Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
9081191
Publish by OIDC trusted publishing instead of a stored npm token
unbraind Aug 26, 2026
991ef8f
Fail closed on the npm version actually in use, and scope the guards …
unbraind Aug 26, 2026
999fc52
Fail the release before it bumps when npm refuses the workflow's iden…
unbraind Aug 26, 2026
f186661
Reject npm credential aliases and the --global install spelling
unbraind Aug 26, 2026
8f8d83e
Close two guards that passed without the behaviour they protect
unbraind Aug 26, 2026
70458cd
Restore the docstring the guard suite's docstring gate requires
unbraind Aug 26, 2026
c44ab3e
Do not let the OIDC exchange credential outlive the step that fetched it
unbraind Aug 26, 2026
f7e25f1
Record the release-hardening evidence on the tracked item
unbraind Aug 26, 2026
91c153d
Encode the package name and accept 201, or the preflight blocks corre…
unbraind Aug 26, 2026
08eb49f
Scrub every legacy credential, bound the preflight, and name a regist…
unbraind Aug 26, 2026
2ddcc5e
State the incident dates in these records as UTC
unbraind Aug 26, 2026
ac6a3d2
Refuse a non-main ref before requesting a publish credential
unbraind Aug 26, 2026
ec6242e
Gate the job by ref, re-verify npm at publish time, and make failures…
unbraind Aug 26, 2026
7af89f0
Freeze the history and gate the future on commit identity and host paths
unbraind Aug 27, 2026
d7142ee
Close a vacuous credential guard and stop interpolating context into …
unbraind Aug 27, 2026
96b1b71
Measure the mutation coverage instead of maintaining a tally
unbraind Aug 27, 2026
1ec3302
Reject and scrub global npm credentials, not only registry-scoped ones
unbraind Aug 27, 2026
5ef16d4
Catch credential writes that carry a flag, and scrub npm's global config
unbraind Aug 27, 2026
e99ac67
chore(git): ignore SDK workspace-transaction journals
unbraind Aug 27, 2026
293361e
fix(test): make the inline-permissions branch capable of passing
unbraind Aug 27, 2026
bc7635c
fix(ci): stop three guards failing open, and stop one gate measuring …
unbraind Aug 27, 2026
0a6cce8
docs(pm): state the mutation property instead of a tally that goes stale
unbraind Aug 27, 2026
6aecd47
fix: split on unspaced shell separators, and stop two guards at the r…
unbraind Aug 27, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .agents/pm/history/pm-github-m8u2.jsonl
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
{"ts":"2026-08-26T19:33:40.186Z","author":"claude","author_source":"asserted","agent_harness":"claude-code","agent_instance":"f559dcd5a5f387bc7221097a","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"create","patch":[{"op":"replace","path":"/body","value":"Trusted publishing replaces the stored credential. The registry mints a short lived credential from the workflow OIDC identity, so there is no secret left to expire. Requires a one time configuration on npmjs.com binding this package to unbraind/pm-github and the release.yml workflow."},{"op":"add","path":"/metadata/id","value":"pm-github-m8u2"},{"op":"add","path":"/metadata/title","value":"The release job authenticated with a stored npm token that expired, so publishing stopped while every other gate stayed green"},{"op":"add","path":"/metadata/description","value":"The Publish npm package step read NODE_AUTH_TOKEN from the repository secret NPM_TOKEN. That credential began being rejected on 2026-08-17. From then until 2026-08-26 every daily release run reached the publish step and failed with npm code E404 on PUT to the registry, which is how npm reports a rejected write credential rather than a missing package. Rotating the secret on 2026-08-22 did not help, and the copy of the credential on the maintainer host answers 401 to npm whoami, so the token is dead rather than mis-stored. Because the version bump and the release commit both land before the publish step, main advanced to 2026.8.18 with no matching tag and no published artifact while npm still serves 2026.8.18. Sixteen of the eighteen published fleet packages are in the same state."