diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index d05f457e..18a8289c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1052,9 +1052,14 @@ jobs: exit 1 fi - # npm >= 11.5.1 is required for the OIDC trusted-publisher flow. - - name: Install latest npm - run: npm install -g npm@latest + # npm >= 11.5.1 is required for the OIDC trusted-publisher flow. Keep the + # exact npm release compatible with the Node version pinned above: an + # unconstrained npm@latest upgraded this job to npm 12, whose engine + # rejected Node 22.14.0 before any npm package could be published. + - name: Install OIDC-capable npm + run: | + npm install -g npm@11.19.1 + test "$(npm --version)" = "11.19.1" # Authentication note: this workflow does NOT use an NPM_TOKEN. It relies # on npm's OIDC trusted-publisher flow — the `id-token: write` permission