') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); Set up workflow permissions for trusted publishing by harmony7 · Pull Request #1644 · fastly/cli · GitHub
Skip to content

Set up workflow permissions for trusted publishing - #1644

Merged
kpfleming merged 1 commit into
mainfrom
kats/npmjs-trusted-publishing
Feb 2, 2026
Merged

Set up workflow permissions for trusted publishing#1644
kpfleming merged 1 commit into
mainfrom
kats/npmjs-trusted-publishing

Conversation

@harmony7

@harmony7harmony7 commented Feb 2, 2026

Copy link
Copy Markdown
Member

Change summary

This PR updates the publish_release.yml workflow file:

  1. enables the permission id-token: write for OpenID Connect (OIDC) authentication for use with Trusted Publishing with npmjs
  2. removes the auth token as it's no longer used when Trusted Publishing is used

All Submissions:

  • Have you followed the guidelines in our Contributing document?
  • Have you checked to ensure there aren't other open Pull Requests for the same update/change?

New Feature Submissions:

  • Does your submission pass tests?
    N/A

Changes to Core Features:

  • Have you written new tests for your core changes, as applicable?
  • Have you successfully run tests with your changes locally?
    N/A

User Impact

None

Are there any considerations that need to be addressed for release?

None

@harmony7harmony7 self-assigned this Feb 2, 2026
@harmony7
harmony7 requested a review from a team as a code ownerFebruary 2, 2026 09:48
@harmony7
harmony7 requested a review from rcarilFebruary 2, 2026 09:48
@harmony7
harmony7force-pushed the kats/npmjs-trusted-publishing branch from 9dbdd95 to 87215c4CompareFebruary 2, 2026 10:10
@kpflemingkpfleming added the Skip-Changelog do not add a changelog entry for this change label Feb 2, 2026
@kpfleming
kpfleming requested review from kpfleming and removed request for rcarilFebruary 2, 2026 14:44
@kpfleming
kpfleming merged commit a7ebdb3 into mainFeb 2, 2026
20 of 21 checks passed
@kpfleming
kpfleming deleted the kats/npmjs-trusted-publishing branch February 2, 2026 15:07
anthony-gomez-fastly pushed a commit that referenced this pull request Apr 13, 2026
### Change summary
This PR restores a permission in the workflow that had been removed in
#1718 that is needed for publishing to NPM.
Publishing to NPM using trusted publishing requires `id-token: write` as
added in #1644.
### New Feature Submissions:
* [x] Does your submission pass tests?
### Changes to Core Features:
* [ ] Have you written new tests for your core changes, as applicable?
* [ ] Have you successfully run tests with your changes locally?
### Are there any considerations that need to be addressed for release?
A new point release (14.3.1) would be needed to get this version into
NPM.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Skip-Changelogdo not add a changelog entry for this change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@harmony7@kpfleming