Publish all packages in single step, skip already-published versions#196
Merged
leoromanovsky merged 1 commit intomainfrom Mar 3, 2026
Merged
Publish all packages in single step, skip already-published versions#196leoromanovsky merged 1 commit intomainfrom
leoromanovsky merged 1 commit intomainfrom
Conversation
Consolidates the 3 separate publish steps into one. This ensures the OIDC token stays valid across all publishes and allows re-runs to skip packages that were already published successfully.
sameerank
approved these changes
Mar 3, 2026
| fi | ||
|
|
||
| echo "Package not yet available, waiting 10 seconds..." | ||
| sleep 10 |
Contributor
There was a problem hiding this comment.
I don't know how short-lived this token is, so I wonder if it might help to shorten the wait if you haven't tried this yet
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Two issues with the current release workflow:
Can't re-run releases: Core was published via OIDC successfully, but browser failed. Re-running the release fails with
You cannot publish over the previously published versions: 1.1.0because core tries to publish again.OIDC token is single-use per publish: Each
npm publish --provenancecall exchanges a short-lived OIDC token for a single-operation npm API token that expires immediately after that publish:When publish steps were separate, the first step (core) consumed the OIDC token. The browser step then tried to authenticate and failed with
ENEEDAUTHbecause it couldn't obtain a fresh token. Publishing all packages in a single shell step keeps access toACTIONS_ID_TOKEN_REQUEST_URL, allowing npm to request a fresh OIDC token for each publish call.Evidence from the failed run:
✅ Signed provenance statement with source and build information from GitHub Actionsnpm error code ENEEDAUTH— same job, next step, token goneChanges
npm viewbefore each publish — skip if version already exists on npmHow re-runs work now
On re-run, each
publish_packagecall checks npm first:References