Update release.yml to remove NPM_TOKEN - #451
HarshTyagi8010 wants to merge 1 commit into
Conversation
Removed NPM_TOKEN from semantic-release environment.
|
Fix npm tokens |
clark-cant
left a comment
There was a problem hiding this comment.
Metadata-First Review Summary
PR: #451 — Update release.yml to remove NPM_TOKEN
Author: @HarshTyagi8010
Size: +0/-2 (1 file)
mergeStateStatus: CLEAN
mergeable: MERGEABLE
reviewDecision: (none yet)
Change Analysis
This PR removes two lines from .github/workflows/release.yml:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}env var-p @semantic-release/npmplugin
This effectively disables npm publishing from the semantic-release workflow.
Context
Related to #215 where @luantaraschi documented that uipro-cli on npm is stale (last published 2026-01-29) while development moved to ui-ux-pro-max-cli. This change may be intentional cleanup, but it's a significant CI/CD decision that needs maintainer confirmation.
Decision: Needs Maintainer Approval
- Cannot merge without explicit maintainer sign-off
- The change is valid but has downstream implications for release workflow
- @zuey or maintainers: please confirm if npm publishing should be fully removed
Posted by github-maintain cron
clark-cant
left a comment
There was a problem hiding this comment.
Request changes\n\nRemoving @semantic-release/npm disables the repository’s configured npm publish step: .releaserc.json still declares that plugin with pkgRoot: cli, and the release workflow is the place that installs/runs the semantic-release plugins. Removing NPM_TOKEN is only valid if this PR also changes the release strategy/config to intentionally stop npm publishing and documents the replacement.\n\nPlease either retain @semantic-release/npm and its required token, or include a complete, tested migration to another publishing mechanism.\n\nMandatory gates: duplicate/prior work checked (release PRs #375/#384/#393); project standards checked (CLAUDE.md); strategic necessity is not justified because the change breaks the npm release path.\n\nPosted by github-maintain cron
clark-cant
left a comment
There was a problem hiding this comment.
Review of PR #451 — Update release.yml to remove NPM_TOKEN
Summary: Removes NPM_TOKEN env var and -p @semantic-release/npm flag from release.yml.
Risk level: Medium
Verdict: Request changes
Findings
Critical:
- Does not fix the reported outage (#457).
.releaserc.jsonstill declares@semantic-release/npmas a plugin withpkgRoot: cli. Since@semantic-release/npmis a direct dependency ofsemantic-release,npx semantic-releasestill installs and loads it regardless of whether the-pflag is passed. With no trusted publisher configured on npm and the NPM_TOKEN expired, the release will still fail.
Important:
2. Branch is stale. mergeStateStatus is BLOCKED and head branch patch-2 has not been updated since 2026-08-20.
3. No linked issue. The PR description does not reference #457 or explain how removing the -p flag resolves the publishing failure while .releaserc.json still configures the npm plugin.
Suggestion:
4. PR description retains default template placeholders without filling them in.
Correct fix path
Either (a) rotate the NPM_TOKEN secret with a valid granular access token, or (b) configure npm trusted publishing for this repository/workflow and then remove both the secret and the npm plugin config from .releaserc.json.
Posted by github-maintain cron at 2026-09-15T08:30:00Z
Removed NPM_TOKEN from semantic-release environment.
What does this PR change?
Why?
Checklist
src/ui-ux-pro-max/(source of truth), not directly in.claude/or.factory/npm run sync:assets && npm run check:assetsincli/if data/scripts/templates changed.claude/skills/*/scripts/tests/,cli/tests/e2e/)feat:,fix:,docs:, etc.)main