npm on GitHub Packages

Publishing an npm Package to GitHub Packages

GitHub 29 's npm registry 2,036 lives at https://npm.pkg.github.com 29 and accepts only scoped names whose scope is the owning account, all lowercase. BookNest's new packages/catalog exports the six seed books, so another project can reuse the data without the API. Its package.json names it @binarybehemoth/booknest-catalog, lists index.js and seed.json in files, links it to BookNest through repository (with directory: packages/catalog), and sets publishConfig.registry to GitHub's registry, so a stray npm publish cannot reach npmjs.com. Outside Actions the registry accepts only a classic personal access token; inside Actions, GITHUB_TOKEN with packages: write publishes to the workflow's own repository. The dispatch-only workflow grants exactly that (contents: read, packages: write) and runs one job:

.github/workflows/publish-npm.yml (the job)YAML
jobs:
  publish:
    runs-on: ubuntu-24.04
    env:
      NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
    steps:
      - uses: actions/checkout@v7
      - uses: actions/setup-node@v7
        with:
          node-version-file: .nvmrc
          registry-url: https://npm.pkg.github.com
          scope: "@binarybehemoth"
      - name: Publish
        working-directory: packages/catalog
        run: cp ../../db/seed.json . && npm publish
      - name: Install it the way a consumer would
        run: |
          mkdir "$RUNNER_TEMP/consumer" && cd "$RUNNER_TEMP/consumer"
          npm install --no-audit --no-fund @binarybehemoth/booknest-catalog
          node -p "require('@binarybehemoth/booknest-catalog').map((b) => b.title).join(', ')"

registry-url and scope make setup-node write an .npmrc that sends @binarybehemoth packages to GitHub and reads the token from NODE_AUTH_TOKEN. Run 36148588724 published and then installed the package:

Output of 100
npm notice 📦  @binarybehemoth/booknest-catalog@1.0.0
...
npm notice Publishing to https://npm.pkg.github.com/ with tag latest and default access
+ @binarybehemoth/booknest-catalog@1.0.0
added 1 package in 579ms
The Quiet Harbor, Patterns of the Deep Web, Salt and Saffron, Small Steps to Big Summits, ...

A version can be published only once: dispatching again failed with npm error You cannot publish over the previously published versions: 1.0.0., so release workflows bump version (or derive it from a tag) first.