GitHub 29 's npm registry 2,036 lives at https://npm.pkg.github.com 29 and accepts only scoped names whose scope is the owning account, all lowercase. BookNest's new packages/catalog exports the six seed books, so another project can reuse the data without the API. Its package.json names it @binarybehemoth/booknest-catalog, lists index.js and seed.json in files, links it to BookNest through repository (with directory: packages/catalog), and sets publishConfig.registry to GitHub's registry, so a stray npm publish cannot reach npmjs.com. Outside Actions the registry accepts only a classic personal access token; inside Actions, GITHUB_TOKEN with packages: write publishes to the workflow's own repository. The dispatch-only workflow grants exactly that (contents: read, packages: write) and runs one job:
jobs:
publish:
runs-on: ubuntu-24.04
env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
registry-url: https://npm.pkg.github.com
scope: "@binarybehemoth"
- name: Publish
working-directory: packages/catalog
run: cp ../../db/seed.json . && npm publish
- name: Install it the way a consumer would
run: |
mkdir "$RUNNER_TEMP/consumer" && cd "$RUNNER_TEMP/consumer"
npm install --no-audit --no-fund @binarybehemoth/booknest-catalog
node -p "require('@binarybehemoth/booknest-catalog').map((b) => b.title).join(', ')"registry-url and scope make setup-node write an .npmrc that sends @binarybehemoth packages to GitHub and reads the token from NODE_AUTH_TOKEN. Run 36148588724 published and then installed the package:
npm notice 📦 @binarybehemoth/booknest-catalog@1.0.0 ... npm notice Publishing to https://npm.pkg.github.com/ with tag latest and default access + @binarybehemoth/booknest-catalog@1.0.0 added 1 package in 579ms The Quiet Harbor, Patterns of the Deep Web, Salt and Saffron, Small Steps to Big Summits, ...
A version can be published only once: dispatching again failed with npm error You cannot publish over the previously published versions: 1.0.0., so release workflows bump version (or derive it from a tag) first.