• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

panates / rman / 36484207267
95%
main: 95%

Build:
Build:
LAST BUILD BRANCH: dev
DEFAULT BRANCH: main
Ran 28 Sep 2026 09:10PM UTC
Jobs 1
Files 89
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 09:08PM UTC coverage: 94.138% (+0.007%) from 94.131%
36484207267

push

github

erayhanoglu
fix(ci): clear the empty auth line setup-node writes, so npm reaches for OIDC

The diagnostic found it. On the runner:

  NODE_AUTH_TOKEN: unset
  /home/runner/work/_temp/.npmrc:
    //registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}
    registry=https://registry.npmjs.org/

`registry-url` makes setup-node write that pair into the file it points
NPM_CONFIG_USERCONFIG at. With no token the reference resolves to nothing, and
npm reads *having* an `_authToken` entry for the registry as being authenticated
already - so it never asks GitHub for an OIDC token, sends a credential that is
not one, and the registry answers

  404 Not Found - PUT https://registry.npmjs.org/rman

which is what npm returns instead of 403 so nobody can probe which packages
exist. Every other candidate was already ruled out by the same diagnostic: npm
12.1.0 (OIDC needs 11.5.1), the id-token request URL present, nothing shadowing
the global npm, and the package's own `repository` field naming panates/rman.

Removing the line is not a workaround - an `_authToken` with nothing behind it
cannot help any code path, and an empty field is precisely what lets npm decide
it has to authenticate some other way. `registry=` stays, which is the half of
`registry-url` that was wanted.

Stripped first and unconditionally, so a real NPM_TOKEN is never left competing
with the placeholder for the same registry.

Not `sed -i`: BSD sed reads the next word as a backup suffix, so the line is a
silent no-op on macOS and the `|| true` guarding it hides that. Measured while
checking this step - the first version of it deleted nothing here and would have
worked only on the runner. `grep -v` into a temp file is POSIX and verifiable
anywhere, which matters for a step whose whole job is to remove one line. Both
branches measured on a real npmrc: without a token only `registry=` is left;
with one, `registry=` plus a single auth line.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

2886 of 3166 branches covered (91.16%)

Branch coverage included in aggregate %.

17348 of 18328 relevant lines covered (94.65%)

195.37 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36484207267.1 28 Sep 2026 09:10PM UTC 89
94.14
GitHub Action Run
Source Files on build 36484207267
  • Tree
  • List 89
  • Changed 19
  • Source Changed 0
  • Coverage Changed 19
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36484207267
  • 0d9754b3 on github
  • Prev Build on dev (#36483573275)
  • Next Build on dev (#36484897462)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc