Repository navigation
ci: re-enable npm provenance now that the repo is public - #35
Conversation
--provenance requires a public repository, so the flag was removed while this repo was internal. The repo is public now, so published packages can carry sigstore provenance attestations again. Prerequisites are already in place: workflow-level id-token: write, and the release job upgrades npm before publishing. Closes #4
|
Claude finished @dangrondahl's task in 1m 24s —— View job Review:
|
Auth is npm Trusted Publishing (OIDC), not token auth — id-token: write exists for that, not for --provenance. The previous comment implied the opposite, which would mislead anyone pruning permissions. Trusted publishing emits provenance automatically on a public repo, so the flag is redundant rather than load-bearing; noted as such.
The flag is redundant under trusted publishing on a public repo, but not inert: it makes npm fail when provenance cannot be generated, where the automatic path may skip silently. bc20f2d ('fix: remove --provenance flag (requires public repo)') is this repo's own evidence — the flag broke the publish while private rather than degrading quietly. Records a reason that survives scrutiny, so the next reader doesn't delete it as dead weight.
Version bump only — `package.json` and `package-lock.json`. Merge this, then tag `v0.5.0` on `main` to trigger the release. ## What ships One user-facing change since `v0.4.0`: the regenerated catalog from #18. - `list_flows` gains `space_id` and `tag` query filters - `include_scaling` is marked `deprecated` - `list_artifact_approvals` is **removed** — the endpoint was retired upstream Everything else since `v0.4.0` is CI, docs, and repo hygiene, none of which reaches the npm tarball. The README does ship, so the new beta notice and write-action caution go out with this. ## Why minor, not patch An action disappearing from the catalog is user-visible: anything calling `list_artifact_approvals` via `execute_read_action` stops resolving. Pre-1.0, a minor bump is the conventional signal for that, even though the removal originated upstream rather than here. ## Notes - `manifest.json` still holds its `0.0.0-replaced-at-build-time` placeholder, injected by the pack script — untouched, as intended. - Both `package.json` and `package-lock.json` were updated via `npm version --no-git-tag-version`, so the lockfile doesn't drift. - Tests pass locally: 8 files, 65 tests. - This should be the first release carrying npm provenance, now that the repo is public and #35 has landed. Verify after publish with `npm view @kosli/mcp-server dist.attestations` — it returned `null` for 0.4.0.
Closes #4.
One line:
npm publish --access public→npm publish --access public --provenance.The flag was removed while the repo was internal, since npm provenance requires a public repository. That's no longer true, so published packages can carry sigstore provenance attestations again — npmjs.com shows a "Built and signed on GitHub Actions" badge linking back to the workflow run that produced the tarball.
Prerequisites, verified against the workflow
id-token: writeis already granted at workflow level (alongsidecontents: write) — provenance needs it to mint the OIDC token.npm install -g npm@latestbefore publishing, so the npm version is new enough to support the flag.actions/setup-nodealready setsregistry-url.Nothing else changes.
NODE_AUTH_TOKENand the tag-vs-package.jsonversion check are untouched.Note on verification
This can only be confirmed by cutting a release — there's no way to exercise
npm publishfrom CI without publishing. The next tagged release will either produce a package with provenance or fail loudly at the publish step, which is the same blast radius the publish step already has.Complementary to #21: sigstore provenance proves who built the npm package; Kosli attestations record what the artifact is and what evidence backs it.