Publish /snapit snapshots through release.yml with npm OIDC - #4057
Open
fredericoo wants to merge 1 commit into
Open
fredericoo wants to merge 1 commit into
fredericoo wants to merge 1 commit into
Conversation
npm now rejects Trusted Publishing token exchanges for issue_comment runs, and the NPM_TOKEN snapit relied on has been dead since npm revoked classic tokens. snapit.yml now only validates the /snapit request and dispatches release.yml (already the trusted publisher for every package) on the PR branch. There, the branch is built and packed without a publish credential, and a job that runs no repository code validates the tarballs and publishes them over OIDC.
Contributor
|
Oxygen deployed a preview of your
Learn more about Hydrogen's GitHub integration. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WHY are these changes introduced?
Supersedes #4018.
/snapithas been broken since 2025-12-09. That day npm revoked classic tokens, and theNPM_TOKENit used stopped working. Every/snapitsince then has failed. Run 28592264687 showsE404 PUT @shopify/cli-hydrogenwith the token set.The approaches discussed on #4018 would not work either:
snapit.ymlas a second trusted publisher. npm does allow several trusted publishers per package now (up to 10, docs), so the one-workflow limit no longer applies. That alone isn't enough, though: since about 2026-09-17, npm rejects OIDC token exchanges forissue_commentruns. Shopify/cli runs/snapitinside its trustedrelease.yml. Its diagnostics (Diagnose npm OIDC failures without publishing cli#8582) show identicalsub/repository/workflow_refclaims for both events, butissue_commentgets 404 whileworkflow_dispatchgets 201. Add manual snapshot releases and remove temporary diagnostics cli#8583 and Shopify/app-bridge#3432 both moved toworkflow_dispatch.release.ymlunderissue_comment. It fails for the same reason.Shopify/snapit@v0.1.0. It documentstrigger_commentbut readscomment_command, so with the documented inputs it does nothing and reports success.release.ymlis already the trusted publisher for all 7 packages (I checked the provenance on npm), so this PR needs no changes to npm settings.WHAT is this pull request doing?
snapit.ymlis now a thin bridge. It never checks out or runs PR code. On/snapitit:release.ymldoesn't have the snapshot jobs yet (e.g. thepreviewline);release.ymlon the PR branch withexpected_sha, so the run fails if the branch moved after the comment.release.ymlgets threeworkflow_dispatchjobs:snapshot-buildbuilds and packs the branch withcontents: readonly and no publish credential.snapshot-publishruns no repo code, onlyid-token: write. It validates each tarball, then publishes over OIDC under thesnapshottag. The checks are:package/, there's exactly one manifest, and there are no links;0.0.0-snapshot-<timestamp>;publishConfigexactly matches the expected value;--dry-runreports the same name and version.snapshot-reportcomments the versions on the PR, or a failure link.Splitting build from publish means a compromised dependency or build step on an unreviewed branch (say, a Dependabot PR) can never get a publish token. The tarball checks close the remaining gap: a poisoned build could produce a real-looking
2026.xversion, which^ranges would install even under a non-latestdist-tag.Also in
release.yml:/snapitcan't cancel one mid-publish.permissions: {}, withcompilenow declaring itscontents: write. No other job changes behaviour.Updates the release-process skill.
You can also start a snapshot without commenting: Actions → Release → Run workflow → pick the branch.
HOW to test your changes?
This can't be tried end to end before merge. The
issue_commenttrigger always runs frommain, and dispatching this branch would publish real snapshot versions. What I checked locally:actionlint: nothing new (the 10 existing shellcheck infos are on untouched jobs).LIB_VERSIONandoclif.manifest.json, and noworkspace:/catalog:left in the published manifests.publishConfig; extra root directory; duplicate manifest;./,package/./and..paths; symlink; hardlink; duplicate name; extra files; 0 or 8 tarballs.After merge: comment
/snapiton a PR that's up to date withmain. Expect 👀 then 🚀, then a comment listing@shopify/hydrogenand@shopify/cli-hydrogensnapshot versions. One thing is still unproven: whether npm accepts a dispatch whose actor isgithub-actions[bot](dispatches by a person are proven by Shopify/cli). If it doesn't, the manual Run workflow path still works.Post-merge steps
NPM_TOKENrepo secret once the first snapshot publishes.0.0.0-next-1842c33shipped fromrefs/heads/2025-05, so anyone who can push a branch can publish any version through an editedrelease.yml. Worth binding the trusted publisher to a GitHub Environment limited to release branches.Found along the way, not fixed here
next-releasehas silently stopped publishing.pnpm run changeset -- version --snapshot …logs "Too many arguments passed to changesets", the job still succeeds, and thenextdist-tag hasn't moved since 2026-03-19 (run 34604190295).releasejob's major-bypass step callsgh pr closewith aGITHUB_TOKENthat has nopull-requests: write.Checklist