Repository navigation
Conversation
FNA-1654 Long-lived npm tokens are no longer permitted, so the expired NPM_TOKEN cannot be rotated and keyless publishing via GitHub OIDC is the only route to releasing. This is the workflow half of that change, which needs no npm account access and is safe to merge before the trusted-publisher entries are registered on npmjs.org. Split the single release job in two. The `release` job opens the version PR as before. A new `publish` job does the publishing, so that the `production` approval gate applies only to actual releases rather than to every merge into main. The publish job declares id-token: write, runs on Node 24, and installs npm 11 explicitly, since OIDC trusted publishing requires npm 11.5.1 or newer and Node 24 does not bundle a new enough npm in every release. This replaces the npm@10 pin, which dated to the Node 16 era and capped npm below that minimum. Dropped the registry-url added in #566 along with the NPM_TOKEN and NODE_AUTH_TOKEN env vars. They exist to make a token-based publish work; under OIDC the .npmrc _authToken line they produce would make npm try a dead credential instead of exchanging its OIDC token. Publishing does not work until the six trusted-publisher entries are registered on npmjs.org. That is the remaining half of FNA-1654. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
jannoteelem
approved these changes
Sep 22, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
FNA-1654 · blocked release: FNA-1653 · registration request: SSCHELP-3009 · npm publishing guide
Important
This does not make the release work on its own. Publishing stays broken until the six trusted-publisher entries are registered on npmjs.org, which needs a package-owner login and is the other half of FNA-1654.
Status (2026-09-30): SSC has set up a JFrog OIDC provider for the twilio-labs org (
github-actions-twilio-labs), which is for curated dependency resolution, not publishing. The npm trusted-publisher registration for all six packages is still outstanding and being chased in SSCHELP-3009.Why
The
NPM_TOKENsecret is expired and cannot be rotated — long-lived npm tokens are no longer permitted. So keyless publishing via GitHub OIDC is not a nice-to-have follow-up any more, it's the only route to releasing.twilio-run@6.0.0and five other packages are sitting unpublished behind this.This is the workflow half. It needs no npm account access and is safe to merge ahead of registration.
Changes
Split the release job in two.
releaseopens the version PR exactly as before; a newpublishjob does the publishing. This matters because theproductionapproval gate has to sit on the publish job only. Left as one job, every merge intomainwould wait on a reviewer just to open a version PR.publishjob:id-token: write, Node 24, and an explicitnpm i -g npm@11. OIDC trusted publishing needs npm ≥ 11.5.1, and Node 24 does not bundle a new enough npm in every release, so the minimum is installed rather than assumed. This replaces thenpm i -g npm@10pin, which dated to the Node 16 era (8f0d104) and capped npm below the minimum — it had gone from vestigial to actively blocking.Removed the token plumbing: the
registry-urladded in #566, plus theNPM_TOKEN/NODE_AUTH_TOKENenv vars. Those exist to make a token-based publish work. Under OIDC the.npmrc_authTokenline they produce is actively harmful, because npm would try a dead credential instead of exchanging its OIDC token. Publishing targetsregistry.npmjs.org, which is npm's default; curated Artifactory is for resolving dependencies, not a publish target.Explicit
permissionsblocks. Worth a careful look: an explicit block replaces the repository defaults, so every scope has to be listed.releaseneedscontents: writeandpull-requests: writeto push the branch and open the PR;publishneedscontents: writefor the tag push andid-token: writefor OIDC.What this PR does not do
on-merge-main.yml, and theproductionenvironment. Needs a login astwilio-labs-ciortwilio-serverless. All six packages already exist on npm, so the guide's one-time manual seed publish does not apply. Requested in SSCHELP-3009.productionenvironment protection rules. The job references the environment, but required reviewers have to be set separately (gh api --method PUT repos/twilio-labs/serverless-toolkit/environments/production). Until they are, the environment exists without a gate and publishing is not paused. Note the wait timer is in minutes — leave it at 0.artifactory-oidcstep must run aftersetup-node, withprovider-name: github-actions-twilio-labs(the action defaults togithub-actions, which is not configured for this org). Keep it out of thepublishjob: it writes an Artifactoryregistry=into~/.npmrc, andchangeset publishwould then try to publish there.Decision for reviewers
Adding required reviewers to
productionturns every release into a manual approval, where today it auto-publishes on merge. The guide recommends the gate. The job split means you can adopt it without gating version PRs, but it is still a real change to how the team ships.Open question
Keyless publish with changesets is expected to work but I have not found it demonstrated.
changeset publishshells out tonpm publishper package and the OIDC exchange happens inside the npm CLI, so with npm ≥ 11.5.1 and a trusted publisher per package it should be fine. Worth noting the guide's monorepo section does not show a keyless multi-package publish; it recommends deferring. Suggest verifying with one package before assuming all six, and keeping a manual publish in reserve for the first release.Testing
Workflow changes cannot be exercised from a PR branch: this workflow only runs on
pushtomain. What I verified:publishneedsrelease, gated onneeds.release.outputs.has_changesets == 'false', withenvironment: productionsetup-nodesteps receive only{node-version: 24}— noregistry-urlsurvives except in an explanatory commentNPM_TOKENandnpm@10remainmain, just moved behind anif:instead of the oldif/elseorigin/main(1669e74) with this single commit🤖 Generated with Claude Code