From 8ca8c57793b1ab742afc4d77682f97005584af62 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Sebastian=20Kr=C3=BCger?= Date: Sun, 16 Aug 2026 14:16:41 +0200 Subject: [PATCH] Stop routing pnpm install through the Gitea registry actions/setup-node's registry-url sets the *default* npm registry for every install, not just publishing - since triggershell is an unscoped package name, that meant `pnpm install` tried to fetch every ordinary dependency (zod, typescript, ws, ...) from dev.pivoine.art/api/packages/valknar/npm/ instead of the public npm registry, and got hammered with 429s retrying each one. Removes registry-url from setup-node entirely (installs go back to the default public registry) and instead scopes the auth token to just that one registry host+path via `pnpm config set "//dev.pivoine.art/api/packages/valknar/npm/:_authToken" ...` right before the publish step - publishConfig.registry in package.json already tells `pnpm publish` specifically where to go (verified locally via `pnpm publish --dry-run` earlier), this only supplies the matching credential without touching install resolution. Co-Authored-By: Claude Sonnet 5 --- .gitea/workflows/release.yaml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/.gitea/workflows/release.yaml b/.gitea/workflows/release.yaml index 60bdda5..1c91973 100644 --- a/.gitea/workflows/release.yaml +++ b/.gitea/workflows/release.yaml @@ -18,7 +18,6 @@ jobs: - uses: https://github.com/actions/setup-node@v4 with: node-version: 22 - registry-url: https://dev.pivoine.art/api/packages/valknar/npm/ - run: pnpm install --frozen-lockfile @@ -31,7 +30,13 @@ jobs: - name: Set package version from the tag run: npm pkg set version="${GITHUB_REF_NAME#v}" + # Scoped to this one registry host+path (via publishConfig.registry in package.json) rather + # than actions/setup-node's registry-url, which would set it as the *default* registry for + # every install - breaking `pnpm install` for this project's own (unscoped, public) deps. + - name: Configure registry auth for publish + run: pnpm config set "//dev.pivoine.art/api/packages/valknar/npm/:_authToken" "$PACKAGE_TOKEN" + env: + PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }} + - name: Publish to Gitea npm registry run: pnpm publish --no-git-checks - env: - NODE_AUTH_TOKEN: ${{ secrets.PACKAGE_TOKEN }}