• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

panates / rman / 36484897462
95%
main: 95%

Build:
Build:
LAST BUILD BRANCH: dev
DEFAULT BRANCH: main
Ran 28 Sep 2026 09:16PM UTC
Jobs 1
Files 89
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

28 Sep 2026 09:14PM UTC coverage: 94.128% (-0.01%) from 94.138%
36484897462

push

github

erayhanoglu
ci: probe OIDC from inside rman's spawn, and withdraw the npm upgrade

Stripping the empty auth line was the right mechanism and did not fix it: the
diagnostic confirms the npmrc is down to `registry=https://registry.npmjs.org/`
at publish time, and the failure moved from E404 to ENEEDAUTH. Both mean the
same thing - npm never attempted the OIDC exchange, once with a credential that
was not one, once with none at all. So the empty line was real (it is
actions/setup-node#1551, and stripping it is the reported workaround) and it was
not the whole story.

Two changes, both of them mine to make rather than the user's:

**The diagnostic now reads the OIDC variables from inside rman's own spawn
path.** `npm publish` here is a grandchild - `rman publish` execs it through
`BinPath.env`, which rebuilds the environment from `{ ...process.env }` - and
that is the one difference left between this workflow and every working report
of trusted publishing. Measured locally with both variables faked:

  child OIDC url: present, child OIDC token: present, child npm: 11.12.1

so rman carries them and is ruled out. The runner's own line will say the same
or it will not, and either way it is an answer rather than a guess.

It prints `present`/`ABSENT` and never a value. The first version used
`${VAR:+present}${VAR:-ABSENT}`, which reads as a tidy one-liner and prints
`present<the value>` when set - and ACTIONS_ID_TOKEN_REQUEST_TOKEN is a live
credential GitHub does not mask, since it is not a registered secret. Caught by
running the step locally with a fake token and grepping the output for it.

**`npm install -g npm@latest` is gone.** It was insurance against a runner image
moving, and it moved the runner instead: Node 24.21.0 ships npm 11.19.0, well
past the 11.5.1 Trusted Publishing needs, and the upgrade took the job to npm
12.1.0 - a major the documented recipe never contemplates, since that recipe has
no upgrade step and recommends Node 24 precisely because its bund... (continued)

2883 of 3165 branches covered (91.09%)

Branch coverage included in aggregate %.

17348 of 18328 relevant lines covered (94.65%)

195.34 hits per line

Jobs
ID Job ID Ran Files Coverage
1 36484897462.1 28 Sep 2026 09:16PM UTC 89
94.13
GitHub Action Run
Source Files on build 36484897462
  • Tree
  • List 89
  • Changed 4
  • Source Changed 0
  • Coverage Changed 4
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #36484897462
  • be0f9f16 on github
  • Prev Build on dev (#36484207267)
  • Next Build on dev (#36540284663)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc