[DOCS] `npm trust circle` docs should warn that OIDC token exchange in SSH reruns isn't supported
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 68/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- javascript
- Domain
- cli, documentation
Research direction
Start at the documentation entry point for npm trust circle and read the trusted publishing guidance alongside the CircleCI SSH rerun limitation described in the issue. Update the relevant docs to warn that OIDC token exchange is unsupported in SSH reruns, so users do not misdiagnose the resulting 404; confirm the warning is visible in the npm trust circle documentation.
Written by the indexing model from the issue text.
Description
Is there an existing issue for this?
- I have searched the existing issues
This is a CLI Docs Problem, not another kind of Docs Problem.
- This is a CLI Docs Problem.
Description of Problem
When I first tried to set up trusted publishing with CircleCI, I was getting 404s even though all the UUIDs I had configured for my trusted publisher were valid. I had no idea what was wrong for two reasons:
- It was giving me a
404 package not founderror instead of something like403 not supported in SSH reruns - OIDC exchange failures aren't even logged by default: https://github.com/npm/cli/issues/9923
- I read all of your docs about
npm trust circleand trusted publishing, but they didn't warn that SSH reruns aren't supported.
The CircleCI docs say that SSH reruns aren't supported, but I read your docs. Your docs and error messages alone should be sufficient to figure out how to get trusted publishing to work. Paying customers deserve a better DX than this.
Potential Solution
No response
Affected URL
No response
- Dominant language
- JavaScript
- Stars
- 10.1k
- Forks
- 4.7k
- Avg merge
- 2d 2h
- Merged PRs (30d)
- 21
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from npm/cli
-
Documentation Needs Triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
-
Bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
allowScripts Bug Needs Triage Priority 2
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
Bug Needs Triage
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HarperFast/skills#96 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
sugarlabs/musicblocks#8847 ·
-
client-controller-update ta-bot-triage team-money-movement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
MetaMask/metamask-mobile#36594 ·