From 867f310df842c686fa463187abe491841606967e Mon Sep 17 00:00:00 2001 From: kjgbot Date: Sun, 20 Sep 2026 08:43:04 -0700 Subject: [PATCH] fix(release): pin OIDC-compatible npm --- .github/workflows/publish.yml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index d05f457e..18a8289c 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1052,9 +1052,14 @@ jobs: exit 1 fi - # npm >= 11.5.1 is required for the OIDC trusted-publisher flow. - - name: Install latest npm - run: npm install -g npm@latest + # npm >= 11.5.1 is required for the OIDC trusted-publisher flow. Keep the + # exact npm release compatible with the Node version pinned above: an + # unconstrained npm@latest upgraded this job to npm 12, whose engine + # rejected Node 22.14.0 before any npm package could be published. + - name: Install OIDC-capable npm + run: | + npm install -g npm@11.19.1 + test "$(npm --version)" = "11.19.1" # Authentication note: this workflow does NOT use an NPM_TOKEN. It relies # on npm's OIDC trusted-publisher flow — the `id-token: write` permission