Skip to content

fix: restore npm auth and tag pushing in release workflow - #566

Merged
AndreLars merged 1 commit into
mainfrom
fna-1653-release-npm-auth
Sep 21, 2026
Merged

AndreLars merged 1 commit into
mainfrom
fna-1653-release-npm-auth

Conversation

@AndreLars

Copy link
Copy Markdown
Contributor

FNA-1653 · follow-up to FNA-1286 / #559

Important

The release pipeline has not published anything since June. npm is two releases behind main.

Problem

Every package fails to publish:

npm error code ENEEDAUTH
npm error need auth This command requires you to be logged in to https://registry.npmjs.org

#559 replaced changesets/action@v1 with equivalent shell commands to get around the enterprise Actions policy. That action did two things beyond versioning and publishing, and both were lost in the swap:

  1. npm authentication. It wrote an authenticated .npmrc before publishing. Nothing does that now. The NPM_TOKEN / NODE_AUTH_TOKEN env vars on the publish step look like auth but have no effect on their own — npm never reads NPM_TOKEN, and NODE_AUTH_TOKEN is only consumed through an .npmrc that references it, which actions/setup-node writes only when given a registry-url. This workflow never passed one, so npm had no credentials at all.
  2. Tag pushing. changeset publish creates a git tag per published package and changesets/action pushed them. The workflow does not, which is why the newest tag in the repo is twilio-run@5.0.1.

Impact

Versions were bumped and committed, but nothing reached npm:

Package Latest on npm Version on main
twilio-run 5.0.1 6.0.0
create-twilio-function 4.0.0 5.0.0

twilio-run@5.1.0 (#561) was never published either. The failure is invisible from outside the Actions log, so it went unnoticed for ~3 months until the 6.0.0 release attempt surfaced it.

Change

      - name: Setup Node.js 22
        uses: actions/setup-node@...
        with:
          node-version: 22
+         registry-url: 'https://registry.npmjs.org'   # writes the .npmrc
...
            npm run npm:publish
+           git push origin --follow-tags

Eight added lines, six of which are comments explaining why each is load-bearing, so the next person refactoring this step doesn't drop them again.

Before merging — needs someone with repo admin access

Please confirm the NPM_TOKEN repository secret still exists and is valid. ENEEDAUTH means no credentials were presented at all, which the missing .npmrc fully explains — but if the secret is also empty or expired, this change moves the failure to E401 rather than fixing it. The token needs publish rights on all six packages, and must be an automation token if 2FA-on-publish is enabled.

I could not verify this myself.

Recovery after merge

changeset publish skips versions already on npm, so re-running the release job on main is safe and idempotent — it will publish 6.0.0 and everything else currently missing in one pass.

Note the intermediate 5.1.0 / 4.1.0 versions will be skipped permanently: main has moved past them, so those numbers will never exist on npm unless someone publishes them by hand. Worth a deliberate decision rather than a surprise.

Testing

Workflow changes can't be exercised from a PR branch — the release job only runs on push to main. What I did verify:

  • The file parses as valid YAML and setup-node receives {node-version: 22, registry-url: 'https://registry.npmjs.org'}
  • The branch is a clean copy of origin/main (84058ed) with this commit as the only change
  • Confirmed against the npm registry that twilio-run@5.1.0 and create-twilio-function@4.1.0 are genuinely absent, and that no tag newer than twilio-run@5.0.1 exists in the repo

🤖 Generated with Claude Code

FNA-1653

Every package fails to publish with ENEEDAUTH. The NPM_TOKEN and
NODE_AUTH_TOKEN env vars on the publish step look like authentication
but have no effect on their own: npm never reads NPM_TOKEN, and
NODE_AUTH_TOKEN is only consumed through an .npmrc that references it —
which actions/setup-node writes only when given a registry-url. Nothing
has written an authenticated .npmrc since changesets/action@v1 was
replaced in #559, so npm had no credentials at all.

Pass registry-url to setup-node so the .npmrc is written, and push tags
after a successful publish — changeset publish creates a tag per
package and changesets/action used to push them, which is why the
newest tag in the repo is twilio-run@5.0.1.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Sep 21, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: f45b382

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@AndreLars
AndreLars merged commit 1669e74 into main Sep 21, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants