From d7e9b8ee5c45422515d2b2153074d673674d0a79 Mon Sep 17 00:00:00 2001 From: Matt Hillsdon Date: Tue, 8 Sep 2026 16:15:46 +0000 Subject: [PATCH 1/2] Publish to npm via trusted publishing Replaces the NPM_TOKEN secret with OIDC, following makecode-embed. The build job packs the workspace tarball and a separate publish job, with no checkout and the only id-token permission, stages it to npm from the npm-publish environment. npm stage is unaware of workspaces, but publishing the tarball from npm pack -w sidesteps that. npm pack now runs on every build so packaging problems fail a branch build rather than a release. Also drops the packages: write permission and the GITHUB_TOKEN passed to npm ci, left over from GitHub Packages; nothing here resolves from that registry. --- .github/workflows/build.yml | 41 +++++++++++++++++++++++++++++-------- 1 file changed, 32 insertions(+), 9 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index cc31d1a..a5f6aba 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -5,29 +5,52 @@ on: push: branches: - "**" +env: + # renovate: datasource=npm depName=npm + NPM_VERSION: "11" + jobs: build: runs-on: ubuntu-latest permissions: contents: read - packages: write steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: node-version: "24.x" - registry-url: "https://registry.npmjs.org" cache: npm - - run: npm install -g npm@11 --registry=https://registry.npmjs.org + - run: npm install -g npm@${{ env.NPM_VERSION }} --registry=https://registry.npmjs.org - run: npm ci - env: - NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: npm run format:check - uses: microbit-foundation/npm-package-versioner-action@v3 with: working-directory: packages/microbit-connection - run: npm run ci - - run: npm publish -w @microbit/microbit-connection --allow-directory=all - if: github.event_name == 'release' && github.event.action == 'created' - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + - run: npm pack -w @microbit/microbit-connection + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + if: github.event_name == 'release' + with: + name: npm-tarball + path: '*.tgz' + if-no-files-found: error + retention-days: 1 + + publish: + needs: build + if: github.event_name == 'release' + runs-on: ubuntu-latest + environment: npm-publish + permissions: + contents: read + id-token: write + steps: + - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: npm-tarball + - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 + with: + node-version: '24.x' + registry-url: 'https://registry.npmjs.org' + - run: npm install -g npm@${{ env.NPM_VERSION }} --registry=https://registry.npmjs.org + - run: npm stage publish --allow-file=all ./*.tgz From 8df2b039e4a4371414e3cc6ac215d9788aa50b0e Mon Sep 17 00:00:00 2001 From: Matt Hillsdon Date: Wed, 9 Sep 2026 12:30:06 +0000 Subject: [PATCH 2/2] Format workflow with Prettier --- .github/workflows/build.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index a5f6aba..0bd91be 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -32,7 +32,7 @@ jobs: if: github.event_name == 'release' with: name: npm-tarball - path: '*.tgz' + path: "*.tgz" if-no-files-found: error retention-days: 1 @@ -50,7 +50,7 @@ jobs: name: npm-tarball - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7 with: - node-version: '24.x' - registry-url: 'https://registry.npmjs.org' + node-version: "24.x" + registry-url: "https://registry.npmjs.org" - run: npm install -g npm@${{ env.NPM_VERSION }} --registry=https://registry.npmjs.org - run: npm stage publish --allow-file=all ./*.tgz