Skip to content

ci(release): pin npm 11.x for trusted publishing - #450

Merged
crs48 merged 1 commit into
mainfrom
fix/npm-release-pin-npm11
Jul 10, 2026
Merged

ci(release): pin npm 11.x for trusted publishing#450
crs48 merged 1 commit into
mainfrom
fix/npm-release-pin-npm11

Conversation

@crs48

@crs48 crs48 commented Jul 10, 2026

Copy link
Copy Markdown
Owner

npm 12.0.0 (released today, now npm@latest) is missing the sigstore module its own libnpmpublish provenance path requires — every --provenance publish dies with MODULE_NOT_FOUND. This broke today's release run (nothing published; all packages still at their prior versions, no partial state).

Pin the trusted-publishing step to npm@11 (what all previous successful releases used). Bump deliberately once a 12.x publish is verified.

After merge, the push-triggered npm Release run should publish the staged 0.8.0/0.2.0 versions from #421.

🤖 Generated with Claude Code

…ng provenance publish

Signed-off-by: xNet Test <test@xnet.dev>
@crs48 crs48 added the skip-changelog Exclude this PR from the changelog label Jul 10, 2026
@crs48
crs48 temporarily deployed to pr-450 July 10, 2026 15:53 — with GitHub Actions Inactive
github-actions Bot added a commit that referenced this pull request Jul 10, 2026
@github-actions

github-actions Bot commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

Preview removed for PR #450.

@crs48
crs48 merged commit ebec5e0 into main Jul 10, 2026
13 of 14 checks passed
@crs48
crs48 deleted the fix/npm-release-pin-npm11 branch July 10, 2026 16:01
github-actions Bot added a commit that referenced this pull request Jul 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Exclude this PR from the changelog

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant