← Release notes

v0.2.229 Jul 2026

Trusted publishing, and the bundle the README promised

The publish workflow depended on a secret that was never set, and never attached the .mcpb the README links to.

NPM_TOKEN had never been set, so the workflow would have failed at the publish step. It now uses npm trusted publishing over OIDC — no long-lived credential stored anywhere. setup-node’s registry-url is deliberately dropped, since it writes an _authToken line that breaks OIDC.

The .mcpb is now packed and attached to the release the README already pointed people at.

Commits for this release: v0.2.1…v0.2.2