},{"op":"add","path":"/metadata/type","value":"Issue"},{"op":"add","path":"/metadata/status","value":"in_progress"},{"op":"add","path":"/metadata/priority","value":0},{"op":"add","path":"/metadata/tags","value":["npm","release","supply-chain"]},{"op":"add","path":"/metadata/created_at","value":"2026-08-26T19:33:40.186Z"},{"op":"add","path":"/metadata/updated_at","value":"2026-08-26T19:33:40.186Z"},{"op":"add","path":"/metadata/deadline","value":"2026-09-02T00:00:00.000Z"},{"op":"add","path":"/metadata/assignee","value":"claude"},{"op":"add","path":"/metadata/author","value":"claude"},{"op":"add","path":"/metadata/estimated_minutes","value":90},{"op":"add","path":"/metadata/acceptance_criteria","value":"No release workflow references NODE_AUTH_TOKEN NPM_TOKEN or secrets.NPM outside a comment; the publish job carries id-token write; npm is raised to at least 11.5.1 before the publish step because the npm bundled with node 22 cannot exchange an OIDC token; a test fails closed if a stored token is reintroduced or the npm upgrade is removed"},{"op":"add","path":"/metadata/comments","value":[{"created_at":"2026-08-26T19:33:40.186Z","author":"claude","text":"Guards verified as non-vacuous: reintroducing NODE_AUTH_TOKEN fails the OIDC test and deleting the npm upgrade step fails the npm-version test, while the unmodified tree passes both."}]},{"op":"add","path":"/metadata/notes","value":[{"created_at":"2026-08-26T19:33:40.186Z","author":"claude","text":"Root cause was found by comparing npm view against the branch, not by reading CI. Every job except publish was green for ten days."}]},{"op":"add","path":"/metadata/learnings","value":[{"created_at":"2026-08-26T19:33:40.186Z","author":"claude","text":"A release pipeline that bumps and commits the version before it publishes hides a credential outage indefinitely. Registry state, not workflow state, is the definition of released."}]},{"op":"add","path":"/metadata/files","value":[{"path":".github/workflows/release.yml","scope":"project"}]},{"op":"add","path":"/metadata/tests","value":[{"command":"npx tsx --test test/release-workflow.test.ts","scope":"project"}]},{"op":"add","path":"/metadata/docs","value":[{"path":"https://docs.npmjs.com/trusted-publishers","scope":"project","note":"npm trusted publishing setup"}]}],"before_hash":"3cc22dff72be7b14824654a7a64ea62b04799939b2fee54c1b5f52ca60bf6df0","after_hash":"4a18fb50a710db67eeedf85a8591f5864248be8eaa39c8c2a0f9bf6304bed33e","item_hash_version":2,"message":"Record the npm credential outage and migrate this package to trusted publishing","context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
{"ts":"2026-08-26T23:06:20.627Z","author":"codex","author_source":"configured","agent_harness":"claude-code","agent_instance":"66f51baccd944ab11404f28c","agent_provenance":{"model":null,"effort":{"value":"xhigh","source":"environment"},"role":{"value":"implementer","source":"argv"},"topic":null},"op":"update","patch":[{"op":"replace","path":"/metadata/updated_at","value":"2026-08-26T23:06:20.627Z"},{"op":"replace","path":"/metadata/description","value":"The Publish npm package step read NODE_AUTH_TOKEN from the repository secret NPM_TOKEN. That credential began being rejected on 2026-08-17 UTC. From then until 2026-08-26 UTC every daily release run reached the publish step and failed with npm code E404 on PUT to the registry, which is how npm reports a rejected write credential rather than a missing package. Rotating the secret on 2026-08-22 UTC did not help, and the copy of the credential on the maintainer host answers 401 to npm whoami, so the token is dead rather than mis-stored. Because the version bump and the release commit both land before the publish step, main advanced to 2026.8.18 with no matching tag and no published artifact while npm still serves 2026.8.18. Sixteen of the eighteen published fleet packages are in the same state."}],"before_hash":"4a18fb50a710db67eeedf85a8591f5864248be8eaa39c8c2a0f9bf6304bed33e","after_hash":"3c88f3bf5e2161a0773e5ebda180b96d791fac742ebc0244f6379eeebb6ca152","item_hash_version":2,"context":{"agent_provenance_outcomes":{"model":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"},"version":{"status":"failed","reason":"resolver_failed","resolver":"claude_session_file","rule_version":"v1"}}}}
Loading