Skip to content

Conversation

@vadyvas
Copy link

@vadyvas vadyvas commented Nov 6, 2025

What issue does this pull request resolve?

The publish GitHub Actions workflow may run with an npm version that is too old for npm Trusted Publishing. To reliably use trusted publishing (with OIDC), we should ensure that the workflow runs on an npm version 11.5.1 or later, instead of relying on whatever version is preinstalled on the runner.

What changes did you make?

  • Updated the actions/setup-node step in .github/workflows/publish.yml to use Node.js 20.
  • Added a step to install npm@^11.5.1 before running any npm commands, to guarantee a version that fully supports trusted publishing.
  • Left the rest of the workflow unchanged.

Is there anything that requires more attention while reviewing?

-

@vadyvas vadyvas requested a review from tatomyr November 6, 2025 16:56
@vadyvas vadyvas marked this pull request as ready for review November 6, 2025 17:18
@vadyvas vadyvas merged commit e389611 into master Nov 6, 2025
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants