diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index b62c39406..122130310 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -371,7 +371,15 @@ jobs: - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 with: - node-version: 22 + # Node 24 ships with npm >= 11.5.x, which is the minimum that + # supports npm Trusted Publishing OIDC. Node 22 ships with npm + # 10.9.x (no OIDC) and `npm install -g npm@latest` to self-upgrade + # is fragile — it can crash the in-flight reify with + # `MODULE_NOT_FOUND` on `promise-retry` etc. Bumping the Node + # version is the clean fix; the package's `engines` field is + # `>=22.0.0` so consumer-side compatibility is unaffected (this + # Node version is only used during publish, not by package users). + node-version: 24 # `registry-url:` is intentionally OMITTED. Under npm Trusted # Publishing, OIDC only engages when no credential is configured. # Setting `registry-url:` would make setup-node write @@ -388,18 +396,6 @@ jobs: # cache-poisoning audit). ~30s slower per release; runs rarely. package-manager-cache: false - # npm Trusted Publishing requires npm >= 11.5.1. The Node 22 runner - # currently ships with npm 10.9.x which has no OIDC support — without - # this upgrade, `npm publish` falls back to classic auth and the - # registry returns 404 because no token is configured. Upgrade - # globally so subsequent `npm` invocations in this job use the new - # binary. - - name: Upgrade npm for Trusted Publishing - shell: bash - run: | - npm install -g npm@latest - npm --version - - name: Build gitnexus-shared run: npm install && npm run build working-directory: gitnexus-shared