From ce15b4050088945a85b9616a11df6355a2d0eb85 Mon Sep 17 00:00:00 2001 From: Julie Muzina Date: Fri, 5 Dec 2025 09:49:42 -0500 Subject: [PATCH 1/5] move release permissions from workflow level to job level --- .github/workflows/publish-on-release.yml | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/.github/workflows/publish-on-release.yml b/.github/workflows/publish-on-release.yml index a2975fbcb..f3f855bec 100644 --- a/.github/workflows/publish-on-release.yml +++ b/.github/workflows/publish-on-release.yml @@ -4,11 +4,6 @@ on: release: types: [published] -# https://docs.npmjs.com/trusted-publishers#step-2-configure-your-cicd-workflow -permissions: - id-token: write # to enable use of OIDC for npm provenance - contents: read # to enable reading the contents of the release for publishing - jobs: build: name: Build Vanilla @@ -37,6 +32,10 @@ jobs: name: Publish to NPM needs: build runs-on: ubuntu-latest + # https://docs.npmjs.com/trusted-publishers#step-2-configure-your-cicd-workflow + permissions: + id-token: write # to enable use of OIDC for npm provenance + contents: read # to enable reading the contents of the release for publishing steps: - uses: actions/checkout@v6 - uses: actions/setup-node@v6 From 309d23d20a09c3804a7643c37167cefb85c902de Mon Sep 17 00:00:00 2001 From: Julie Muzina Date: Fri, 5 Dec 2025 09:50:04 -0500 Subject: [PATCH 2/5] use experimental version number to avoid polluting published packages --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 8bdc3453a..a45376117 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "vanilla-framework", - "version": "4.38.0", + "version": "4.38.0.experimental.1", "author": { "email": "webteam@canonical.com", "name": "Canonical Webteam" From fdf29926df3c8bfca1ea638369fee9503e809fd5 Mon Sep 17 00:00:00 2001 From: Julie Muzina Date: Fri, 5 Dec 2025 09:53:45 -0500 Subject: [PATCH 3/5] Downgrade version from 4.38.0.experimental.1 to 4.38.0.experimental.0 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index a45376117..54de673d2 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "vanilla-framework", - "version": "4.38.0.experimental.1", + "version": "4.38.0.experimental.0", "author": { "email": "webteam@canonical.com", "name": "Canonical Webteam" From 8f349af387666f044493ae7dff83c3e3fae182e4 Mon Sep 17 00:00:00 2001 From: Julie Muzina Date: Fri, 5 Dec 2025 10:02:15 -0500 Subject: [PATCH 4/5] Revert "Downgrade version from 4.38.0.experimental.1 to 4.38.0.experimental.0" This reverts commit fdf29926df3c8bfca1ea638369fee9503e809fd5. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 54de673d2..a45376117 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "vanilla-framework", - "version": "4.38.0.experimental.0", + "version": "4.38.0.experimental.1", "author": { "email": "webteam@canonical.com", "name": "Canonical Webteam" From 911299f4c9824c59f182a69ca22280d01a072eef Mon Sep 17 00:00:00 2001 From: Julie Muzina Date: Fri, 5 Dec 2025 10:02:21 -0500 Subject: [PATCH 5/5] Revert "use experimental version number to avoid polluting published packages" This reverts commit 309d23d20a09c3804a7643c37167cefb85c902de. --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index a45376117..8bdc3453a 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "vanilla-framework", - "version": "4.38.0.experimental.1", + "version": "4.38.0", "author": { "email": "webteam@canonical.com", "name": "Canonical Webteam"