Release runs fail at publish.nodejs (ENEEDAUTH) after publishing the GitHub release
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
Research direction
Start by locating the repository's release workflow and inspect how it invokes Extra-Chill/homeboy-action@v2, especially the publish.nodejs step and the id-token permission. Review the v2.20.0 trusted-publishing change and confirm the workflow no longer fails when these packages are not intended for npm, then rerun or inspect a release workflow to verify the GitHub release succeeds without a red run.
Written by the indexing model from the issue text.
Description
Observed
The last two Release runs published their GitHub release and assets, then ended in failure:
- v0.28.0: https://github.com/Automattic/wp-codebox/actions/runs/36139907539
- v0.27.3
The failing step is publish.nodejs:
Release step publish.nodejs (publish.nodejs) failed: Publish to nodejs via nodejs was not completed: registry authentication required (ENEEDAUTH)
The job also logs actions/create-github-app-token@v3 failing on an empty client-id.
Context
- None of
@automattic/wp-codebox-cli,@automattic/wp-codebox-core, or@automattic/wp-codebox-playgroundexists on npm, and the rootwp-codebox-workspaceisprivate: true. - The shared workflow (
Extra-Chill/homeboy-actionrelease workflow@v2) gained an npm trusted-publishing path in v2.20.0, and 72a453a7 grantedid-token: writeso it could start. The repository has no npm trusted publisher and no token, so the new publish step runs and fails on every release.
Expected
One of these:
- Opt out of
publish.nodejsfor this component (the non-private workspace packages are not meant for npm). - Or configure npm trusted publishing for the packages that should be published.
The GitHub release step already succeeds. Only the red run and the failed-SHA bookkeeping are affected, but that masks real release failures.
AI assistance: written with Claude Code (Claude Opus 4) from the release run logs and npm registry checks; a human reviewed it.
- Dominant language
- TypeScript
- Stars
- 17
- Forks
- 4
- Avg merge
- 51m
- Merged PRs (30d)
- 60
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Automattic/wp-codebox
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Automattic/wp-codebox#2467 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Automattic/wp-codebox#2466 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Automattic/wp-codebox#2105 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Automattic/wp-codebox#2061 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Automattic/wp-codebox#1714 · 1 comment ·
Maintainers usually reply within 1 day
All issues in Automattic/wp-codebox
Similar issues
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
inu-appcenter/memorIN-frontend#106 ·
Maintainers usually reply within 1 day
-
kind/bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 7 days
-
[Bug] @deck.gl/arcgis dist import resolves to unpublished @deck.gl/core source path (9.3.11, 9.4.0)Open
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
CSCfi/sd-search-ui#145 ·
Maintainers usually reply within 1 day
-
Add: Cbeebies pl SDOpencheck:passed streams:add
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day