Repository navigation
ci: stage npm releases and skip install scripts in publish jobs - #91
Open
mislavivanda wants to merge 1 commit into
Open
mislavivanda wants to merge 1 commit into
mislavivanda wants to merge 1 commit into
Conversation
Signed-off-by: Mislav Ivanda <mislavivanda454@gmail.com>
There was a problem hiding this comment.
No issues found across 3 files
This PR changes infrastructure or deployment configuration. Ultrareviews find 2.4x more serious bugs than standard reviews. Comment @cubic-dev-ai ultrareview to run one.
View guided diff | Turn on auto-fix | Re-trigger cubic
aprojic
approved these changes
Oct 9, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Harden every npm release job that holds
id-token: write:npm ci --ignore-scripts, preventing dependency lifecycle scripts from minting the job's OIDC tokennpm publishwithnpm stage publish --provenance --access publicThe threat is the combination of dependency install scripts and
id-token: write: a compromised install script can request the GitHub OIDC token and publish a package with valid provenance. Staged publishing also removes CI's ability to make a version live without a maintainer's 2FA approval.Per-job changes and local verification
--ignore-scripts@daytona/n8n-nodes-daytonanpm ci --ignore-scripts,npm run build --if-present,npm pack --dry-run--ignore-scripts.isolated-vmis present transitively throughn8n-workflow, butn8n-node buildand packaging do not need its native install artifact; no targeted rebuild is needed.@daytona/pi--ignore-scripts.@daytona/opencode--ignore-scripts.@daytona/convex--ignore-scripts; the release build is onlytsc.@daytona/claude-toolsets--ignore-scripts; only the publish command changes--ignore-scriptsThe n8n
RELEASE_MODE=truebehavior remains intact. npm 12'snpm stage publish --dry-runwas also checked locally and did invokeprepublishOnly/n8n-node prerelease, so staged publishing preserves that package's release hook./home/opencode/go/bin/actionlint .github/workflows/release.yml .github/workflows/ci.ymlpasses.Staged publishing flow
Merging an npm package's Release PR now stages its version with provenance rather than making it live. A maintainer reviews and approves it with 2FA either at npmjs.com → package → Staged Packages, or via:
npm stage publishrequires npm >= 11.15.0 and Node >= 22.14.0.actions/setup-nodewithlts/*currently resolves to Node 24.21.0, and every npm publish job runsnpm install -g npm@latest(currently npm 12.2.0). The stage command supports both--access publicand--provenance; provenance is generated with the staged artifact in CI and is present when that artifact is approved.OWNER CHECKLIST
Quick check before this PR merges
npm's current trusted-publisher docs state that
npm stage publishis always allowed for every trusted publisher; the allowed-actions setting only controls the additional directnpm publishandnpm dist-tagrights (docs, "Allowed actions"). The note about configurations created before May 20, 2026 being "npm publishonly" describes how the direct-publish right was migrated; it does not remove staging. So no config should need editing before merge, but because a wrong assumption here fails the next release, confirm it on each package's npmjs.com → Settings → Trusted publishing page (the "Allowed actions" section should read "npm stage publish is always allowed"):@daytona/n8n-nodes-daytona@daytona/pi@daytona/opencode@daytona/convex@daytona/claude-toolsets(already confirmed when it was created on 2026-10-08)If an older package's page does not show staging as allowed, delete and recreate that connection with the same fields (
daytona/integrations,release.yml, environmentnpm) before merging. If a release does fail authentication, fix the config and re-run the failed job; no new release is needed.After stage access is confirmed (may be done immediately after merge)
For all five npm packages, untick/disable direct
npm publishon the trusted publisher while leavingnpm stage publishallowed:@daytona/n8n-nodes-daytona@daytona/pi@daytona/opencode@daytona/convex@daytona/claude-toolsetsThat owner-only setting ensures the workflow identity can stage but can never bypass maintainer review and 2FA approval.
npm documentation
npm stageCLIFYI @aprojic, who raised the install-script/OIDC issue.
This touches the
release.ymlarea near draft #90's release-workflow restructure. Whichever PR merges second will need a trivial rebase.Summary by cubic
Npm release jobs now stage versions for maintainer review and 2FA approval instead of publishing live, and all publish jobs run
npm ci --ignore-scriptsso dependency lifecycle scripts can't mint the workflow's GitHub OIDC token. The same hardened install applies to the matching PR-check jobs, and the README documents the staged-publishing flow; provenance is generated at stage time, and release hooks like n8n'sprepublishOnlystill run.Migration
npm stage publishto the GitHub Actions trusted publisher for@daytona/n8n-nodes-daytona,@daytona/pi,@daytona/opencode, and@daytona/convex; configs created before May 20, 2026 only allownpm publish. If the existing connection can't be edited, delete and recreate it with stage permission.npm publishon the trusted publisher for all five packages so the workflow identity can only stage.Written for commit 4cc587f. Summary will update on new commits.