
go-tokenless
io.github.Continuous-Actionsv0.1.0更新於 Oct 6, 2026
Move npm publishing in GitHub Actions from NPM_TOKEN to trusted publishing (OIDC).
概覽
讓助理規劃並套用把 GitHub Actions 的 npm 發佈從 NPM_TOKEN 改為 npm 信任發佈(OIDC)的變更。
- 功能
- 提供兩個工具:plan_trusted_publishing 為唯讀,會報告即將發生的變更;apply_trusted_publishing 會把變更寫入工作流程與 package.json 檔案。它會從發佈步驟移除 NODE_AUTH_TOKEN 與 NPM_TOKEN、授予 id-token: write、加入 registry-url、更新被固定版本的發佈 action,並修正 repository 欄位。它也會印出 npm trust github 指令與剩下的手動步驟,在信任發佈無法運作時直接拒絕,而不是自行猜測。
- 適用情境
- 適用於從 GitHub Actions 發佈 npm 套件的儲存庫,想以 OIDC 信任發佈取代長期有效的 npm 權杖,包括 changesets、semantic-release、release-please、Lerna、Nx、pnpm、Yarn Berry 與 release-it 等發佈方式。
- 執行需求
- 以 npx 在本機執行的程序(npm 套件 go-tokenless),需要 Node 22.14+。未宣告任何帳號、API 金鑰、環境變數或標頭。它會讀取本機儲存庫的工作流程與 package.json;可用 --offline 略過 npm registry 查詢。
安裝
在 SourceWeft 中
- 開啟 儀表板中的 go-tokenless,將其新增到工作區。
- 為需要使用其工具的對話啟用該服務。
Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。
其他 MCP 客戶端
參照 儲存庫 中的啟動說明。
README
go-tokenless
Delete your NPM_TOKEN. One command switches your GitHub Actions release workflow to npm trusted publishing (OIDC), so no long-lived npm token has to be stored anywhere.
npm is retiring direct publishing with tokens: from January 2027 a granular token with "bypass 2FA" can no longer publish on its own (npm docs). Trusted publishing is the replacement for CI. It also adds a provenance badge to every release.
What it does
It reads your workflows and package.json files, then:
It also prints the exact npm trust github … command for every package and the remaining manual steps.
It refuses (exit code 1) rather than guessing when trusted publishing can't work: self-hosted runners, or a repository field pointing at another repo. It leaves jobs that publish to GitHub Packages alone.
Example
The default command also prints a unified diff. Your file's comments, quoting and layout are kept: only the lines that need to change are touched.
Supported release setups
Version floors are checked against your package.json where possible.
Things only you can do
The tool never touches your npm account. After applying:
- Add a trusted publisher for each package: the printed
npm trust github …commands (npm 11.15+, needs your 2FA), or npmjs.com → package → Settings → Trusted publishing. - Brand-new packages must be published once by hand first; npm can only attach a trusted publisher to a package that exists. The plan flags these.
- Delete the secret and revoke the token once a release has gone out.
Use it from an AI coding agent
Agents can run the CLI with --json (stable shape, status field, exit codes), or use the MCP server:
Tools: plan_trusted_publishing (read-only) and apply_trusted_publishing (writes files, no git or network writes). There is also an Agent Skill:
Or install the skill and MCP server together as a plugin:
Just ask: "Move our npm publishing to trusted publishing."
Options
Exit codes: 0 ok, 1 blocked (errors to fix by hand), 2 usage error, 3 unexpected error. Needs Node 22.14+.
npm version
When a publish job runs on a Node version whose bundled npm is too old, go-tokenless adds npm install -g npm@^12. It is pinned to one major on purpose: a new npm major can change how publishing behaves, and a release pipeline should not change under you. npm 12 needs Node 22.22.2+ or 24.15+; jobs pinned to an older exact Node 22 get a warning.
To use a different npm, pass --npm-version (for example --npm-version ^11.6.0). go-tokenless warns that an untested version may break the release, and refuses versions older than 11.5.1, which cannot use trusted publishing.
Troubleshooting the errors people hit
npm error code ENEEDAUTH: the job has noid-token: write, npm is older than 11.5.1, or the workflow file name doesn't match the trusted publisher exactly (case-sensitive, with.yml).npm error 404 Not Found - PUT https://registry.npmjs.org/...: usually the same causes as ENEEDAUTH, anenvironmentmismatch, or the package has no trusted publisher yet.npm error code E422…repository.url:package.jsonrepositorydoesn't match the GitHub repo.go-tokenless applyfixes the format; a different repo is reported as an error.- Publishing still uses the token: something still sets
NODE_AUTH_TOKEN,NPM_TOKEN, an.npmrc_authToken, or.yarnrc.ymlnpmAuthToken. Runnpx go-tokenlessagain; it reports leftovers.
License
MIT
來源:README.md,提交 108300f
工具
0版本歷史
1- v0.1.0最新Oct 6, 2026


