From b18090c1df06186b3952f70c20182a4eb0ed23e6 Mon Sep 17 00:00:00 2001 From: david ruiz Date: Tue, 29 Sep 2026 17:44:50 +0200 Subject: [PATCH 1/3] Release 5.5.0 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 04c6fb6..c001110 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "checkout-sdk-node", - "version": "5.4.0", + "version": "5.5.0", "description": "Official Node.js SDK for Checkout.com payment gateway - Full API coverage with TypeScript support", "type": "module", "engines": { From f14246453e6ccedd26cc65e0b394e689f4b7d518 Mon Sep 17 00:00:00 2001 From: david ruiz Date: Mon, 5 Oct 2026 10:54:57 +0200 Subject: [PATCH 2/3] Release 5.5.0 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index c001110..e06c13e 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "checkout-sdk-node", "version": "5.5.0", - "description": "Official Node.js SDK for Checkout.com payment gateway - Full API coverage with TypeScript support", + "description": "Official Node.js SDK for Checkout.com payment gateway - SDK with full API coverage with TypeScript support", "type": "module", "engines": { "node": ">=18" From 1f4cc5a09c6ffedf6eb6d9eb024712d277bcb065 Mon Sep 17 00:00:00 2001 From: Jason Lafferty <102971289+jason-lafferty-cko@users.noreply.github.com> Date: Mon, 5 Oct 2026 09:49:17 +0100 Subject: [PATCH 3/3] ci: publish to npm via trusted publishing (OIDC) (#466) * ci: publish to npm via trusted publishing (OIDC) The release job authenticated with a long-lived NODE_AUTH_TOKEN secret, which npm no longer accepts; the 5.5.0 release failed with a 404 on PUT. The package already has a trusted publisher configured for checkout/checkout-sdk-node, build-release.yml, environment production. - bind the job to the production environment and grant id-token: write - drop NODE_AUTH_TOKEN and publish with --provenance - move to actions/checkout@v4 and setup-node@v4 on Node 22 (v2/v3 run on deprecated Node 20) and upgrade npm to >= 11.5.1 * ci: pin npm to 11.21.0 and install it with --ignore-scripts --- .github/workflows/build-release.yml | 21 +++++++++++++++------ 1 file changed, 15 insertions(+), 6 deletions(-) diff --git a/.github/workflows/build-release.yml b/.github/workflows/build-release.yml index 91d705f..94d2dc4 100644 --- a/.github/workflows/build-release.yml +++ b/.github/workflows/build-release.yml @@ -10,13 +10,22 @@ on: jobs: deploy: runs-on: ubuntu-latest + # Must match the environment configured on the npm trusted publisher + environment: production + permissions: + contents: write # create the GitHub release + id-token: write # npm trusted publishing (OIDC) steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v4 - id: setup-node - uses: actions/setup-node@v2.5.1 + uses: actions/setup-node@v4 with: - node-version: 18 + node-version: 22 registry-url: https://registry.npmjs.org/ + - id: upgrade-npm + # Trusted publishing needs npm >= 11.5.1; Node 22 bundles npm 10. + # Pinned so the release job is reproducible. + run: npm install -g npm@11.21.0 --ignore-scripts && npm --version - id: build-and-analyse env: CHECKOUT_PROCESSING_CHANNEL_ID: ${{ secrets.IT_CHECKOUT_PROCESSING_CHANNEL_ID }} @@ -43,9 +52,9 @@ jobs: - id: print-version run: echo "Releasing $CURRENT_VERSION" - id: publish-to-npm - env: - NODE_AUTH_TOKEN: ${{secrets.NODE_AUTH_TOKEN}} - run: npm publish + # No token: npm exchanges the GitHub OIDC token with the registry + # and publishes with provenance. + run: npm publish --provenance --access public - id: create-release uses: actions/create-release@v1 env: