Skip to content

ci: check the release credentials every week, not only at release time - #320

Merged
Higangssh merged 1 commit into
mainfrom
ci/check-credentials-weekly
Oct 8, 2026
Merged

Higangssh merged 1 commit into
mainfrom
ci/check-credentials-weekly

Conversation

@Higangssh

Copy link
Copy Markdown
Owner

npm's token form says tokens with write access "will expire in 7 days by default (90 days maximum)". While the release publishes with NPM_TOKEN, a release can fail every 90 days the way v0.41.3 did. #317 moved the check to the start of the release, but that still shows up only when a tag is pushed.

The Credentials workflow now also runs on Mondays at 00:17 UTC. An expired or revoked token then fails a scheduled run that week, and GitHub's default notification for a failed scheduled workflow reaches the repository owner, without anyone having to remember the expiry date. Nothing is published; it runs the same scripts/check-credentials.sh as the manual dispatch.

Until NPM_TOKEN is replaced, the scheduled run will fail on npm. That failure is correct.

The schedule should be removed once npm publishing moves to trusted publishing (#318), since then there is no token left to expire.

npm's write tokens last at most 90 days. While the release depends on one,
the Credentials workflow running on a schedule makes an expired token a
failed run that week rather than a failed release. The schedule goes when
npm publishing moves to trusted publishing (#318).
@Higangssh
Higangssh merged commit 44302f5 into main Oct 8, 2026
7 checks passed
@Higangssh
Higangssh deleted the ci/check-credentials-weekly branch October 8, 2026 11:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant