Skip to content

ci: publish to npm on version tag - #27

Merged
taylanpince merged 2 commits into
masterfrom
npm-publish-workflow
Sep 28, 2026
Merged

taylanpince merged 2 commits into
masterfrom
npm-publish-workflow

Conversation

@ScreamingHawk

@ScreamingHawk ScreamingHawk commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Stages an npm release when a v* tag is pushed. CI runs npm stage publish over npm trusted publishing (OIDC), so the repo holds no npm token. A staged version stays private until an npm maintainer approves it.

The job fails before staging if the tag isn't on master or doesn't match the package.json version (v2.0.0 for 2.0.0). It builds explicitly and stages with --ignore-scripts, so the package never depends on the prepare hook running.

Needs a one-time setup by an npm maintainer before the first tag: on npmjs.com, @0xsequence/catapult > Settings > Trusted Publisher > GitHub Actions, with organization 0xsequence, repository catapult, workflow publish.yml, environment blank, and stage publish allowed (publish not allowed). npm doesn't validate these on save, so a typo only shows up as ENEEDAUTH on the first run.

Once merged and configured, releasing 2.0.0 is:

git tag v2.0.0 origin/master
git push origin v2.0.0

Then a maintainer approves it, either on npmjs.com or with npm stage list @0xsequence/catapult and npm stage approve <stage-id> (prompts for 2FA).

Every version already on npm has a tag, except 1.3.2, whose publish commit was never pushed. Don't re-push or re-create those tags: the version is already on npm, so the staging step would fail.

@taylanpince

Copy link
Copy Markdown

npm side setup. However as a general rule I am not allowing direct publishing on these integrations. It requires an admin approval and a npm stage publish in the CI. Can you change accordingly?

@taylanpince taylanpince left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

npm stage publish

@taylanpince
taylanpince merged commit d519074 into master Sep 28, 2026
7 checks passed
@ScreamingHawk
ScreamingHawk deleted the npm-publish-workflow branch September 28, 2026 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants