<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: John Smith</title>
    <description>The latest articles on DEV Community by John Smith (@john_smith_0fe98c53831097).</description>
    <link>https://dev.to/john_smith_0fe98c53831097</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3693560%2Fc5c30848-7c36-42d1-9b4a-14f746903d00.png</url>
      <title>DEV Community: John Smith</title>
      <link>https://dev.to/john_smith_0fe98c53831097</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/john_smith_0fe98c53831097"/>
    <language>en</language>
    <item>
      <title>How did I automate a VS Code Marketplace release without a PAT?</title>
      <dc:creator>John Smith</dc:creator>
      <pubDate>Wed, 07 Oct 2026 11:59:57 +0000</pubDate>
      <link>https://dev.to/john_smith_0fe98c53831097/how-did-i-automate-a-vs-code-marketplace-release-without-a-pat-17lo</link>
      <guid>https://dev.to/john_smith_0fe98c53831097/how-did-i-automate-a-vs-code-marketplace-release-without-a-pat-17lo</guid>
      <description>&lt;p&gt;&lt;strong&gt;Question:&lt;/strong&gt; How can I publish a VS Code extension from a Git tag without storing a long-lived Marketplace token, and what should I check when the build passes but publishing fails?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Answer:&lt;/strong&gt; I split the problem into packaging, federation, publisher access and Marketplace readback. Treating those as separate steps made today's 0.0.2 release straightforward to diagnose.&lt;/p&gt;

&lt;p&gt;The 0.0.2 listing update also included the new logo, official website and documentation, instructions for the required CLI, and a contact for problems. The CLI requirement matters: the editor plugin reads generated project files; it does not install the icon library by itself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 1: Prove that the extension package is good.&lt;/strong&gt; My workflow ran TypeScript compilation, 39 tests, a build, release metadata validation and &lt;code&gt;vsce package&lt;/code&gt; in a job that had no cloud credentials. It completed successfully before the publish request failed. That told me to investigate identity rather than alter the source code or rebuild the VSIX.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 2: Check the Marketplace authentication path.&lt;/strong&gt; Direct &lt;code&gt;vsce publish --oidc&lt;/code&gt; first failed because the client request did not match the current protocol. After a narrowly guarded client fix, the Marketplace still replied that trusted publishing was not supported. I switched to a GitHub Actions OIDC token exchanged through Microsoft Entra and passed the resulting Entra identity to &lt;code&gt;vsce publish --azure-credential&lt;/code&gt;. This avoids putting a client secret or PAT in the repository.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 3: Make the federation subject match the workflow.&lt;/strong&gt; My federated credential trusts &lt;code&gt;main&lt;/code&gt;, but a tag-triggered GitHub workflow has a tag subject. Rather than weakening the credential, the tag job dispatches a second workflow on &lt;code&gt;main&lt;/code&gt;. That workflow validates the stable tag, checks that it matches &lt;code&gt;package.json&lt;/code&gt;, confirms the tag commit is on &lt;code&gt;main&lt;/code&gt;, and builds from the tag.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 4: Authorize the identity in the publisher.&lt;/strong&gt; A successful Entra login only proves that GitHub can sign into the Entra application. My next check still failed with “operation not allowed.” I fetched the identity ID from the Marketplace profile API and the publisher owner added it to the &lt;code&gt;moewolf&lt;/code&gt; publisher as a Contributor. The publisher access check and actual publish then passed.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Step 5: Publish the reviewed bytes and read them back.&lt;/strong&gt; Because version 0.0.2 already had a GitHub Release asset, the workflow verified its SHA-256 and compared each file with a fresh build of the tag. It retained the original VSIX and sent that artifact to Marketplace. The publish run completed, and the public extension metadata subsequently showed version 0.0.2.&lt;/p&gt;

&lt;p&gt;The central lesson: a green build does not prove authentication, and successful login does not prove Marketplace publisher permission. Check each boundary, avoid printing credentials, and keep the package digest attached to the release.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://moeicons.com/" rel="noopener noreferrer"&gt;https://moeicons.com/&lt;/a&gt;&lt;br&gt;
&lt;a href="https://moeicons.com/search" rel="noopener noreferrer"&gt;https://moeicons.com/search&lt;/a&gt;&lt;br&gt;
&lt;a href="https://moeicons.com/docs/" rel="noopener noreferrer"&gt;https://moeicons.com/docs/&lt;/a&gt;&lt;/p&gt;

</description>
      <category>automation</category>
      <category>cli</category>
      <category>devops</category>
      <category>vscode</category>
    </item>
    <item>
      <title>If five icons turn into 312 KB gzipped, the cause is almost always packaging, not your code. Three things to check, in order: is the package resolving to CommonJS (weak static analysis, keeps everything), does the root entry re-export every icon via a barr</title>
      <dc:creator>John Smith</dc:creator>
      <pubDate>Sun, 04 Oct 2026 05:39:14 +0000</pubDate>
      <link>https://dev.to/john_smith_0fe98c53831097/if-five-icons-turn-into-312-kb-gzipped-the-cause-is-almost-always-packaging-not-your-code-three-4n29</link>
      <guid>https://dev.to/john_smith_0fe98c53831097/if-five-icons-turn-into-312-kb-gzipped-the-cause-is-almost-always-packaging-not-your-code-three-4n29</guid>
      <description></description>
      <category>javascript</category>
      <category>performance</category>
      <category>software</category>
    </item>
    <item>
      <title>I tried quite a few game strategies today, and it was a very interesting experience.</title>
      <dc:creator>John Smith</dc:creator>
      <pubDate>Fri, 16 Jan 2026 09:26:24 +0000</pubDate>
      <link>https://dev.to/john_smith_0fe98c53831097/i-tried-quite-a-few-game-strategies-today-and-it-was-a-very-interesting-experience-3pfc</link>
      <guid>https://dev.to/john_smith_0fe98c53831097/i-tried-quite-a-few-game-strategies-today-and-it-was-a-very-interesting-experience-3pfc</guid>
      <description></description>
    </item>
    <item>
      <title>Perfect for a nightcap, hello</title>
      <dc:creator>John Smith</dc:creator>
      <pubDate>Fri, 09 Jan 2026 04:26:36 +0000</pubDate>
      <link>https://dev.to/john_smith_0fe98c53831097/perfect-for-a-nightcap-hello-3f9m</link>
      <guid>https://dev.to/john_smith_0fe98c53831097/perfect-for-a-nightcap-hello-3f9m</guid>
      <description></description>
    </item>
  </channel>
</rss>
