From a9bb2e2f8b4df15c63d9dc6fa1e797d30e0cf352 Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Wed, 4 Feb 2026 11:09:56 -0500 Subject: [PATCH] Fix npm trusted publishing in release workflow Bump setup-node to v6 and add npm upgrade step to ensure npm >= 11.5.1, which is required for OIDC-based trusted publishing to work. --- .github/workflows/publish_artifacts.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/publish_artifacts.yaml b/.github/workflows/publish_artifacts.yaml index 4329d28cc81..dcb68f85594 100644 --- a/.github/workflows/publish_artifacts.yaml +++ b/.github/workflows/publish_artifacts.yaml @@ -38,7 +38,7 @@ jobs: - name: Read Node.js version id: node-version run: echo "version=$(cat client/.node_version)" >> $GITHUB_OUTPUT - - uses: actions/setup-node@v5 + - uses: actions/setup-node@v6 with: node-version: ${{ steps.node-version.outputs.version }} cache: 'yarn' @@ -47,6 +47,9 @@ jobs: - name: build client run: yarn && yarn build-production working-directory: 'client' + # Ensure npm 11.5.1 or later for trusted publishing + - run: npm install -g npm@latest + working-directory: 'client' - name: publish client if: "!github.event.release.prerelease" run: npm publish --provenance --access public