Skip to content

Remove unused snapit workflow - #135

Merged
pauloroberto-pozzato merged 1 commit into
mainfrom
remove-snapit-workflow-pr84704
Sep 22, 2026
Merged

pauloroberto-pozzato merged 1 commit into
mainfrom
remove-snapit-workflow-pr84704

Conversation

@pauloroberto-pozzato

Copy link
Copy Markdown
Contributor

Removes .github/workflows/snapit.yml, the last workflow in this repo that reads the long-lived secrets.NPM_TOKEN.

Addresses shop/issues#84704.

Why this is safe

  • Release publishing remains covered by npm Trusted Publishing/OIDC through .github/workflows/release.yml: it grants id-token: write and sets NPM_TOKEN: "" to force OIDC authentication.
  • The unused /snapit snapshot workflow was the only remaining long-lived npm token path in this repo.
  • Removing it eliminates the standing NPM_TOKEN exposure from this public repo.

After this change, the only remaining NPM_TOKEN reference is the intentional NPM_TOKEN: "" line in release.yml.

Note: the repository or organization secret should be deleted separately by an admin if it still exists.

@pauloroberto-pozzato
pauloroberto-pozzato merged commit b589382 into main Sep 22, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants