Skip to content

fix(release): dispatch publish/homebrew instead of workflow_call (npm OIDC mismatch)#81

Merged
I4cTime merged 1 commit into
developfrom
fix/release-dispatch
Jul 11, 2026
Merged

fix(release): dispatch publish/homebrew instead of workflow_call (npm OIDC mismatch)#81
I4cTime merged 1 commit into
developfrom
fix/release-dispatch

Conversation

@I4cTime

@I4cTime I4cTime commented Jul 11, 2026

Copy link
Copy Markdown
Owner

Summary

Second and final fix from the first live v0.13.0 tag run. The concurrency deadlock (#78) was fixed; the retry then created the GitHub Release but npm rejected the publish — trusted publishing validates the OIDC token's top-level workflow file, which is release.yml under workflow_call, while the npm trusted publisher is registered for publish.yml (npm's misleading E404, same signature as the v0.10.1 incident).

Fix: release.yml now dispatches publish.yml and update-homebrew.yml on the tag ref. Explicit workflow_dispatch API calls are allowed with GITHUB_TOKEN (recursion prevention only blocks event-triggered runs), and dispatched runs are top-level, so the OIDC claim matches the existing npm config. Homebrew already polls npm for up to 5 minutes, so dispatch ordering is safe.

After this lands on develop → main, delete the v0.13.0 release + tag and re-push the tag to run the chain end-to-end.

Type

  • Fix

Checklist

  • Workflow YAML validates
  • No code changes — typecheck/lint/test unaffected
  • docs/releasing.md updated with the dispatch architecture

Breaking changes

None.

🤖 Generated with Claude Code

… OIDC)

The first v0.13.0 run created the GitHub Release but npm rejected the
publish with its misleading E404: npm trusted publishing validates the
OIDC token's top-level workflow file, which is release.yml when
publish.yml runs via workflow_call — but the trusted publisher on
npmjs.com is registered for publish.yml.

release.yml now dispatches publish.yml and update-homebrew.yml on the
tag ref via the workflow_dispatch API (allowed with GITHUB_TOKEN; the
recursion block only suppresses event-triggered runs). Dispatched runs
have publish.yml as their top-level workflow, so the OIDC claim matches
the existing npm configuration and the manual re-run path keeps working
unchanged.

- release.yml: permissions actions:write (id-token no longer needed
  here), dispatch step after release creation
- publish.yml: drop the now-unused workflow_call trigger
- update-homebrew.yml: workflow_call -> workflow_dispatch (it already
  polls npm for up to 5 min, so dispatch order doesn't matter)
- docs/releasing.md: document the dispatch architecture and both
  failure modes hit on the first tag run

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@I4cTime
I4cTime merged commit 3f23e8c into develop Jul 11, 2026
8 checks passed
@I4cTime
I4cTime deleted the fix/release-dispatch branch July 11, 2026 07:00
I4cTime added a commit that referenced this pull request Jul 11, 2026
… OIDC) (#81) (#82)

The first v0.13.0 run created the GitHub Release but npm rejected the
publish with its misleading E404: npm trusted publishing validates the
OIDC token's top-level workflow file, which is release.yml when
publish.yml runs via workflow_call — but the trusted publisher on
npmjs.com is registered for publish.yml.

release.yml now dispatches publish.yml and update-homebrew.yml on the
tag ref via the workflow_dispatch API (allowed with GITHUB_TOKEN; the
recursion block only suppresses event-triggered runs). Dispatched runs
have publish.yml as their top-level workflow, so the OIDC claim matches
the existing npm configuration and the manual re-run path keeps working
unchanged.

- release.yml: permissions actions:write (id-token no longer needed
  here), dispatch step after release creation
- publish.yml: drop the now-unused workflow_call trigger
- update-homebrew.yml: workflow_call -> workflow_dispatch (it already
  polls npm for up to 5 min, so dispatch order doesn't matter)
- docs/releasing.md: document the dispatch architecture and both
  failure modes hit on the first tag run

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant