Repository navigation
fix: restore npm auth and tag pushing in release workflow - #566
Merged
Merged
Conversation
FNA-1653 Every package fails to publish with ENEEDAUTH. The NPM_TOKEN and NODE_AUTH_TOKEN env vars on the publish step look like authentication but have no effect on their own: npm never reads NPM_TOKEN, and NODE_AUTH_TOKEN is only consumed through an .npmrc that references it — which actions/setup-node writes only when given a registry-url. Nothing has written an authenticated .npmrc since changesets/action@v1 was replaced in #559, so npm had no credentials at all. Pass registry-url to setup-node so the .npmrc is written, and push tags after a successful publish — changeset publish creates a tag per package and changesets/action used to push them, which is why the newest tag in the repo is twilio-run@5.0.1. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
jannoteelem
approved these changes
Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
FNA-1653 · follow-up to FNA-1286 / #559
Important
The release pipeline has not published anything since June. npm is two releases behind
main.Problem
Every package fails to publish:
#559 replaced
changesets/action@v1with equivalent shell commands to get around the enterprise Actions policy. That action did two things beyond versioning and publishing, and both were lost in the swap:.npmrcbefore publishing. Nothing does that now. TheNPM_TOKEN/NODE_AUTH_TOKENenv vars on the publish step look like auth but have no effect on their own — npm never readsNPM_TOKEN, andNODE_AUTH_TOKENis only consumed through an.npmrcthat references it, whichactions/setup-nodewrites only when given aregistry-url. This workflow never passed one, so npm had no credentials at all.changeset publishcreates a git tag per published package andchangesets/actionpushed them. The workflow does not, which is why the newest tag in the repo istwilio-run@5.0.1.Impact
Versions were bumped and committed, but nothing reached npm:
maintwilio-runcreate-twilio-functiontwilio-run@5.1.0(#561) was never published either. The failure is invisible from outside the Actions log, so it went unnoticed for ~3 months until the 6.0.0 release attempt surfaced it.Change
Eight added lines, six of which are comments explaining why each is load-bearing, so the next person refactoring this step doesn't drop them again.
Before merging — needs someone with repo admin access
Please confirm the
NPM_TOKENrepository secret still exists and is valid.ENEEDAUTHmeans no credentials were presented at all, which the missing.npmrcfully explains — but if the secret is also empty or expired, this change moves the failure toE401rather than fixing it. The token needs publish rights on all six packages, and must be an automation token if 2FA-on-publish is enabled.I could not verify this myself.
Recovery after merge
changeset publishskips versions already on npm, so re-running the release job onmainis safe and idempotent — it will publish 6.0.0 and everything else currently missing in one pass.Note the intermediate
5.1.0/4.1.0versions will be skipped permanently:mainhas moved past them, so those numbers will never exist on npm unless someone publishes them by hand. Worth a deliberate decision rather than a surprise.Testing
Workflow changes can't be exercised from a PR branch — the release job only runs on
pushtomain. What I did verify:setup-nodereceives{node-version: 22, registry-url: 'https://registry.npmjs.org'}origin/main(84058ed) with this commit as the only changetwilio-run@5.1.0andcreate-twilio-function@4.1.0are genuinely absent, and that no tag newer thantwilio-run@5.0.1exists in the repo🤖 Generated with Claude Code