From 03dd155569226638c57268c654a2a1a403ce7ae8 Mon Sep 17 00:00:00 2001 From: x1xhlol Date: Sun, 4 Oct 2026 18:33:44 +0000 Subject: [PATCH 1/3] Document pending npm authorization and registry release gates --- CHANGELOG.md | 2 +- registry/README.md | 13 +++++++++++++ 2 files changed, 14 insertions(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index a9d3fd8..70754b2 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,7 +3,7 @@ ## [2.1.1] - 2026-10-04 - Fixed release verification for npm 12's package metadata format while retaining compatibility with earlier npm versions. Packed package names and versions are checked against the manifest, and publish dry runs still create and install real test artifacts. -- First npm release of the AI SDK inspection tool. The 2.1.0 publication stopped during verification before uploading a package; this version includes all changes below. +- Includes all AI SDK inspection tool changes below. The 2.1.0 publication stopped during verification before uploading a package. The 2.1.1 checks pass, but npm publication is pending publisher authentication. ## [2.1.0] - 2026-10-04 diff --git a/registry/README.md b/registry/README.md index 38aa36f..cf33ead 100644 --- a/registry/README.md +++ b/registry/README.md @@ -6,6 +6,19 @@ The public integration guide is `https://zeroleaks.ai/docs/shield-sdk/providers/ Before submitting, confirm that npm serves `@zeroleaks/shield@2.1.1` and the integration guide is live. The source repository, README, public docs, and published package must describe the same exports and supported SDK versions. +The 2.1.1 release passed code and package checks but npm rejected authentication (`ENEEDAUTH`). It is not published yet. No npm token is configured in the repository or its `npm` environment. The app documentation PR also requires a review before production deployment: https://github.com/x1xhlol/zeroleaks-v2/pull/229. + +An npm package administrator can authorize the existing workflow in the package's [trusted publisher settings](https://www.npmjs.com/package/@zeroleaks/shield/access), following [npm's instructions](https://docs.npmjs.com/trusted-publishers/). Use the exact GitHub owner `ZeroLeaks`, repository `shield`, workflow filename `publish.yml`, and environment `npm`. Permit direct `npm publish`; staged-only permission will not publish this release. The workflow already uses GitHub-hosted runners, Node 24, current npm, and `id-token: write`. + +After authorization, retry the existing release run, then verify the registry version: + +```bash +gh run rerun 37224605299 --repo ZeroLeaks/shield --failed +npm view @zeroleaks/shield@2.1.1 version +``` + +Once npm serves the release, update the GitHub release's pending status and remove this publication-blocker note. Confirm the integration guide is deployed before submitting upstream. + Run the release checks from the Shield repository: ```bash From ed12be9ba08b06b8b6dcd9d90d2f9010a6cf16a1 Mon Sep 17 00:00:00 2001 From: x1xhlol Date: Sun, 4 Oct 2026 18:36:10 +0000 Subject: [PATCH 2/3] Expose npm OIDC failure diagnostics for release retries --- .github/workflows/publish.yml | 5 +++-- registry/README.md | 4 ++-- 2 files changed, 5 insertions(+), 4 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 367c675..3df7be7 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -38,6 +38,7 @@ jobs: - uses: actions/setup-node@v6 with: node-version: 24 + package-manager-cache: false - uses: oven-sh/setup-bun@v2 with: @@ -87,10 +88,10 @@ jobs: - name: Validate package if: github.event_name == 'workflow_dispatch' && inputs.dry_run - run: npm publish --dry-run --access public + run: npm publish --dry-run --access public --loglevel verbose - name: Publish package if: steps.registry.outputs.published != 'true' && (github.event_name == 'release' || (github.event_name == 'workflow_dispatch' && !inputs.dry_run)) env: NPM_TAG: ${{ github.event_name == 'workflow_dispatch' && inputs.npm_tag || 'latest' }} - run: npm publish --access public --provenance --tag "$NPM_TAG" + run: npm publish --access public --provenance --tag "$NPM_TAG" --loglevel verbose diff --git a/registry/README.md b/registry/README.md index cf33ead..c6a7838 100644 --- a/registry/README.md +++ b/registry/README.md @@ -10,10 +10,10 @@ The 2.1.1 release passed code and package checks but npm rejected authentication An npm package administrator can authorize the existing workflow in the package's [trusted publisher settings](https://www.npmjs.com/package/@zeroleaks/shield/access), following [npm's instructions](https://docs.npmjs.com/trusted-publishers/). Use the exact GitHub owner `ZeroLeaks`, repository `shield`, workflow filename `publish.yml`, and environment `npm`. Permit direct `npm publish`; staged-only permission will