From f45b382e54b22b7b412f84ad2f2df37ecf305b68 Mon Sep 17 00:00:00 2001 From: Andre Lars Da Cunha Date: Mon, 21 Sep 2026 11:59:04 +0200 Subject: [PATCH] fix: restore npm auth and tag pushing in release workflow MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit FNA-1653 Every package fails to publish with ENEEDAUTH. The NPM_TOKEN and NODE_AUTH_TOKEN env vars on the publish step look like authentication but have no effect on their own: npm never reads NPM_TOKEN, and NODE_AUTH_TOKEN is only consumed through an .npmrc that references it — which actions/setup-node writes only when given a registry-url. Nothing has written an authenticated .npmrc since changesets/action@v1 was replaced in #559, so npm had no credentials at all. Pass registry-url to setup-node so the .npmrc is written, and push tags after a successful publish — changeset publish creates a tag per package and changesets/action used to push them, which is why the newest tag in the repo is twilio-run@5.0.1. Co-Authored-By: Claude Opus 5 --- .github/workflows/on-merge-main.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/workflows/on-merge-main.yml b/.github/workflows/on-merge-main.yml index e64ea07d..50239e98 100644 --- a/.github/workflows/on-merge-main.yml +++ b/.github/workflows/on-merge-main.yml @@ -25,6 +25,10 @@ jobs: uses: actions/setup-node@3235b876344d2a9aa001b8d1453c930bba69e610 # v3 with: node-version: 22 + # Required for publishing: this is what writes an .npmrc wired up to + # NODE_AUTH_TOKEN. Without it npm has no credentials at all and every + # publish fails with ENEEDAUTH. + registry-url: 'https://registry.npmjs.org' - name: Update npm to 10.x run: | npm i -g npm@10 @@ -70,6 +74,10 @@ jobs: else # No changesets — publish any packages whose version exceeds what is on npm npm run npm:publish + # changeset publish creates a git tag per published package; push + # them so releases stay traceable from the repo. changesets/action + # used to do this before it was replaced in #559. + git push origin --follow-tags fi env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}