From 4170a459c67a7a1c4b03e98af64d0da0639eb94a Mon Sep 17 00:00:00 2001 From: Xiao Yijun Date: Mon, 31 Aug 2026 16:28:10 +0800 Subject: [PATCH] fix: publish through npx npm@11 with an explicit dist-tag The tag-triggered publish failed on npm 11's new prerelease guard: "You must specify a tag using --tag when publishing a prerelease version." Publish via `npx npm@11` with an explicit `--tag latest` (the beta deliberately lands on `latest`), mirroring the working logto-io/cli-auth setup: the npx pin also removes the dependency on the Node-bundled npm version, so the publish job goes back to Node 22 in line with the rest of CI. Also normalize `repository.url` to the `git+https` form npm 11 auto-corrects at publish time. Co-Authored-By: Claude Fable 5 --- .github/workflows/publish.yml | 12 ++++++------ packages/mcp-auth/package.json | 2 +- 2 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 71eb404..e5e8f71 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -24,14 +24,14 @@ jobs: uses: silverhand-io/actions-node-pnpm-run-steps@v5 with: pnpm-version: 10.34.5 - # Node 24, not 22: `pnpm publish` delegates the actual publish to the npm CLI, - # and npm's OIDC trusted publishing requires npm >= 11.5.1 — bundled with - # Node 24, while Node 22 still ships npm 10.x. - node-version: 24 + node-version: 22 # Authenticates via OIDC trusted publishing (configured on npmjs.com for this # package: repository mcp-auth/js, workflow publish.yml) — no npm token involved. - # Requires the `id-token: write` permission above. + # Runs through `npx npm@11` because npm's OIDC support requires npm >= 11.5.1, + # while `pnpm publish` delegates to the npm bundled with Node (10.x on Node 22). + # npm 11 also requires an explicit --tag for prerelease versions; this package + # deliberately publishes betas to `latest` (the ecosystem default is MCP SDK v2). - name: Publish to npm working-directory: packages/mcp-auth - run: pnpm publish --provenance --no-git-checks + run: npx --yes npm@11 publish --tag latest --provenance diff --git a/packages/mcp-auth/package.json b/packages/mcp-auth/package.json index f084a2a..b5b67db 100644 --- a/packages/mcp-auth/package.json +++ b/packages/mcp-auth/package.json @@ -28,7 +28,7 @@ "license": "MIT", "repository": { "type": "git", - "url": "https://github.com/mcp-auth/js.git", + "url": "git+https://github.com/mcp-auth/js.git", "directory": "packages/mcp-auth" }, "scripts": {