Skip to content

ci: re-enable npm provenance now that the repo is public - #35

Merged
dangrondahl merged 3 commits into
mainfrom
ci/npm-provenance
Aug 11, 2026
Merged

dangrondahl merged 3 commits into
mainfrom
ci/npm-provenance

Conversation

@dangrondahl

Copy link
Copy Markdown
Contributor

Closes #4.

One line: npm publish --access public → npm publish --access public --provenance.

The flag was removed while the repo was internal, since npm provenance requires a public repository. That's no longer true, so published packages can carry sigstore provenance attestations again — npmjs.com shows a "Built and signed on GitHub Actions" badge linking back to the workflow run that produced the tarball.

Prerequisites, verified against the workflow

  • id-token: write is already granted at workflow level (alongside contents: write) — provenance needs it to mint the OIDC token.
  • The job already runs npm install -g npm@latest before publishing, so the npm version is new enough to support the flag.
  • actions/setup-node already sets registry-url.

Nothing else changes. NODE_AUTH_TOKEN and the tag-vs-package.json version check are untouched.

Note on verification

This can only be confirmed by cutting a release — there's no way to exercise npm publish from CI without publishing. The next tagged release will either produce a package with provenance or fail loudly at the publish step, which is the same blast radius the publish step already has.

Complementary to #21: sigstore provenance proves who built the npm package; Kosli attestations record what the artifact is and what evidence backs it.

--provenance requires a public repository, so the flag was removed while
this repo was internal. The repo is public now, so published packages can
carry sigstore provenance attestations again.

Prerequisites are already in place: workflow-level id-token: write, and the
release job upgrades npm before publishing.

Closes #4
@claude

claude Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Claude finished @dangrondahl's task in 1m 24s —— View job


Review: ci: re-enable npm provenance now that the repo is public

  • Read CLAUDE.md and repo conventions
  • Diff origin/main...HEAD and read the full release.yml
  • Re-check the two findings from the previous runs against the new commits
  • Verify provenance prerequisites in package.json

Both points from the earlier reviews landed — 97d3824 fixed the id-token: write misattribution and 0048762 replaced the weak "intent survives an auth change" justification with the fail-closed framing. The comment at .github/workflows/release.yml:51-54 is now accurate on all three claims: OIDC auth is what the permission is for, trusted publishing generates provenance automatically on a public repo, and --provenance turns a silent skip into a hard failure. No further changes needed on the diff itself.

Prerequisite check (all satisfied)

--provenance needs npm to match the package's declared source against the building repo, and it refuses to publish if they disagree. Verified:

  • package.json:24-27 — repository.url is git+https://github.com/kosli-dev/mcp-server.git, matching kosli-dev/mcp-server. This is the prerequisite most likely to bite, and it holds.
  • No publishConfig block, so nothing can silently override the flag (a publishConfig.provenance: false would have).
  • id-token: write at release.yml:9, registry-url at :27, npm upgraded at :29-30.

One optional follow-up (not in the diff, so no inline suggestion possible)

The comment's load-bearing warning is "dropping it breaks publishing entirely" — but it sits at line 51, and whoever prunes permissions is editing lines 7-9. A pointer where they'll actually be looking:

permissions:
  contents: write
  id-token: write # npm Trusted Publishing (OIDC) — removing this breaks `npm publish`

Fix this →

Pre-existing, out of scope

npm install -g npm@latest (:29-30) is unpinned in the release path. It's what makes both trusted publishing and provenance work today, but it also means a breaking npm release can fail a tagged release with no change on this side. Worth pinning to a floor (npm@^11) at some point — not something this PR should take on.

Nice work

The PR description does the thing most one-line CI changes skip: it enumerates the prerequisites and states plainly that this can only be verified by cutting a release, with an honest read on blast radius. The commit history is also good practice — three focused ci: commits rather than amending the correction into the original, so the reasoning behind the comment's wording is recoverable from git log. Conventional Commits followed throughout; manifest.json's version placeholder untouched.

Verdict: approve. No blocking issues. Nothing in src/ changed, so no tests were warranted; I did not run the suite as there is nothing here it could exercise. Note I can't push to .github/workflows/ myself (GitHub App permissions exclude workflow files), so the optional follow-up above is yours to take or leave.
· branch ci/npm-provenance

Comment thread .github/workflows/release.yml
Auth is npm Trusted Publishing (OIDC), not token auth — id-token: write
exists for that, not for --provenance. The previous comment implied the
opposite, which would mislead anyone pruning permissions.

Trusted publishing emits provenance automatically on a public repo, so the
flag is redundant rather than load-bearing; noted as such.
Comment thread .github/workflows/release.yml
The flag is redundant under trusted publishing on a public repo, but not
inert: it makes npm fail when provenance cannot be generated, where the
automatic path may skip silently. bc20f2d ('fix: remove --provenance flag
(requires public repo)') is this repo's own evidence — the flag broke the
publish while private rather than degrading quietly.

Records a reason that survives scrutiny, so the next reader doesn't delete
it as dead weight.
@dangrondahl
dangrondahl enabled auto-merge (squash) August 11, 2026 14:15
@dangrondahl
dangrondahl merged commit c910c58 into main Aug 11, 2026
4 checks passed
@dangrondahl
dangrondahl deleted the ci/npm-provenance branch August 11, 2026 14:31
FayeSGW pushed a commit that referenced this pull request Aug 11, 2026
Version bump only — `package.json` and `package-lock.json`. Merge this,
then tag `v0.5.0` on `main` to trigger the release.

## What ships

One user-facing change since `v0.4.0`: the regenerated catalog from #18.

- `list_flows` gains `space_id` and `tag` query filters
- `include_scaling` is marked `deprecated`
- `list_artifact_approvals` is **removed** — the endpoint was retired
upstream

Everything else since `v0.4.0` is CI, docs, and repo hygiene, none of
which reaches the npm tarball. The README does ship, so the new beta
notice and write-action caution go out with this.

## Why minor, not patch

An action disappearing from the catalog is user-visible: anything
calling `list_artifact_approvals` via `execute_read_action` stops
resolving. Pre-1.0, a minor bump is the conventional signal for that,
even though the removal originated upstream rather than here.

## Notes

- `manifest.json` still holds its `0.0.0-replaced-at-build-time`
placeholder, injected by the pack script — untouched, as intended.
- Both `package.json` and `package-lock.json` were updated via `npm
version --no-git-tag-version`, so the lockfile doesn't drift.
- Tests pass locally: 8 files, 65 tests.
- This should be the first release carrying npm provenance, now that the
repo is public and #35 has landed. Verify after publish with `npm view
@kosli/mcp-server dist.attestations` — it returned `null` for 0.4.0.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Re-enable --provenance flag when repo becomes public

2 participants