STAT-133: Add NPM_TOKEN support to node and test/npm actions for private registry auth

npm ci fails with E401 when a consuming repo's package-lock.json pins a
package to the private Gitea npm registry, since these composite actions
never write an .npmrc or set a registry auth token. Add an optional
NPM_TOKEN input that writes .npmrc before install; existing consumers that
don't pass it are unaffected.
This commit is contained in:
2026-09-17 11:48:24 -04:00
parent 3f7c00f1e7
commit 9df18983c3
4 changed files with 37 additions and 0 deletions
+10
View File
@@ -10,6 +10,7 @@ Composite action: install dependencies and run an npm test script.
| `TEST_SCRIPT` | npm script to run (must exist in `package.json`) | `test` |
| `TEST_ARGS` | Additional arguments passed after `--` to the test script | `` |
| `WORKING_DIRECTORY` | Directory to run commands in | `.` |
| `NPM_TOKEN` | Auth token for the private Gitea npm registry (`@stat-tackler` scope). Leave empty if the repo installs no private packages. | `` |
## Usage
@@ -19,6 +20,15 @@ Composite action: install dependencies and run an npm test script.
TEST_SCRIPT: test:unit
```
With a private `@stat-tackler` package in `package.json`:
```yaml
- uses: stat-tackler/stat-tackler-infra/test/npm@main
with:
TEST_SCRIPT: test:unit
NPM_TOKEN: ${{ secrets.REGISTRY_READ_WRITE_AGENT }}
```
With extra args:
```yaml