Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Release runs fail at publish.nodejs (ENEEDAUTH) after publishing the GitHub release

Open Beginner friendly
#2,531 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
68/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
github-actions, nodejs
Domain
ci-cd, release

Research direction

Start by locating the repository's release workflow and inspect how it invokes Extra-Chill/homeboy-action@v2, especially the publish.nodejs step and the id-token permission. Review the v2.20.0 trusted-publishing change and confirm the workflow no longer fails when these packages are not intended for npm, then rerun or inspect a release workflow to verify the GitHub release succeeds without a red run.

Written by the indexing model from the issue text.

Description

Observed

The last two Release runs published their GitHub release and assets, then ended in failure:

The failing step is publish.nodejs:

Release step publish.nodejs (publish.nodejs) failed: Publish to nodejs via nodejs was not completed: registry authentication required (ENEEDAUTH)

The job also logs actions/create-github-app-token@v3 failing on an empty client-id.

Context

  • None of @automattic/wp-codebox-cli, @automattic/wp-codebox-core, or @automattic/wp-codebox-playground exists on npm, and the root wp-codebox-workspace is private: true.
  • The shared workflow (Extra-Chill/homeboy-action release workflow @v2) gained an npm trusted-publishing path in v2.20.0, and 72a453a7 granted id-token: write so it could start. The repository has no npm trusted publisher and no token, so the new publish step runs and fails on every release.

Expected

One of these:

  • Opt out of publish.nodejs for this component (the non-private workspace packages are not meant for npm).
  • Or configure npm trusted publishing for the packages that should be published.

The GitHub release step already succeeds. Only the red run and the failed-SHA bookkeeping are affected, but that masks real release failures.


AI assistance: written with Claude Code (Claude Opus 4) from the release run logs and npm registry checks; a human reviewed it.

Dominant language
TypeScript
Stars
17
Forks
4
Avg merge
51m
Merged PRs (30d)
60

Getting set up

We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Automattic/wp-codebox

All issues in Automattic/wp-codebox

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.