ci(release): switch to OIDC trusted publishing and enforce conventional commit pipeline - #9
Merged
Merged
Conversation
Trusted publisher configured on npmjs.com: - Publisher: GitHub Actions - Repository: kamansoft/vite-plugin-flatwave-react - Workflow: release.yml - Permission: npm publish Publishing access on npmjs.com set to 'disallow tokens' (most restrictive). No long-lived NPM_TOKEN secret needed — OIDC handles auth automatically.
… details - Accurate current state: OIDC trusted publishing is active, NPM_TOKEN removed - Complete npmjs.com settings: trusted publisher form values, publishing access - Complete GitHub settings: branch protection rules with correct check names, secrets status (NPM_TOKEN can be deleted) - All commands executed during setup with explanations - Orphaned tag cleanup procedure documented - Expanded troubleshooting: stale pending checks, orphaned tags, self-hosted runner limitation, manual workflow trigger
…ion chain - Add end-to-end diagram showing how PR title gates the semver bump - Document squash-only merge enforcement (allow_merge_commit: false, allow_rebase_merge: false) and why it is critical - Document squash_merge_commit_title: PR_TITLE setting that locks the commit message to the validated PR title - Add gh CLI command to apply merge strategy settings - Add comparison table (before/after) for all changed merge settings
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bundles three changes that were previously pushed directly to
main— now going through the proper PR flow.Changes included
ci(release)NPM_TOKENfrom workflow; authenticate exclusively via npm OIDC trusted publishingdocs(ci-cd)docs/ci-cd-release-automation.mdwith all setup steps, commands, and settingsdocs(ci-cd)Why this PR exists
The three commits above were made with an admin bypass directly to
mainwhile the pipeline was being debugged. Now that the pipeline is stable, they are being retroactively brought through the correct workflow as a baseline for theenforce_admins: truerule that will be applied once this PR is merged.After this PR merges
mainwill be fully locked: no direct pushes, no force pushes, not even for admins.