You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Releases on main fail at the publish step with E404 Not Found - PUT https://registry.npmjs.org/react-three-map (failing run). That 404 is npm's response to invalid auth — the NPM_TOKEN secret is no longer valid. Rather than rotating another expiring token, this migrates to npm Trusted Publishing (OIDC).
Changes
Add id-token: write permission and remove the NPM_TOKEN env var — changesets/action@v1 automatically uses OIDC trusted publishing when no token is set.
Upgrade npm to latest in the release job (trusted publishing requires npm >= 11.5.1).
Bump .nvmrc from Node 20.11.1 to 22.17.1 — npm 11 requires Node ^20.17.0 || >=22.9.0, and Node 20 is past EOL.
Bump actions/checkout and actions/setup-node to v4.
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
This PR includes no changesets
When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Releases on main fail at the publish step with
E404 Not Found - PUT https://registry.npmjs.org/react-three-map(failing run). That 404 is npm's response to invalid auth — theNPM_TOKENsecret is no longer valid. Rather than rotating another expiring token, this migrates to npm Trusted Publishing (OIDC).Changes
id-token: writepermission and remove theNPM_TOKENenv var —changesets/action@v1automatically uses OIDC trusted publishing when no token is set..nvmrcfrom Node 20.11.1 to 22.17.1 — npm 11 requires Node^20.17.0 || >=22.9.0, and Node 20 is past EOL.actions/checkoutandactions/setup-nodeto v4.Manual steps before merging
react-three-mappackage → Settings → Publishing access, add a trusted publisher: GitHub Actions, repositoryRodrigoHamuy/react-three-map, workflowrelease.yml, environment blank.NPM_TOKENrepo secret.🤖 Generated with Claude Code