| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
The v0.24.3 publish failed with E404 and I read it as a missing trusted
publisher on npmjs.com. It was this file.
`registry-url` makes setup-node write
//registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}
into an .npmrc. That is right for token auth and quietly fatal under trusted
publishing: with no NODE_AUTH_TOKEN the line resolves to an empty token, npm
believes it already has credentials, and never attempts the OIDC exchange. The
registry answers the unauthenticated PUT with E404 — an error naming neither
OIDC nor trusted publishing, which is what sent me looking at the registry
config rather than at the workflow. actions/setup-node#1551, and npm/cli#9088
tracks the misleading diagnostics.
Dropping registry-url writes no .npmrc, and npm defaults to
registry.npmjs.org, which is where we publish.
Also:
- node 24 rather than 22, which bundles npm 11 and has been reported to settle
OIDC handshakes that 22 did not. The npm floor check stays, so this does not
depend on what a runner image ships.
- `--provenance` back on the publish. npm documents it as automatic under
trusted publishing but reports disagree; asking explicitly cannot give a
weaker result, and it is what v0.24.2 published with.
- the header now separates the two causes of that E404 instead of asserting the
wrong one.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan92 finding(s) HIGH/CRITICAL: 50 | MEDIUM: 42
…and 42 more. Full results in the Security tab. Snippets are redacted; ThreatCrush never prints matched credential material. |
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
The v0.24.3 failure was this file, not npmjs.com
I read the E404 as a missing trusted publisher. It wasn't.
registry-url makes actions/setup-node write
//registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}into an .npmrc. That is correct for token auth and quietly fatal under trusted publishing: with no NODE_AUTH_TOKEN the line resolves to an empty token, npm believes it already has credentials, and never attempts the OIDC exchange at all. The registry answers the unauthenticated PUT with E404 — an error naming neither OIDC nor trusted publishing.
The evidence was in the logs the whole time: the v0.24.1 token run logged Signed provenance statement… before its E422, while the v0.24.3 OIDC run has no such line. No exchange was ever attempted.
Known issue: actions/setup-node#1551. npm tracks the misleading diagnostics in npm/cli#9088.
Changes
Verification
Main is already at 0.24.3 and unpublished, so a plain dispatch tests this for real — no new release needed. If it still fails, the registration genuinely is missing and NPM_TOKEN (still set, and proven by v0.24.2) is one revert away.
🤖 Generated with Claude Code