Skip to content

Migrate npm publishing to trusted publishing - #21

Merged
durga256 merged 3 commits into
mainfrom
durga/use-npm-trusted-publishing
Oct 6, 2026
Merged

durga256 merged 3 commits into
mainfrom
durga/use-npm-trusted-publishing

Conversation

@durga256

@durga256 durga256 commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Why

The release workflow currently exposes a long-lived npm publishing credential to a public-repository GitHub Actions job. If that credential is exfiltrated, it can be reused to publish a malicious @shopify/toml-patch version.

Addresses https://github.com/shop/issues/issues/84640 and https://vault.shopify.io/teams/2238-DevTools/issues/77805-secure-artifact-publish-tokens-and-harden-release-workflows-in-oss-repos.

What changed

  • grant the release workflow only contents: read and the id-token: write permission required for npm Trusted Publishing
  • use Node 22.14.0 and install a current npm CLI with OIDC support
  • disable package-manager caching in the release job
  • remove the NPM_TOKEN secret from the publish step so npm uses OIDC
  • add the canonical GitHub repository URL to the generated npm package metadata, which npm validates during trusted publishing

Verification

  • wasm-pack build --target nodejs --release --scope='shopify' — generated pkg/package.json with repository.url set to https://github.com/Shopify/toml-patch
  • wasm-pack test --node — 30 tests passed
  • yamllint and Ruby YAML parser — workflow is valid YAML
  • npm view @shopify/toml-patch version --registry=https://registry.npmjs.org — package exists (0.3.0)

Release prerequisite

Before the next release, configure @shopify/toml-patch on npm with a GitHub Actions Trusted Publisher for Shopify/toml-patch and publish.yml, allowing direct npm publish. A new trusted-publisher configuration must complete its first publish within two days. After the first successful OIDC publish, remove the repository's old NPM_TOKEN secret and configure npm publishing access to disallow token-based publishing.

@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

 RUN  v3.1.2 /home/runner/work/toml-patch/toml-patch/example


 ✓ test.bench.ts > TOML update 1239ms
     name         hz     min     max    mean     p75     p99    p995    p999     rme  samples
   · JS    33,502.30  0.0277  0.3768  0.0298  0.0291  0.0499  0.0564  0.2225  ±0.52%    16752
   · WASM  39,080.51  0.0243  0.0849  0.0256  0.0254  0.0362  0.0397  0.0475  ±0.12%    19541   fastest

 BENCH  Summary

  WASM - test.bench.ts > TOML update
    1.17x faster than JS

@durga256
durga256 marked this pull request as ready for review October 6, 2026 18:25
@durga256
durga256 requested a review from shauns October 6, 2026 18:25

@Suleimanlatrsh Suleimanlatrsh left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Small nit: NPM_TOKEN: "" doesn't do anything here, so that env block can go. No need for a re-review.

@durga256
durga256 merged commit ef30d0c into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants