diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 2784ab46e..7fb597e64 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -49,6 +49,11 @@ jobs: release: runs-on: ubuntu-latest timeout-minutes: 20 + # npm trusted publishing: auth comes from the GitHub OIDC token, so no + # NPM_TOKEN secret is needed. contents: write covers tag pushes and releases. + permissions: + contents: write + id-token: write steps: - name: Checkout repo uses: actions/checkout@v4 @@ -58,9 +63,12 @@ jobs: - name: Setup repo uses: ./.github/actions/setup + # pnpm 10 publish delegates to npm, which needs >=11.5.1 for OIDC. + # pnpm 11+ publishes natively, so re-verify OIDC when bumping pnpm. + - name: Update npm + run: npm install -g npm@^11.5.1 + - name: Create and publish versions run: pnpm ci:publish env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/ark/regex/package.json b/ark/regex/package.json index 8ce18a22d..0ded04cef 100644 --- a/ark/regex/package.json +++ b/ark/regex/package.json @@ -3,6 +3,11 @@ "description": "A drop-in replacement for new RegExp() with types", "version": "0.0.10", "license": "MIT", + "repository": { + "type": "git", + "url": "https://github.com/arktypeio/arktype.git", + "directory": "ark/regex" + }, "author": { "name": "David Blass", "email": "david@arktype.io", diff --git a/ark/util/package.json b/ark/util/package.json index fbee5eb87..0f471ae03 100644 --- a/ark/util/package.json +++ b/ark/util/package.json @@ -2,6 +2,11 @@ "name": "@ark/util", "version": "0.56.4", "license": "MIT", + "repository": { + "type": "git", + "url": "https://github.com/arktypeio/arktype.git", + "directory": "ark/util" + }, "author": { "name": "David Blass", "email": "david@arktype.io",