fix(release): make npm publishing work again - #71
Merged
Merged
Conversation
Newer backstage-cli refuses to prepack plugin packages without backstage.pluginId, which made the 1.5.1 release fail on npm publish. Bumps to 1.5.2 since the release workflow only runs on version changes.
mateobur
previously approved these changes
Sep 24, 2026
Drops the long-lived NPM_AUTH_TOKEN in favor of OIDC, which needs npm (not yarn) >= 11.5.1. Publishes to npm before creating the GitHub release so a failed publish no longer leaves an orphan release behind.
mateobur
approved these changes
Sep 24, 2026
Hammond95
approved these changes
Sep 24, 2026
This was referenced Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No release since 1.3.2 (2024-09) has reached npm. The 1.4.1, 1.5.0 and 1.5.1 runs all created the GitHub release and then failed on publish, because
backstage-cli package prepackrequiresbackstage.pluginId(the check was already there in CLI 0.34.5). I generated the fields withbackstage-cli repo fix --publish, andpluginIdmatchessrc/plugin.ts.Publishing moves to npm trusted publishing (OIDC) instead of
NPM_AUTH_TOKEN, since that token hasn't worked since 2024 and long-lived npm write tokens are being phased out. This requiresnpm publishbecause the yarn docs don't cover OIDC. npm now runs before the GitHub release, so a failed publish won't leave an orphan release behind.This also refreshes
yaml,qsanddiffto patched versions, which covers Dependabot #59 and #44.Before merging: add a trusted publisher for
@sysdig/backstage-plugin-sysdigon npmjs.com (reposysdiglabs/backstage-plugin-sysdig, workflowrelease.yaml). Without it the publish fails.The version goes to 1.5.2 so the release workflow triggers.