go-tokenless

io.github.Continuous-Actionsv0.1.0更新于 Oct 6, 2026

Move npm publishing in GitHub Actions from NPM_TOKEN to trusted publishing (OIDC).

概览

AI 生成的概览

让助手规划并执行把 GitHub Actions 中的 npm 发布从 NPM_TOKEN 迁移到 npm 可信发布(OIDC)的改动。

功能
提供两个工具:plan_trusted_publishing 为只读,报告将要发生的改动;apply_trusted_publishing 会把改动写入工作流和 package.json 文件。它会从发布步骤中移除 NODE_AUTH_TOKEN 和 NPM_TOKEN、授予 id-token: write、添加 registry-url、更新被固定版本的发布 action,并修正 repository 字段。它还会打印 npm trust github 命令和剩余的手动步骤,在可信发布无法生效时拒绝执行而不是猜测。
适用场景
适用于从 GitHub Actions 发布 npm 包的仓库,希望用 OIDC 可信发布取代长期有效的 npm 令牌,包括 changesets、semantic-release、release-please、Lerna、Nx、pnpm、Yarn Berry 和 release-it 等发布方式。
运行要求
通过 npx 在本地运行的进程(npm 包 go-tokenless),需要 Node 22.14+。未声明任何账号、API 密钥、环境变量或请求头。它会读取本地仓库的工作流和 package.json;可用 --offline 跳过 npm registry 查询。
安装前请注意
apply_trusted_publishing 会写入仓库中的工作流和 package.json 文件,请先查看计划或 diff,并在分支上提交。它不会操作 npm 账号:添加可信发布者、首次手动发布全新包、删除或吊销旧的 NPM_TOKEN 密钥仍需手动完成。它拒绝处理自托管 runner 和 repository 字段不匹配的情况。

安装

在 SourceWeft 中

  1. 打开 控制台中的 go-tokenless,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。

其他 MCP 客户端

参照 仓库 中的启动说明。

README

go-tokenless

Delete your NPM_TOKEN. One command switches your GitHub Actions release workflow to npm trusted publishing (OIDC), so no long-lived npm token has to be stored anywhere.

bash
npx go-tokenless          # show what would change (writes nothing)npx go-tokenless apply    # make the changes

npm is retiring direct publishing with tokens: from January 2027 a granular token with "bypass 2FA" can no longer publish on its own (npm docs). Trusted publishing is the replacement for CI. It also adds a provenance badge to every release.

What it does

It reads your workflows and package.json files, then:

ProblemFix it makes
NODE_AUTH_TOKEN / NPM_TOKEN passed to the publish step or jobRemoves it (a token, even an empty one, stops npm from using OIDC)
Job can't request an OIDC tokenAdds permissions: id-token: write (keeping the permissions the job already had)
Node 22 or older ships npm < 11.5.1Adds an npm install -g npm@^12 step (pinned to one major, see npm version), or moves Node < 22 to 24
actions/setup-node without registry-urlAdds registry-url: https://registry.npmjs.org
changesets/action@v1, JS-DevTools/npm-publish@v3Updates to the version that supports trusted publishing
Script writes _authToken into .npmrcRemoves those lines
repository missing or in the wrong form in package.jsonAdds git+https://github.com/<owner>/<repo>.git (with directory in monorepos)

It also prints the exact npm trust github … command for every package and the remaining manual steps.

It refuses (exit code 1) rather than guessing when trusted publishing can't work: self-hosted runners, or a repository field pointing at another repo. It leaves jobs that publish to GitHub Packages alone.

Example

text
$ npx go-tokenlessgo-tokenless: Ready to go tokenless. (acme/widgets)
Changes:  .github/workflows/release.yml    - publish: remove `NODE_AUTH_TOKEN` from job env    - publish: grant `id-token: write`    - publish: raise setup-node from Node 20 to 24 (trusted publishing needs Node 22.14+)  package.json    - widgets: add repository.url git+https://github.com/acme/widgets.git
Next:  1. Run `npx go-tokenless apply` (or apply the diff above) and commit the changes on a branch.  2. Add a trusted publisher for each package. With npm 11.15+ logged in with 2FA, run:       npm trust github widgets --repo acme/widgets --file release.yml --allow-publish --yes  3. Merge, then let the release workflow publish once. Check the new version shows a provenance badge.  4. Delete the old secret (`gh secret delete NPM_TOKEN`) and revoke the token on npmjs.com.

