Skip to content

ci: publish v3 with npm trusted publishing - #2270

Merged
TrySound merged 1 commit into
v3.xfrom
fix/v3-npm-publish
Aug 24, 2026
Merged

TrySound merged 1 commit into
v3.xfrom
fix/v3-npm-publish

Conversation

@TrySound

Copy link
Copy Markdown
Member

Summary

  • switch the v3 publish workflow from Yarn's publisher to npm 11.5.1 so npm trusted publishing can use GitHub OIDC
  • build the package with Yarn before invoking npm with lifecycle scripts disabled
  • always publish this release line under the v3 dist-tag
  • use Node.js 24 for publishing

This fixes the authentication failure observed while publishing v3.3.5 (YN0033: No authentication configured for request).

@TrySound
TrySound merged commit 4c84fe7 into v3.x Aug 24, 2026
@TrySound
TrySound deleted the fix/v3-npm-publish branch August 24, 2026 10:54
@SethFalco

SethFalco commented Aug 24, 2026 •

Copy link
Copy Markdown
Member

Thank you for fixing that! I had some trouble with it before as well back with Yarn Berry, I thought it was simply because our Yarn version was too old, so I was hoping migrating to pnpm would've solved it. :/

On the side, I've noticed you've backported to v3, but not to v2. I know it was a bit overkill of me anyway to have backported anything to v2 anyway. 😅

Do you have thoughts on that?

Shall we consider SVGO v2 completely dead and deprecated, or shall we continue to backport the security fixes?

If you think we shouldn't give it security fixes either, I vote we deprecate v2 in npm too, similarly to what we (well, someone in the org!) already did for SVGO v1.

If we do deprecate it, the message could include a link to the SVGO v2 to v3 Migration Guide.

@TrySound

Copy link
Copy Markdown
Member Author

Already running an agent to backport to v2 as well though yeah we may deprecate it later. Maybe once v5 is ready.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants