From 3b5dd2e67dc97b3509f5996dc233a122099f54da Mon Sep 17 00:00:00 2001 From: Willie Chalmers III Date: Sat, 19 Sep 2026 15:35:09 -0700 Subject: [PATCH] fix(ci): Publish Analytics with pnpm Use the repository's pinned pnpm release for OIDC trusted publishing. Keep the release contract covered before the initial package release. Co-authored-by: Codex --- .github/workflows/publish.yml | 4 ++-- packages/analytics/tests/publishing.test.ts | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 5f8190d..5390adb 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -29,7 +29,7 @@ jobs: - name: Validate run: pnpm check - - name: Configure npm trusted publishing + - name: Configure npm registry uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version-file: package.json @@ -42,4 +42,4 @@ jobs: - name: Publish with provenance working-directory: packages/analytics - run: npm publish --access public + run: pnpm publish --access public --no-git-checks diff --git a/packages/analytics/tests/publishing.test.ts b/packages/analytics/tests/publishing.test.ts index f216be4..edea17c 100644 --- a/packages/analytics/tests/publishing.test.ts +++ b/packages/analytics/tests/publishing.test.ts @@ -17,8 +17,8 @@ test('publishes from the canonical repository through npm trusted publishing', a type: 'git', url: 'git+https://github.com/LasVegasForTransit/analytics.git', }); - expect(workflow).toContain('npm publish --access public'); - expect(workflow).not.toContain('pnpm publish'); + expect(workflow).toContain('pnpm publish --access public --no-git-checks'); + expect(workflow).not.toMatch(/(^|\s)npm publish/); expect(workflow).not.toContain('NODE_AUTH_TOKEN'); expect(packageJson.version).toBe('0.1.0'); expect(VERSION).toBe(packageJson.version);