Skip to content

ci: publish the 1.x line to npm with trusted publishing, so the next 1.x release does not fail at npm - #349

Merged
maartenbreddels merged 1 commit into
1.xfrom
ci/npm-trusted-publishing-1x
Oct 6, 2026
Merged

maartenbreddels merged 1 commit into
1.xfrom
ci/npm-trusted-publishing-1x

Conversation

@maartenbreddels

Copy link
Copy Markdown
Collaborator

The 1.x release job now publishes to npm with trusted publishing, because the npm token no longer works and the next 1.x release would fail at npm publish.

Problem

The 1.x line has an unreleased fix: #347 (core-js update) and the commits after 1.11.3.
Its release job publishes to npm with the NPM_TOKEN secret and node 14.
ipyvue's releases of 3.1.0 and 1.13.0 failed at that step with E404 Not Found - PUT, until ipyvue switched to npm trusted publishing.
ipyvuetify 1.x uses the same old setup, so its next release would publish to PyPI and then fail on npm.

Change

The release job in .github/workflows/test.yml:

  • gets the permission id-token: write, which trusted publishing (OIDC) needs;
  • installs node 22 and the newest npm, because trusted publishing needs npm 11.5.1 or newer;
  • publishes without NODE_AUTH_TOKEN.

This is the same change as ipyvue's 1.x commit 0c1b9cf, which published jupyter-vue 1.13.0. ipyvuetify master (3.x) already publishes this way.
The PyPI step, the latest-1 npm tag and the release-dry-run job do not change.

Validation

  • The YAML parses.
  • Nothing runs the release job before a tag, so the first real check is the next 1.x release.

Gaps

  • The npm trusted publisher for jupyter-vuetify on npmjs.com must allow the repository widgetti/ipyvuetify with the workflow file test.yml. Master uses the same file name, so the existing setting may already cover it. Maarten has to check this on npmjs.com.
  • js/package.json already points at widgetti/ipyvuetify, which npm's provenance check needs.

Align results

Caution

/align was not run on this change: a release-pipeline fix that the ipyvue release session found while it published ipyvue 3.1.0 and 1.13.0.

Crossreview results

Round 1, by astra and gpt-6.1-sol. Neither found a defect. Both noted the one thing git cannot check: npm must list widgetti/ipyvuetify with test.yml as a trusted publisher for jupyter-vuetify (see Gaps).

🤖 Generated with Claude Code

The npm token secret no longer publishes: ipyvue's 1.x and 3.x releases failed at npm publish with E404 on PUT until ipyvue switched to npm trusted publishing (OIDC). This release job still used NODE_AUTH_TOKEN with node 14, so the next 1.x release would fail the same way. It now gets an id-token, uses node 22 with the newest npm (trusted publishing needs npm 11.5.1 or newer), and publishes without a token, as ipyvue 1.x does since 0c1b9cf. The master (3.x) workflow already publishes this way. The npm trusted publisher for jupyter-vuetify must allow this workflow file (test.yml).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@maartenbreddels
maartenbreddels marked this pull request as ready for review October 6, 2026 08:16
@maartenbreddels
maartenbreddels merged commit 2e12963 into 1.x Oct 6, 2026
16 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant