Skip to content

docs: the registry-side trusted publisher is owner work, not a given - #15

Merged
firejune merged 1 commit into
mainfrom
docs/registry-side-status
Aug 23, 2026
Merged

docs: the registry-side trusted publisher is owner work, not a given#15
firejune merged 1 commit into
mainfrom
docs/registry-side-status

Conversation

@firejune

Copy link
Copy Markdown
Owner

The first two automated publish runs proved the workflow side end to end — release PR driven to a tested merge, tags and GitHub releases cut, OIDC id-token minted (run 1 even signed a provenance statement) — and then failed at the registry with ENEEDAUTH: npm found no trusted publisher to exchange its token with. So the Trusted Publisher form on npmjs.com is not (correctly) in place yet for headerless / vite-plugin-headerless. Record that honestly: it is owner work the automation can neither do nor verify, and until it matches, every automated publish fails this way.

The first two automated publish runs proved the workflow side end to
end (PR driven to a tested merge, tags and releases cut, OIDC id-token
minted) and then failed at the registry: ENEEDAUTH, npm finding no
trusted publisher to exchange its token with. Record that state
honestly instead of assuming the form is filled.
@firejune
firejune enabled auto-merge (squash) August 23, 2026 11:27
@firejune
firejune merged commit e11c792 into main Aug 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant