# Takumi Guard: npm and PyPI GitHub Actions Updated

We have updated the Takumi Guard GitHub Actions [flatt-security/setup-takumi-guard-npm](https://github.com/flatt-security/setup-takumi-guard-npm) and [flatt-security/setup-takumi-guard-pypi](https://github.com/flatt-security/setup-takumi-guard-pypi).

These changes are already available as [v1.4.0](https://github.com/flatt-security/setup-takumi-guard-npm/releases/tag/v1.4.0) of the npm action and [v1.3.0](https://github.com/flatt-security/setup-takumi-guard-pypi/releases/tag/v1.3.0) of the PyPI action. On <strong><u>Tuesday, October 13, 2026</u></strong>, we will move the `v1` tags to these versions.

This note describes the changes and what you may need to check or change.

## Affected Workflows {#scope}

This update covers the following two actions.

- [flatt-security/setup-takumi-guard-npm](https://github.com/flatt-security/setup-takumi-guard-npm)
- [flatt-security/setup-takumi-guard-pypi](https://github.com/flatt-security/setup-takumi-guard-pypi)

The update affects **workflows that reference the actions with the `@v1` tag**.

Workflows pinned to a commit SHA or a version (such as `@v1.2.0`) are not affected. However, earlier versions may run installs without going through Takumi Guard, or treat them as anonymous installs not linked to the bot, so we recommend updating the pinned version to the latest release.

## npm Action (v1.4.0) {#npm}

Until now, the npm action wrote the registry and token to the `.npmrc` at the root of your checkout, so an install in a subdirectory or with `working-directory` could ignore that file and fetch packages without going through Takumi Guard.

The updated action writes the configuration to an `.npmrc` for the job outside your checkout, and passes its location to later steps in the job through an environment variable. Installs in any directory now go through Takumi Guard, and no file in your checkout is modified.

With this change, if you use npm, pnpm or Yarn Classic, you may need to make the following changes.

- Workflows whose Dockerfile runs `COPY .npmrc`
  - Pass the file as a build secret with `docker build --secret id=npmrc,src="$NPM_CONFIG_USERCONFIG"`, and use it in the Dockerfile as in `RUN --mount=type=secret,id=npmrc,target=/root/.npmrc npm ci`.
- Workflows whose repository `.npmrc` contains a `//npm.flatt.tech/:_authToken=` line
  - That line takes precedence over the bot's token. Remove it from the repository.

For details, see the release notes for [v1.3.0](https://github.com/flatt-security/setup-takumi-guard-npm/releases/tag/v1.3.0) and [v1.4.0](https://github.com/flatt-security/setup-takumi-guard-npm/releases/tag/v1.4.0).

## PyPI Action (v1.3.0) {#pypi}

Until now, the PyPI action set the token only in the `PIP_INDEX_URL` and `UV_INDEX_URL` environment variables. Poetry does not read them, so Poetry installs were not linked to the bot even with `bot-id` set.

Also, even with `set-index-url: false`, a successful authentication overwrote these variables with the Takumi Guard URL, which took precedence over your own index configuration.

The updated action writes the token to a `.netrc` for the job, and passes its location to later steps in the job through the `NETRC` environment variable. It also passes the token to uv indexes in your project configuration that point to Takumi Guard.

With this change, you may need to make the following changes.

- Workflows that use pip or uv, set `set-index-url: false`, and relied on the action to set the index
  - Set the index to `https://pypi.flatt.tech/simple/` in your configuration.
- Workflows that use uv and run the action before `actions/checkout`
  - Run the action after `actions/checkout`.

For details, see the release notes for [v1.2.0](https://github.com/flatt-security/setup-takumi-guard-pypi/releases/tag/v1.2.0) and [v1.3.0](https://github.com/flatt-security/setup-takumi-guard-pypi/releases/tag/v1.3.0).

## Changes Common to the npm and PyPI Actions {#common}

With `bot-id` set, **the step now fails when the bot fails to authenticate**.

Today, with the default `set-registry` (npm) or `set-index-url` (PyPI), on an authentication failure the actions print an error annotation and continue in anonymous mode, so the job succeeds but installs are not linked to the bot and are not covered by download tracking or [breach notifications](/docs/t/guard/features/breach-notifications).

The RubyGems, Go and Packagist actions already fail the step on an authentication failure, and this update aligns the npm and PyPI actions with them. Anonymous mode, with `bot-id` omitted, is unchanged.

If authentication fails in your workflow today, the job succeeds in anonymous mode, but an error appears in the Annotations of the run. From October 13, the step will fail, so please check the error and fix its cause.
