Repository navigation
ci: publish the 1.x line to npm with trusted publishing, so the next 1.x release does not fail at npm - #349
Merged
Conversation
The npm token secret no longer publishes: ipyvue's 1.x and 3.x releases failed at npm publish with E404 on PUT until ipyvue switched to npm trusted publishing (OIDC). This release job still used NODE_AUTH_TOKEN with node 14, so the next 1.x release would fail the same way. It now gets an id-token, uses node 22 with the newest npm (trusted publishing needs npm 11.5.1 or newer), and publishes without a token, as ipyvue 1.x does since 0c1b9cf. The master (3.x) workflow already publishes this way. The npm trusted publisher for jupyter-vuetify must allow this workflow file (test.yml). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
maartenbreddels
marked this pull request as ready for review
October 6, 2026 08:16
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The 1.x release job now publishes to npm with trusted publishing, because the npm token no longer works and the next 1.x release would fail at npm publish.
Problem
The 1.x line has an unreleased fix: #347 (core-js update) and the commits after 1.11.3.
Its release job publishes to npm with the
NPM_TOKENsecret and node 14.ipyvue's releases of 3.1.0 and 1.13.0 failed at that step with
E404 Not Found - PUT, until ipyvue switched to npm trusted publishing.ipyvuetify 1.x uses the same old setup, so its next release would publish to PyPI and then fail on npm.
Change
The
releasejob in.github/workflows/test.yml:id-token: write, which trusted publishing (OIDC) needs;NODE_AUTH_TOKEN.This is the same change as ipyvue's 1.x commit 0c1b9cf, which published
jupyter-vue1.13.0. ipyvuetify master (3.x) already publishes this way.The PyPI step, the
latest-1npm tag and therelease-dry-runjob do not change.Validation
Gaps
jupyter-vuetifyon npmjs.com must allow the repositorywidgetti/ipyvuetifywith the workflow filetest.yml. Master uses the same file name, so the existing setting may already cover it. Maarten has to check this on npmjs.com.js/package.jsonalready points atwidgetti/ipyvuetify, which npm's provenance check needs.Align results
Caution
/alignwas not run on this change: a release-pipeline fix that the ipyvue release session found while it published ipyvue 3.1.0 and 1.13.0.Crossreview results
Round 1, by astra and gpt-6.1-sol. Neither found a defect. Both noted the one thing git cannot check: npm must list
widgetti/ipyvuetifywithtest.ymlas a trusted publisher forjupyter-vuetify(see Gaps).🤖 Generated with Claude Code