Repository navigation
project's .npmrc not respected #58
Description
Activity
- added a commit that references this issue
on Oct 28, 2020 I don't think this.npmrcis even being used by changesets.I found that using
action/node-setupand theregistry-urlyou need to setNODE_AUTH_TOKENI had to replace my
env.NPM_TOKENwithenv.NODE_AUTH_TOKENbecause I'm usingactions/node-setupand changesets is working fine without theNPM_TOKEN.Update Explanation:
actions/setup-nodecreates an auth file when the registry-url exists and usesNODE_AUTH_TOKENthen puts that path in theNPM_CONFIG_USERCONFIGenvironment variable. I believe this now overrides the use of the .npmrc file and why it's not used.I wonder if
changesets/actionshould maybe check forNPM_CONFIG_USERCONFIGexisting before it writes out the.npmrcfile and/or log out an explanation.Maybe someone can explain if this is true or clear up any misunderstanding.
Reacted by vxna, Juan Picado, Tommy Chen, Justin Leatherwood and Kyle Moore- added a commit that references this issue
on Nov 23, 2020 - added 2 commits that reference this issue
on Apr 13, 2021 For a CI action to be hard-coded to only check
$HOME/.npmrcis pretty bad imo. At least self-hosted runners are often stateful, and potentially concurrent, so adding files to a shared directory should be avoided. Especially since the action doesn't clean up after itself.As a workaround I opted to change the
$HOMEvariable during the run. Not ideal, but it appears to work just fine.If someone knows how to set $HOME using jobs.steps.env, then that would be even better.# changesets/action presumes the .npmrc is in $HOME # See: # - https://github.com/changesets/action/issues/58 # - https://github.com/changesets/action/blob/2bb9bcbd6bf4996a55ce459a630a0aa699457f59/src/index.ts#L58 - name: Set HOME run: echo "HOME=$(pwd)" >> $GITHUB_ENV
Edit: use
jobs.steps.envlike this, as shown in #147env: HOME: ${{ github.workspace }}
Reacted by Yash Kadaru@nikparo agree with this. I ran into this today. It's also weird that the action forces a check to make sure the default npm registry token is configured. (full on assumes that packages are being published to the public registry alone)
Right now if you have an
.npmrcat the project root that is not respected but rather the following piece of code just checks the.npmrcin the HOME directoryaction/src/index.ts
Lines 44 to 53 in cd904b9
Even the ideal flow for npm or any process is they check for
.npmrcat the project root if not then they look for.npmrcin the HOME directory.