From 3bc49a0133ae7bdc2c963c090912ed84b576943a Mon Sep 17 00:00:00 2001 From: Gray Gilmore Date: Fri, 11 Sep 2026 16:12:12 -0700 Subject: [PATCH 1/3] Remove unused NPM_TOKEN from the manual VS Code release workflow vscode-release.yml only publishes to the VS Code Marketplace and Open VSX; npm publishing lives in release.yml and already runs over OIDC. Nothing in this workflow reads NPM_TOKEN, so drop it. Assisted-By: devx/d9810122-2b8f-4f8d-b51b-eb980219e4b6 --- .github/workflows/vscode-release.yml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/vscode-release.yml b/.github/workflows/vscode-release.yml index 4ed08310a..40bd44e7b 100644 --- a/.github/workflows/vscode-release.yml +++ b/.github/workflows/vscode-release.yml @@ -5,7 +5,6 @@ on: workflow_dispatch env: VSCE_PAT: ${{ secrets.VSCE_PAT }} OVSX_PAT: ${{ secrets.OPENVSX_TOKEN }} - NPM_TOKEN: ${{ secrets.NPM_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} npm_config_registry: "https://registry.npmjs.org" From c05c2be9e9e95a32e87418d0047abe04a78fecbc Mon Sep 17 00:00:00 2001 From: Gray Gilmore Date: Fri, 11 Sep 2026 16:12:13 -0700 Subject: [PATCH 2/3] Scope marketplace tokens to the steps that publish VSCE_PAT and OVSX_PAT were set at the workflow level, so every step, including pnpm install and the build, could read them. Only the vsce and ovsx publish steps need them, so move the tokens onto those steps. vsce show uses the public gallery API and does not need the PAT. Assisted-By: devx/d9810122-2b8f-4f8d-b51b-eb980219e4b6 --- .github/workflows/release.yml | 6 ++++-- .github/workflows/vscode-release.yml | 6 ++++-- 2 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 9e9832842..8df2c4b92 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -8,8 +8,6 @@ on: concurrency: ${{ github.workflow }}-${{ github.ref }} env: - VSCE_PAT: ${{ secrets.VSCE_PAT }} - OVSX_PAT: ${{ secrets.OPENVSX_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} npm_config_registry: "https://registry.npmjs.org" @@ -84,7 +82,11 @@ jobs: - name: VS Code Marketplace publish if: steps.changesets.outputs.hasChangesets == 'false' && steps.marketplace-version.outputs.version != steps.package-version.outputs.version run: pnpm publish:vsce + env: + VSCE_PAT: ${{ secrets.VSCE_PAT }} - name: Open VSX Registry publish if: steps.changesets.outputs.hasChangesets == 'false' && steps.marketplace-version.outputs.version != steps.package-version.outputs.version run: pnpm publish:ovsx + env: + OVSX_PAT: ${{ secrets.OPENVSX_TOKEN }} diff --git a/.github/workflows/vscode-release.yml b/.github/workflows/vscode-release.yml index 40bd44e7b..51fcc058f 100644 --- a/.github/workflows/vscode-release.yml +++ b/.github/workflows/vscode-release.yml @@ -3,8 +3,6 @@ name: VS Code Release Workflow in a pinch on: workflow_dispatch env: - VSCE_PAT: ${{ secrets.VSCE_PAT }} - OVSX_PAT: ${{ secrets.OPENVSX_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} npm_config_registry: "https://registry.npmjs.org" @@ -39,6 +37,10 @@ jobs: - name: VS Code Marketplace publish run: pnpm publish:vsce + env: + VSCE_PAT: ${{ secrets.VSCE_PAT }} - name: Open VSX Registry publish run: pnpm publish:ovsx + env: + OVSX_PAT: ${{ secrets.OPENVSX_TOKEN }} From 91ad85f5d5b103f10e01984ad4a33405d6736ffe Mon Sep 17 00:00:00 2001 From: freddie Date: Tue, 15 Sep 2026 19:13:59 +0100 Subject: [PATCH 3/3] Scope GitHub credentials in release workflows Assisted-By: devx/1fcb32d2-4780-44a8-8dc3-0c25314bc391 --- .github/workflows/release.yml | 5 ++++- .github/workflows/vscode-release.yml | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8df2c4b92..ac8702702 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -8,7 +8,6 @@ on: concurrency: ${{ github.workflow }}-${{ github.ref }} env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} npm_config_registry: "https://registry.npmjs.org" jobs: @@ -24,6 +23,7 @@ jobs: with: submodules: true fetch-depth: 0 + persist-credentials: false - name: Setup pnpm uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10 @@ -79,6 +79,9 @@ jobs: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} NPM_CONFIG_PROVENANCE: true + - name: Clear GitHub credentials before marketplace publish + run: rm -f "$HOME/.netrc" + - name: VS Code Marketplace publish if: steps.changesets.outputs.hasChangesets == 'false' && steps.marketplace-version.outputs.version != steps.package-version.outputs.version run: pnpm publish:vsce diff --git a/.github/workflows/vscode-release.yml b/.github/workflows/vscode-release.yml index 51fcc058f..5ae42353c 100644 --- a/.github/workflows/vscode-release.yml +++ b/.github/workflows/vscode-release.yml @@ -3,9 +3,11 @@ name: VS Code Release Workflow in a pinch on: workflow_dispatch env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} npm_config_registry: "https://registry.npmjs.org" +permissions: + contents: read + jobs: publish-packages: runs-on: ubuntu-latest @@ -14,6 +16,7 @@ jobs: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: submodules: true + persist-credentials: false - name: Setup pnpm uses: pnpm/action-setup@0977fd99725f1db4007ccb2928dbb4e90d06cc86 # v6.0.10