Skip to content

Conversation

@andy-chhuon
Copy link
Contributor

@andy-chhuon andy-chhuon commented Dec 15, 2025

Background

Migrate from npm to OIDC according to docs to avoid 404 error

Also see, #3650 (comment)

image

@andy-chhuon andy-chhuon self-assigned this Dec 15, 2025
@fatbattk fatbattk force-pushed the add-oidc-rc-branch branch 2 times, most recently from 279363c to 528e491 Compare December 16, 2025 00:35
@fatbattk
Copy link
Contributor

fatbattk commented Dec 16, 2025

Update

  • Modified to centralize to deploy.yml because npm OIDC only allows one publish flow file.
    • Works for deploy-rc consolidation but may need different strategy with the snap shots and other flows.
  • Safe to merge and test as publishing to npm does not work now.

@fatbattk fatbattk requested a review from a team December 16, 2025 00:50
@fatbattk fatbattk self-assigned this Dec 16, 2025
@andy-chhuon
Copy link
Contributor Author

andy-chhuon commented Dec 16, 2025

Thanks @fatbattk, makes sense!

context on pr:
slack

context on why only one publish file:
Slack & OIDC docs (control-F for '404' - vault doesn't link correctly)

Snapit won't work as it currently does not support OIDC (currently doesn't work either with NPM token)

- id: changesets
name: Create release Pull Request or publish to NPM
uses: changesets/action@06245a4e0a36c064a573d4150030f5ec548e4fcc # v1.4.10
uses: changesets/action@v1 # Must use latest version for OIDC

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@andy-chhuon do you know what version added support for OIDC or is pinning it to a commit hash not compatible with OIDC? It would be good to keep pinned to a specific version so we don't automatically opt-into new versions.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good point, this was what is recommended in the docs but pinning it to a version makes sense. I pinned it to the latest version just in case and it's a version used throughout shopify too

image

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great, thanks @andy-chhuon ! Surprisingly the intro image does have a pinned version. Could you ping the team that owns the page about the discrepancy and ask them to update it?

image.png

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ah interesting, will do!

@andy-chhuon andy-chhuon merged commit f0df009 into 2026-01-rc Dec 16, 2025
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants