Repository navigation
Commit d51ce8e
chore(release): authenticate both registries before packing
A stale credential used to surface at the very end of a publish. The last
release spent several minutes on tests, the engine-asset probe and the pack
before `npm publish` failed on an expired session, and `mcp-publisher` failed
after that - so every one of those steps had to be repeated.
Both logins now run first. Each has to succeed for the publish to happen
anyway, so checking them up front costs nothing and turns a late failure into
an immediate one.
Gated on --publish. Packing needs no credentials, and this script also runs as
a plain build step and inside the validation gate, where prompting for a login
would hang it. npm is only prompted for when `npm whoami` already fails, so an
existing session is left alone; it stays interactive because the account has
2FA.
The mcp-publisher login uses `gh auth token` because the MCP Registry decides
which namespaces a token may publish to by calling GET /user/memberships/orgs,
which needs the read:org scope. Its own device flow mints a token without that
scope, GitHub answers 403, and the registry treats the 403 as "no admin orgs"
rather than an error - so publishing silently degrades to io.github.<user>/*
and then fails on io.github.codegraph-ai/* with a message blaming organization
membership, which is not the cause. That cost a release cycle to diagnose, so
the reasoning is recorded next to the call. CODEGRAPH_MCP_TOKEN overrides it
for anyone preferring a PAT scoped to read:org alone, since gh's token also
carries repo and workflow.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017rVbt7rENTwXkdHt3Bpgb51 parent 489ccf1 commit d51ce8e
1 file changed
Lines changed: 58 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
34 | 92 | | |
35 | 93 | | |
36 | 94 | | |
| |||
0 commit comments