
go-tokenless
io.github.Continuous-Actionsv0.1.0更新于 Oct 6, 2026
Move npm publishing in GitHub Actions from NPM_TOKEN to trusted publishing (OIDC).
概览
让助手规划并执行把 GitHub Actions 中的 npm 发布从 NPM_TOKEN 迁移到 npm 可信发布(OIDC)的改动。
- 功能
- 提供两个工具:plan_trusted_publishing 为只读,报告将要发生的改动;apply_trusted_publishing 会把改动写入工作流和 package.json 文件。它会从发布步骤中移除 NODE_AUTH_TOKEN 和 NPM_TOKEN、授予 id-token: write、添加 registry-url、更新被固定版本的发布 action,并修正 repository 字段。它还会打印 npm trust github 命令和剩余的手动步骤,在可信发布无法生效时拒绝执行而不是猜测。
- 适用场景
- 适用于从 GitHub Actions 发布 npm 包的仓库,希望用 OIDC 可信发布取代长期有效的 npm 令牌,包括 changesets、semantic-release、release-please、Lerna、Nx、pnpm、Yarn Berry 和 release-it 等发布方式。
- 运行要求
- 通过 npx 在本地运行的进程(npm 包 go-tokenless),需要 Node 22.14+。未声明任何账号、API 密钥、环境变量或请求头。它会读取本地仓库的工作流和 package.json;可用 --offline 跳过 npm registry 查询。
安装
在 SourceWeft 中
- 打开 控制台中的 go-tokenless,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
go-tokenless
Delete your NPM_TOKEN. One command switches your GitHub Actions release workflow to npm trusted publishing (OIDC), so no long-lived npm token has to be stored anywhere.
npm is retiring direct publishing with tokens: from January 2027 a granular token with "bypass 2FA" can no longer publish on its own (npm docs). Trusted publishing is the replacement for CI. It also adds a provenance badge to every release.
What it does
It reads your workflows and package.json files, then:
It also prints the exact npm trust github … command for every package and the remaining manual steps.
It refuses (exit code 1) rather than guessing when trusted publishing can't work: self-hosted runners, or a repository field pointing at another repo. It leaves jobs that publish to GitHub Packages alone.
Example
The default command also prints a unified diff. Your file's comments, quoting and layout are kept: only the lines that need to change are touched.
Supported release setups
Version floors are checked against your package.json where possible.
Things only you can do
The tool never touches your npm account. After applying:
- Add a trusted publisher for each package: the printed
npm trust github …commands (npm 11.15+, needs your 2FA), or npmjs.com → package → Settings → Trusted publishing. - Brand-new packages must be published once by hand first; npm can only attach a trusted publisher to a package that exists. The plan flags these.
- Delete the secret and revoke the token once a release has gone out.
Use it from an AI coding agent
Agents can run the CLI with --json (stable shape, status field, exit codes), or use the MCP server:
Tools: plan_trusted_publishing (read-only) and apply_trusted_publishing (writes files, no git or network writes). There is also an Agent Skill:
Or install the skill and MCP server together as a plugin:
Just ask: "Move our npm publishing to trusted publishing."
Options
Exit codes: 0 ok, 1 blocked (errors to fix by hand), 2 usage error, 3 unexpected error. Needs Node 22.14+.
npm version
When a publish job runs on a Node version whose bundled npm is too old, go-tokenless adds npm install -g npm@^12. It is pinned to one major on purpose: a new npm major can change how publishing behaves, and a release pipeline should not change under you. npm 12 needs Node 22.22.2+ or 24.15+; jobs pinned to an older exact Node 22 get a warning.
To use a different npm, pass --npm-version (for example --npm-version ^11.6.0). go-tokenless warns that an untested version may break the release, and refuses versions older than 11.5.1, which cannot use trusted publishing.
Troubleshooting the errors people hit
npm error code ENEEDAUTH: the job has noid-token: write, npm is older than 11.5.1, or the workflow file name doesn't match the trusted publisher exactly (case-sensitive, with.yml).npm error 404 Not Found - PUT https://registry.npmjs.org/...: usually the same causes as ENEEDAUTH, anenvironmentmismatch, or the package has no trusted publisher yet.npm error code E422…repository.url:package.jsonrepositorydoesn't match the GitHub repo.go-tokenless applyfixes the format; a different repo is reported as an error.- Publishing still uses the token: something still sets
NODE_AUTH_TOKEN,NPM_TOKEN, an.npmrc_authToken, or.yarnrc.ymlnpmAuthToken. Runnpx go-tokenlessagain; it reports leftovers.
License
MIT
来源:README.md,提交 108300f
工具
0版本历史
1- v0.1.0最新Oct 6, 2026


