go-tokenless

io.github.Continuous-Actionsv0.1.0更新於 Oct 6, 2026

Move npm publishing in GitHub Actions from NPM_TOKEN to trusted publishing (OIDC).

概覽

AI 產生的概覽

讓助理規劃並套用把 GitHub Actions 的 npm 發佈從 NPM_TOKEN 改為 npm 信任發佈(OIDC)的變更。

功能
提供兩個工具:plan_trusted_publishing 為唯讀,會報告即將發生的變更;apply_trusted_publishing 會把變更寫入工作流程與 package.json 檔案。它會從發佈步驟移除 NODE_AUTH_TOKEN 與 NPM_TOKEN、授予 id-token: write、加入 registry-url、更新被固定版本的發佈 action,並修正 repository 欄位。它也會印出 npm trust github 指令與剩下的手動步驟,在信任發佈無法運作時直接拒絕,而不是自行猜測。
適用情境
適用於從 GitHub Actions 發佈 npm 套件的儲存庫,想以 OIDC 信任發佈取代長期有效的 npm 權杖,包括 changesets、semantic-release、release-please、Lerna、Nx、pnpm、Yarn Berry 與 release-it 等發佈方式。
執行需求
以 npx 在本機執行的程序(npm 套件 go-tokenless),需要 Node 22.14+。未宣告任何帳號、API 金鑰、環境變數或標頭。它會讀取本機儲存庫的工作流程與 package.json;可用 --offline 略過 npm registry 查詢。
安裝前請注意
apply_trusted_publishing 會寫入儲存庫中的工作流程與 package.json 檔案,請先檢視計畫或 diff,並在分支上提交。它不會動到 npm 帳號:新增信任發佈者、首次手動發佈全新套件、刪除或撤銷舊的 NPM_TOKEN 密鑰仍需手動完成。它會拒絕處理自架 runner 與 repository 欄位不符的情況。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 go-tokenless,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

go-tokenless

Delete your NPM_TOKEN. One command switches your GitHub Actions release workflow to npm trusted publishing (OIDC), so no long-lived npm token has to be stored anywhere.

bash
npx go-tokenless          # show what would change (writes nothing)npx go-tokenless apply    # make the changes

npm is retiring direct publishing with tokens: from January 2027 a granular token with "bypass 2FA" can no longer publish on its own (npm docs). Trusted publishing is the replacement for CI. It also adds a provenance badge to every release.

What it does

It reads your workflows and package.json files, then:

ProblemFix it makes
NODE_AUTH_TOKEN / NPM_TOKEN passed to the publish step or jobRemoves it (a token, even an empty one, stops npm from using OIDC)
Job can't request an OIDC tokenAdds permissions: id-token: write (keeping the permissions the job already had)
Node 22 or older ships npm < 11.5.1Adds an npm install -g npm@^12 step (pinned to one major, see npm version), or moves Node < 22 to 24
actions/setup-node without registry-urlAdds registry-url: https://registry.npmjs.org
changesets/action@v1, JS-DevTools/npm-publish@v3Updates to the version that supports trusted publishing
Script writes _authToken into .npmrcRemoves those lines
repository missing or in the wrong form in package.jsonAdds git+https://github.com/<owner>/<repo>.git (with directory in monorepos)

It also prints the exact npm trust github … command for every package and the remaining manual steps.

It refuses (exit code 1) rather than guessing when trusted publishing can't work: self-hosted runners, or a repository field pointing at another repo. It leaves jobs that publish to GitHub Packages alone.

Example

text
$ npx go-tokenlessgo-tokenless: Ready to go tokenless. (acme/widgets)
Changes:  .github/workflows/release.yml    - publish: remove `NODE_AUTH_TOKEN` from job env    - publish: grant `id-token: write`    - publish: raise setup-node from Node 20 to 24 (trusted publishing needs Node 22.14+)  package.json    - widgets: add repository.url git+https://github.com/acme/widgets.git
Next:  1. Run `npx go-tokenless apply` (or apply the diff above) and commit the changes on a branch.  2. Add a trusted publisher for each package. With npm 11.15+ logged in with 2FA, run:       npm trust github widgets --repo acme/widgets --file release.yml --allow-publish --yes  3. Merge, then let the release workflow publish once. Check the new version shows a provenance badge.  4. Delete the old secret (`gh secret delete NPM_TOKEN`) and revoke the token on npmjs.com.