not publish this release. The workflow already uses GitHub-hosted runners, Node 24, current npm, and `id-token: write`. -After authorization, retry the existing release run, then verify the registry version: +After authorization, retry the current workflow, then verify the registry version. Verbose npm logs report the OIDC exchange reason if authentication fails: ```bash -gh run rerun 37224605299 --repo ZeroLeaks/shield --failed +gh workflow run publish.yml --repo ZeroLeaks/shield --ref master -f dry_run=false -f npm_tag=latest npm view @zeroleaks/shield@2.1.1 version ``` From 3ef7d97b00d5ab0da58d5ab03e3792ca976c4bbe Mon Sep 17 00:00:00 2001 From: x1xhlol Date: Sun, 4 Oct 2026 18:38:09 +0000 Subject: [PATCH 3/3] Document configured npm environment credential and release retries --- CHANGELOG.md | 2 +- registry/README.md | 8 ++++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 70754b2..ac20059 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -3,7 +3,7 @@ ## [2.1.1] - 2026-10-04 - Fixed release verification for npm 12's package metadata format while retaining compatibility with earlier npm versions. Packed package names and versions are checked against the manifest, and publish dry runs still create and install real test artifacts. -- Includes all AI SDK inspection tool changes below. The 2.1.0 publication stopped during verification before uploading a package. The 2.1.1 checks pass, but npm publication is pending publisher authentication. +- Includes all AI SDK inspection tool changes below. The 2.1.0 publication stopped during verification before uploading a package. ## [2.1.0] - 2026-10-04 diff --git a/registry/README.md b/registry/README.md index c6a7838..1dcd02b 100644 --- a/registry/README.md +++ b/registry/README.md @@ -6,18 +6,18 @@ The public integration guide is `https://zeroleaks.ai/docs/shield-sdk/providers/ Before submitting, confirm that npm serves `@zeroleaks/shield@2.1.1` and the integration guide is live. The source repository, README, public docs, and published package must describe the same exports and supported SDK versions. -The 2.1.1 release passed code and package checks but npm rejected authentication (`ENEEDAUTH`). It is not published yet. No npm token is configured in the repository or its `npm` environment. The app documentation PR also requires a review before production deployment: https://github.com/x1xhlol/zeroleaks-v2/pull/229. +Publishing uses the `NPM_TOKEN` Actions secret in the Shield repository's `npm` GitHub environment. The existing workflow configures npm authentication from that secret before publishing. Replace it with `gh secret set NPM_TOKEN --repo ZeroLeaks/shield --env npm`; paste the credential into the hidden prompt, and keep it out of source files. -An npm package administrator can authorize the existing workflow in the package's [trusted publisher settings](https://www.npmjs.com/package/@zeroleaks/shield/access), following [npm's instructions](https://docs.npmjs.com/trusted-publishers/). Use the exact GitHub owner `ZeroLeaks`, repository `shield`, workflow filename `publish.yml`, and environment `npm`. Permit direct `npm publish`; staged-only permission will not publish this release. The workflow already uses GitHub-hosted runners, Node 24, current npm, and `id-token: write`. +The workflow also supports [npm trusted publishing](https://docs.npmjs.com/trusted-publishers/) as an alternative. An npm package administrator can configure it in the package's [trusted publisher settings](https://www.npmjs.com/package/@zeroleaks/shield/access). Use the exact GitHub owner `ZeroLeaks`, repository `shield`, workflow filename `publish.yml`, and environment `npm`. Permit direct `npm publish`; staged-only permission will not publish this release. The workflow already uses GitHub-hosted runners, Node 24, current npm, and `id-token: write`. -After authorization, retry the current workflow, then verify the registry version. Verbose npm logs report the OIDC exchange reason if authentication fails: +To retry a release, run the current workflow and verify the registry version after it succeeds. Verbose npm logs report the OIDC exchange reason if authentication fails: ```bash gh workflow run publish.yml --repo ZeroLeaks/shield --ref master -f dry_run=false -f npm_tag=latest npm view @zeroleaks/shield@2.1.1 version ``` -Once npm serves the release, update the GitHub release's pending status and remove this publication-blocker note. Confirm the integration guide is deployed before submitting upstream. +Confirm the integration guide is deployed before submitting upstream. The app documentation PR requires a review before production deployment: https://github.com/x1xhlol/zeroleaks-v2/pull/229. Run the release checks from the Shield repository: