Repository navigation
ci: check the release credentials every week, not only at release time - #320
Merged
Merged
Conversation
npm's write tokens last at most 90 days. While the release depends on one, the Credentials workflow running on a schedule makes an expired token a failed run that week rather than a failed release. The schedule goes when npm publishing moves to trusted publishing (#318).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
npm's token form says tokens with write access "will expire in 7 days by default (90 days maximum)". While the release publishes with
NPM_TOKEN, a release can fail every 90 days the way v0.41.3 did. #317 moved the check to the start of the release, but that still shows up only when a tag is pushed.The Credentials workflow now also runs on Mondays at 00:17 UTC. An expired or revoked token then fails a scheduled run that week, and GitHub's default notification for a failed scheduled workflow reaches the repository owner, without anyone having to remember the expiry date. Nothing is published; it runs the same
scripts/check-credentials.shas the manual dispatch.Until
NPM_TOKENis replaced, the scheduled run will fail on npm. That failure is correct.The schedule should be removed once npm publishing moves to trusted publishing (#318), since then there is no token left to expire.