From 301341ab231059f364fbe968043c1579601aa8c9 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 18 Mar 2026 07:35:57 +0000 Subject: [PATCH] fix(release): publish from release events without npm token Co-authored-by: okikio <17222836+okikio@users.noreply.github.com> --- .github/workflows/publish.yml | 8 +------- CHANGELOG.md | 4 ++-- README.md | 1 - tests/publishing_setup_test.ts | 29 +++++++++++++++++++++++++++-- 4 files changed, 30 insertions(+), 12 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 686dc94..80d43a0 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -8,7 +8,7 @@ # Release flow: # push to main or manual release-and-publish dispatch # -> semantic-release creates the GitHub Release -# -> this same workflow publishes the tagged commit to JSR and npm +# -> the published release event publishes the tagged commit to JSR and npm # # Publish-only flow: # published GitHub Release or manual publish-only dispatch @@ -138,8 +138,6 @@ jobs: DISPATCH_ACTION: ${{ inputs.action }} DISPATCH_TAG: ${{ inputs.tag }} DISPATCH_TARGET: ${{ inputs.target }} - RELEASED: ${{ needs.release.outputs.released }} - RELEASE_JOB_TAG: ${{ needs.release.outputs.tag }} run: | TAG="" TARGET="both" @@ -149,8 +147,6 @@ jobs: elif [ "$EVENT_NAME" = "workflow_dispatch" ] && [ "$DISPATCH_ACTION" = "publish-only" ]; then TAG="$DISPATCH_TAG" TARGET="$DISPATCH_TARGET" - elif [ "$RELEASED" = "true" ]; then - TAG="$RELEASE_JOB_TAG" fi if [ "$EVENT_NAME" = "workflow_dispatch" ] && [ "$DISPATCH_ACTION" = "publish-only" ] && [ -z "$TAG" ]; then @@ -222,5 +218,3 @@ jobs: run: | cd npm npm publish --provenance --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/CHANGELOG.md b/CHANGELOG.md index 792c602..39d982b 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,9 +1,9 @@ ## [1.0.1](https://github.com/okikio/observables/compare/v1.0.0...v1.0.1) (2026-03-18) - ### Bug Fixes -* **release:** allow publish-only registry retries ([b51c952](https://github.com/okikio/observables/commit/b51c9521d5fccc4da0ee3d38ae3f5905d7237221)) +- **release:** allow publish-only registry retries + ([b51c952](https://github.com/okikio/observables/commit/b51c9521d5fccc4da0ee3d38ae3f5905d7237221)) # 1.0.0 (2026-03-18) diff --git a/README.md b/README.md index a632cb6..990cda7 100644 --- a/README.md +++ b/README.md @@ -9,7 +9,6 @@ [npm](https://www.npmjs.com/package/@okikio/observables) • [GitHub](https://github.com/okikio/observables#readme) • [License](./LICENSE) - A **spec-faithful** yet ergonomic TC39-inspired Observable implementation that diff --git a/tests/publishing_setup_test.ts b/tests/publishing_setup_test.ts index 897d926..1fc7052 100644 --- a/tests/publishing_setup_test.ts +++ b/tests/publishing_setup_test.ts @@ -51,13 +51,38 @@ describe("publishing setup", () => { "publish_npm: ${{ steps.resolve.outputs.publish_npm }}", ); expect(publish_workflow).toContain( - "always() && needs.resolve-release.outputs.publish_jsr == 'true'", + "always() && needs.resolve-release.outputs.should_publish == 'true' && needs.resolve-release.outputs.publish_jsr == 'true'", ); expect(publish_workflow).toContain( - "always() && needs.resolve-release.outputs.publish_npm == 'true'", + "always() && needs.resolve-release.outputs.should_publish == 'true' && needs.resolve-release.outputs.publish_npm == 'true'", ); }); + it("publishes only from release events or explicit publish-only retries", () => { + const publish_workflow = readRepoFile(".github/workflows/publish.yml"); + + expect(publish_workflow).toContain( + "the published release event publishes the tagged commit to JSR and npm", + ); + expect(publish_workflow).not.toContain( + "RELEASED: ${{ needs.release.outputs.released }}", + ); + expect(publish_workflow).not.toContain("RELEASE_JOB_TAG"); + expect(publish_workflow).not.toContain('elif [ "$RELEASED" = "true" ]'); + }); + + it("uses npm trusted publishing without requiring a token secret", () => { + const publish_workflow = readRepoFile(".github/workflows/publish.yml"); + + expect(publish_workflow).toContain( + "npm publish --provenance --access public", + ); + expect(publish_workflow).toContain( + "no NODE_AUTH_TOKEN secret is required here.", + ); + expect(publish_workflow).not.toContain("NODE_AUTH_TOKEN:"); + }); + it("pins publishing-script JSR imports to explicit versions", () => { const build_script = readRepoFile("scripts/build_npm.ts"); -- 2.51.2