Skip to content

Commit 40f4a4d

Browse files
committed
npm: no access token
1 parent 251957a commit 40f4a4d

File tree

1 file changed

+7
-5
lines changed

1 file changed

+7
-5
lines changed

.github/workflows/push_dist_to_npm.yml

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -4,17 +4,21 @@ on:
44
branches:
55
- master
66

7+
permissions:
8+
id-token: write # Required for OIDC
9+
contents: read
10+
711
jobs:
812
publish:
913
if: github.repository_owner == 'graphhopper'
10-
runs-on: ubuntu-22.04
14+
runs-on: ubuntu-latest
1115
environment: npm
1216
steps:
1317
- name: Checkout
14-
uses: actions/checkout@v3
18+
uses: actions/checkout@v4
1519

1620
- name: Setup Node.js
17-
uses: actions/setup-node@v3
21+
uses: actions/setup-node@v4
1822
with:
1923
registry-url: https://registry.npmjs.org/
2024
node-version: v20.14.0
@@ -31,5 +35,3 @@ jobs:
3135
node -e "const packageJson=require('./package.json'); packageJson.scripts={}; packageJson.dependencies={}; packageJson.devDependencies={}; require('fs').writeFileSync('package.json', JSON.stringify(packageJson, null, 4));"
3236
# we need to set the access to public, because organization scoped packages are private by default
3337
npm publish --access public
34-
env:
35-
NODE_AUTH_TOKEN: ${{ secrets.NPM_JS_ORG_ACCESS_TOKEN }}

0 commit comments

Comments
 (0)