-webhook-event-match.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/credits-webhook.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/csrf-input-escaping.test.mjs:31
HIGH secret-generic-credential apps/pwa/test/csrf-input-escaping.test.mjs:101
HIGH secret-generic-credential apps/pwa/test/logout-csrf.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/moshpit-api-key.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-bulk-claim.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-claim-full-name.test.mjs:29
HIGH secret-generic-credential apps/pwa/test/moshpit-crawlable.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-ending-page.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-pins.test.mjs:22
HIGH secret-generic-credential apps/pwa/test/moshpit-pit-page.test.mjs:33
HIGH secret-generic-credential apps/pwa/test/moshpit-records-page.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-records.test.mjs:23
HIGH secret-generic-credential apps/pwa/test/moshpit-registry.test.mjs:20
HIGH secret-generic-credential apps/pwa/test/moshpit-related-endings.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/moshpit-sales.test.mjs:16
HIGH secret-generic-credential apps/pwa/test/moshpit-search.test.mjs:74
HIGH secret-generic-credential apps/pwa/test/moshpit-terms.test.mjs:19
HIGH secret-generic-credential apps/pwa/test/moshpit-tlds-pagination.test.mjs:28
HIGH secret-generic-credential apps/pwa/test/passkey-register-duplicate.test.mjs:38
HIGH secret-generic-credential apps/pwa/test/require-auth-next.test.mjs:31
HIGH secret-generic-credential apps/pwa/test/require-auth-next.test.mjs:35
HIGH secret-generic-credential apps/pwa/test/sessions-output-seq.test.mjs:30
HIGH secret-generic-credential apps/pwa/test/sessions-paste.test.mjs:24
HIGH secret-generic-credential apps/pwa/test/sessions-stream-replay.test.mjs:34
HIGH secret-generic-credential apps/pwa/test/sessions.test.mjs:24
HIGH secret-generic-credential apps/pwa/test/signature.test.mjs:6
HIGH secret-generic-credential test/auth.test.mjs:13
HIGH secret-generic-credential test/auth.test.mjs:63
HIGH secret-generic-credential test/console-cookie-malformed.test.mjs:15
HIGH secret-generic-credential test/console.test.mjs:12
HIGH secret-generic-credential test/mirror.test.mjs:37
HIGH secret-generic-credential test/mirror.test.mjs:77

…and 42 more. Full results in the Security tab.

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit a8548bc into main Aug 6, 2026
4 checks passed
@ralyodio
ralyodio deleted the ci/trusted-publishing-again branch August 6, 2026 05:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant