ci: move to node 24 and drop the npm oidc workaround

node 22 is in maintenance and ships npm 10, which is why the publish job
had to install npm@latest over it. node 24 is the active lts and bundles
npm 11.17.0, above the 11.5.1 oidc floor, so the extra step goes.
This commit is contained in:
pj committed 2026-08-16 17:16:58 +05:30
1 parent de4d0a8fe0
commit fe0c4ee2f7
1 file changed
+10 -11
+10 -11
View File
@@ -51,10 +51,10 @@ jobs:
- name: Set up Android SDK
uses: android-actions/setup-android@40fd30fb8d7440372e1316f5d1809ec01dcd3699 # v4.0.1
- name: Set up Node 22
- name: Set up Node 24
uses: actions/setup-node@v7
with:
node-version: "22"
node-version: "24"
cache: npm
cache-dependency-path: pkg/spec/package-lock.json
@@ -521,21 +521,20 @@ jobs:
# this job needs the git credential afterwards.
persist-credentials: false
- name: Set up Node 22
# registry-url below writes an `_authToken=${NODE_AUTH_TOKEN}` line into
# .npmrc whether or not a token exists, and an npm older than 11.5.1 reads
# that empty line as "auth is configured" and never asks for an OIDC
# token, so the publish fails needing auth. 24 is the oldest Node whose
# bundled npm clears that floor (11.17.0), which is why it is pinned here
# rather than upgrading npm over the top of an older one.
- name: Set up Node 24
uses: actions/setup-node@v7
with:
node-version: "22"
node-version: "24"
registry-url: "https://registry.npmjs.org"
cache: npm
cache-dependency-path: pkg/spec/package-lock.json
# registry-url above writes an `_authToken=${NODE_AUTH_TOKEN}` line into
# .npmrc whether or not a token exists, and an npm older than 11.5.1 reads
# that empty line as "auth is configured" and never asks for an OIDC
# token, so the publish fails needing auth. Node 22 ships npm 10.
- name: Install an npm that can publish over OIDC
run: npm install -g npm@latest
- name: Install dependencies
working-directory: pkg/spec
run: npm ci