The default command also prints a unified diff. Your file's comments, quoting and layout are kept: only the lines that need to change are touched.

Supported release setups

SetupSupportedNotes
npm publish (incl. workspaces)✓
pnpm publish / -r publish✓pnpm 10 hands off to npm; pnpm 11 needs 11.1.3+
Yarn Berry yarn npm publish✓Yarn 4.10.3+; remove npmAuthToken from .yarnrc.yml
changesets (changesets/action)✓updated to v2
semantic-release✓needs @semantic-release/npm 13.1.0+ (semantic-release 25+)
release-please + npm publish✓
Lerna / Nx release✓Lerna 9+
JS-DevTools/npm-publish✓updated to v4
release-it✓also set npm.skipChecks: true
Yarn 1 yarn publish, bun publishwarnsnot supported by those tools yet; switch the command to npm publish
Reusable workflows (workflow_call)✓npm checks the calling workflow's file name; the plan uses it

Version floors are checked against your package.json where possible.

Things only you can do

The tool never touches your npm account. After applying:

  1. Add a trusted publisher for each package: the printed npm trust github … commands (npm 11.15+, needs your 2FA), or npmjs.com → package → Settings → Trusted publishing.
  2. Brand-new packages must be published once by hand first; npm can only attach a trusted publisher to a package that exists. The plan flags these.
  3. Delete the secret and revoke the token once a release has gone out.

Use it from an AI coding agent

Agents can run the CLI with --json (stable shape, status field, exit codes), or use the MCP server:

bash
claude mcp add go-tokenless -- npx -y go-tokenless mcp
json
{ "mcpServers": { "go-tokenless": { "command": "npx", "args": ["-y", "go-tokenless", "mcp"] } } }

Tools: plan_trusted_publishing (read-only) and apply_trusted_publishing (writes files, no git or network writes). There is also an Agent Skill:

bash
npx skills add Continuous-Actions/go-tokenless

Or install the skill and MCP server together as a plugin:

bash
# Claude Code/plugin marketplace add Continuous-Actions/go-tokenless/plugin install go-tokenless@continuous-actions
bash
# Gemini CLIgemini extensions install https://github.com/Continuous-Actions/go-tokenless

Just ask: "Move our npm publishing to trusted publishing."

Options

text
npx go-tokenless [plan|apply|mcp] [--json] [--diff] [--repo owner/repo] [--cwd dir] [--offline]                  [--npm-version <range>] [--npm-args "<args>"]
OptionMeaning
--jsonPrint the full plan as JSON
--diffInclude the diff (always on for plan)
--repoGitHub owner/repo, when the origin remote isn't GitHub
--offlineSkip the npm registry lookup that checks each package already exists
--npm-version <range>npm version for the inserted upgrade step. Default ^12
--npm-args "<args>"Extra arguments appended to every npm command it generates: the upgrade step and the npm trust commands (for example --registry=… or --loglevel=warn)

Exit codes: 0 ok, 1 blocked (errors to fix by hand), 2 usage error, 3 unexpected error. Needs Node 22.14+.

npm version

When a publish job runs on a Node version whose bundled npm is too old, go-tokenless adds npm install -g npm@^12. It is pinned to one major on purpose: a new npm major can change how publishing behaves, and a release pipeline should not change under you. npm 12 needs Node 22.22.2+ or 24.15+; jobs pinned to an older exact Node 22 get a warning.

To use a different npm, pass --npm-version (for example --npm-version ^11.6.0). go-tokenless warns that an untested version may break the release, and refuses versions older than 11.5.1, which cannot use trusted publishing.

Troubleshooting the errors people hit

  • npm error code ENEEDAUTH: the job has no id-token: write, npm is older than 11.5.1, or the workflow file name doesn't match the trusted publisher exactly (case-sensitive, with .yml).
  • npm error 404 Not Found - PUT https://registry.npmjs.org/...: usually the same causes as ENEEDAUTH, an environment mismatch, or the package has no trusted publisher yet.
  • npm error code E422 … repository.url: package.json repository doesn't match the GitHub repo. go-tokenless apply fixes the format; a different repo is reported as an error.
  • Publishing still uses the token: something still sets NODE_AUTH_TOKEN, NPM_TOKEN, an .npmrc _authToken, or .yarnrc.yml npmAuthToken. Run npx go-tokenless again; it reports leftovers.

License

MIT

来源:README.md,提交 108300f

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v0.1.0最新Oct 6, 2026