Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 4 additions & 5 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ jobs:
with:
node-version: '22'
cache: 'pnpm'
registry-url: 'https://registry.npmjs.org'

- run: pnpm install --frozen-lockfile

Expand All @@ -46,9 +47,7 @@ jobs:
exit 1
fi

- name: Publish to GitHub Packages
run: |
pnpm config set //npm.pkg.github.com/:_authToken ${{ secrets.GITHUB_TOKEN }}
pnpm publish --no-git-checks
- name: Publish to npm
run: pnpm publish --no-git-checks --access public
env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
Comment on lines 47 to +53

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High

💻 Syntax: YAML indentation error will prevent env from applying to the publish step

env: is indented under run: instead of being a sibling key, so NODE_AUTH_TOKEN won’t be set and pnpm publish will fail with an auth error.

-       - name: Publish to npm
-         run: pnpm publish --no-git-checks --access public
-          env:
-           NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
+       - name: Publish to npm
+         run: pnpm publish --no-git-checks --access public
+         env:
+           NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
🤖 AI Fix Prompt - Copy this to your AI assistant
Fix the YAML syntax/indentation issue in .github/workflows/release.yml at line 47-53

What’s wrong and why it matters:
The Publish to npm step has `env:` indented under `run:` instead of being a sibling key at the step level. In GitHub Actions YAML, `run` is a scalar string and cannot contain nested keys. Because of this, `NODE_AUTH_TOKEN` will not be applied to the step environment, and `pnpm publish` will fail with an npm authentication error (missing/invalid token). This breaks releases.

What the fix should do:
Move `env:` so it is aligned with `run:` (same indentation level) within the “Publish to npm” step, and ensure `NODE_AUTH_TOKEN` is set from `${{ secrets.NPM_TOKEN }}`. Confirm the step remains a single list item under `steps:` and that indentation matches other steps in the job.

Reference in codebase:
Use any other step in this workflow (or other workflows under .github/workflows/) that correctly defines `env:` as a sibling of `run:` or `uses:` as the indentation reference.

Files that might be affected:
.github/workflows/release.yml
Optionally check other workflow files under .github/workflows/ for similar `env` indentation mistakes, but only change them if they are actually incorrect.

Requirements:
- Update only the indentation/structure; do not change the publish command or token name unless required for correctness
- Ensure `env:` is a sibling of `run:` for the Publish to npm step
- Validate the workflow YAML is syntactically valid after the change
- Keep `NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}` exactly under `env:` with correct indentation

2 changes: 1 addition & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@
},
"publishConfig": {
"access": "public",
"registry": "https://npm.pkg.github.com/"
"registry": "https://registry.npmjs.org/"
},
"devDependencies": {
"@eslint/js": "^9.0.0",
Expand Down
Loading