The default command also prints a unified diff. Your file's comments, quoting and layout are kept: only the lines that need to change are touched.

Supported release setups

SetupSupportedNotes
npm publish (incl. workspaces)✓
pnpm publish / -r publish✓pnpm 10 hands off to npm; pnpm 11 needs 11.1.3+
Yarn Berry yarn npm publish✓Yarn 4.10.3+; remove npmAuthToken from .yarnrc.yml
changesets (changesets/action)✓updated to v2
semantic-release✓needs @semantic-release/npm 13.1.0+ (semantic-release 25+)
release-please + npm publish✓
Lerna / Nx release✓Lerna 9+
JS-DevTools/npm-publish✓updated to v4
release-it✓also set npm.skipChecks: true
Yarn 1 yarn publish, bun publishwarnsnot supported by those tools yet; switch the command to npm publish
Reusable workflows (workflow_call)✓npm checks the calling workflow's file name; the plan uses it

Version floors are checked against your package.json where possible.

Things only you can do

The tool never touches your npm account. After applying:

  1. Add a trusted publisher for each package: the printed npm trust github … commands (npm 11.15+, needs your 2FA), or npmjs.com → package → Settings → Trusted publishing.
  2. Brand-new packages must be published once by hand first; npm can only attach a trusted publisher to a package that exists. The plan flags these.
  3. Delete the secret and revoke the token once a release has gone out.

Use it from an AI coding agent

Agents can run the CLI with --json (stable shape, status field, exit codes), or use the MCP server:

bash
claude mcp add go-tokenless -- npx -y go-tokenless mcp
json
{ "mcpServers": { "go-tokenless": { "command": "npx", "args": ["-y", "go-tokenless", "mcp"] } } }

Tools: plan_trusted_publishing (read-only) and apply_trusted_publishing (writes files, no git or network writes). There is also an Agent Skill:

bash
npx skills add Continuous-Actions/go-tokenless

Or install the skill and MCP server together as a plugin:

bash
# Claude Code/plugin marketplace add Continuous-Actions/go-tokenless/plugin install go-tokenless@continuous-actions
bash
# Gemini CLIgemini extensions install https://github.com/Continuous-Actions/go-tokenless

Just ask: "Move our npm publishing to trusted publishing."

Options

text
npx go-tokenless [plan|apply|mcp] [--json] [--diff] [--repo owner/repo] [--cwd dir] [--offline]                  [--npm-version <range>] [--npm-args "<args>"]
OptionMeaning
--jsonPrint the full plan as JSON
--diffInclude the diff (always on for plan)
--repoGitHub owner/repo, when the origin remote isn't GitHub
--offlineSkip the npm registry lookup that checks each package already exists
--npm-version <range>npm version for the inserted upgrade step. Default ^12
--npm-args "<args>"Extra arguments appended to every npm command it generates: the upgrade step and the npm trust commands (for example --registry=… or --loglevel=warn)

Exit codes: 0 ok, 1 blocked (errors to fix by hand), 2 usage error, 3 unexpected error. Needs Node 22.14+.

npm version

When a publish job runs on a Node version whose bundled npm is too old, go-tokenless adds npm install -g npm@^12. It is pinned to one major on purpose: a new npm major can change how publishing behaves, and a release pipeline should not change under you. npm 12 needs Node 22.22.2+ or 24.15+; jobs pinned to an older exact Node 22 get a warning.

To use a different npm, pass --npm-version (for example --npm-version ^11.6.0). go-tokenless warns that an untested version may break the release, and refuses versions older than 11.5.1, which cannot use trusted publishing.

Troubleshooting the errors people hit

  • npm error code ENEEDAUTH: the job has no id-token: write, npm is older than 11.5.1, or the workflow file name doesn't match the trusted publisher exactly (case-sensitive, with .yml).
  • npm error 404 Not Found - PUT https://registry.npmjs.org/...: usually the same causes as ENEEDAUTH, an environment mismatch, or the package has no trusted publisher yet.
  • npm error code E422 … repository.url: package.json repository doesn't match the GitHub repo. go-tokenless apply fixes the format; a different repo is reported as an error.
  • Publishing still uses the token: something still sets NODE_AUTH_TOKEN, NPM_TOKEN, an .npmrc _authToken, or .yarnrc.yml npmAuthToken. Run npx go-tokenless again; it reports leftovers.

License

MIT

來源:README.md,提交 108300f

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.0最新Oct 6, 2026