Skip to content

ci: fix broken install, bump to Node 22/24, publish via OIDC - #18

Merged
gtjamesa merged 3 commits into
mainfrom
ci/node-24-oidc
Jul 30, 2026
Merged

gtjamesa merged 3 commits into
mainfrom
ci/node-24-oidc

Conversation

@gtjamesa

Copy link
Copy Markdown
Collaborator

Why

CI has been red since 9ad1735. It was never a test failure — every run died at pnpm install, before tests ran:

ERR_PNPM_INVALID_WORKSPACE_CONFIGURATION  packages field missing or empty

pnpm-workspace.yaml was added with only an allowBuilds: key. pnpm 8 (pinned in CI) rejects a workspace file with no packages: field. Local pnpm 11 accepts it, so it only broke on push.

Note: there are currently no test files in the repo, so jest --passWithNoTests exits 0 locally. Nothing was failing locally.

Install chain

  • Pin packageManager: pnpm@11.5.1. The lockfile is v9, so pnpm 8 would have failed --frozen-lockfile immediately after the workspace error regardless.
  • Node matrix 20 → 22, 24; checkout@v7, setup-node@v7, action-setup@v6. Clears the Node 20 runner deprecation warnings.
  • @tsconfig/node20 → @tsconfig/node22, @types/node ^22, engines: node >=22.

OIDC publishing

Completes the work started on the (now deleted) oidc branch and wires it to the npmjs.org trusted-publisher config for service_publish.yml.

  • id-token: write on the reusable workflow and on both caller jobs. The oidc branch only had the former. Per GitHub docs, reusable-workflow permissions "can only be maintained or reduced—not elevated", and id-token is never granted by default — so caller-side grants are required or the first release fails.
  • The oidc branch also kept version: 8. Verified against the shipped binaries that pnpm 10.34.5 has no OIDC support; only 11.x implements the ACTIONS_ID_TOKEN_REQUEST_URL exchange.
  • Deleted .npmrc.ci: it injected an empty ${NPM_TOKEN} and pointed at the legacy registry.yarnpkg.com mirror, which trusted publishing can't use. pnpm publish --dry-run now resolves to registry.npmjs.org.
  • Dropped 5 dead secrets: inherit — no workflow consumes a secret anymore.

Incidental fixes

Path filters excluded CI config. tests.yml only matched **.js/.ts/.tsx/.json, so .github/** and pnpm-*.yaml changes never triggered CI — which is precisely how the broken workspace file reached main untested. Added those paths; confirmed by watching a workflow-only commit trigger a run.

Dangling type entrypoints. types/ is never emitted by the build, but package.json had "types": "./types/index.d.ts", a ./types export subpath, and types in files. Consumers on moduleResolution: node resolved to nothing. Repointed at dist/; verified with pnpm pack.

tsc --noEmit was broken. rootDir: ./src conflicted with the default include glob (TS6059). Scoped include to src and added a typecheck script, now run in CI.

Verification

  • Tests green on Node 22 and 24.
  • Locally reproduced the full CI path in a clean checkout: hoisted --frozen-lockfile install → typecheck → test → build.
  • pnpm pack contents match every path the manifest references.

Not verified: the OIDC publish itself only runs on v* tags, so it can't be exercised until the next release. Everything up to the publish step is verified.

Follow-ups

  • NPM_TOKEN repo secret is now unused and can be deleted.
  • Repo still has no tests.
  • Dependency majors left alone as out of scope: jest 30, TS 7, babel 8, husky 9, lint-staged 17, tsup 8.

🤖 Generated with Claude Code

gtjamesa and others added 3 commits July 30, 2026 08:51
pnpm-workspace.yaml (added in 9ad1735) has no packages field, which pnpm 8
rejects outright - every CI run died at install, never reaching tests.

- pin pnpm via packageManager (11.5.1); lockfile is v9, needs pnpm >=9
- test matrix 20 -> 22/24; checkout v7, setup-node v7, action-setup v6
- publish with npm trusted publishing (OIDC), drop NPM_TOKEN + .npmrc.ci
- add typecheck script; scope tsconfig include to src to fix TS6059
- point types/exports at dist (types/ is never emitted)

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Reusable workflows cannot elevate permissions, and id-token is never granted
by default - without this the OIDC publish would fail on the first release.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Path filters excluded .github and pnpm-*.yaml, so the workspace-config break
landed on main without CI ever running.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gtjamesa
gtjamesa merged commit 1c63960 into main Jul 30, 2026
5 checks passed
@gtjamesa
gtjamesa deleted the ci/node-24-oidc branch July 30, 2026 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant