Skip to content

ci: publish to npm from a GitHub workflow - #10

Merged
agoldis merged 3 commits into
masterfrom
agoldis/publish-workflow
Sep 23, 2026
Merged

agoldis merged 3 commits into
masterfrom
agoldis/publish-workflow

Conversation

@agoldis

@agoldis agoldis commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Adds a "Publish NPM Package" workflow so @currents/commit-info is published from GitHub, like @currents/cmd and @currents/playwright. Today it is published by hand with npm publish.

  • Manual workflow_dispatch with an npm tag: alpha, beta or latest. alpha and beta need a matching -alpha.N / -beta.N version, and latest rejects any prerelease.
  • Two jobs. test checks the version, installs dependencies and runs the unit tests, with read-only permissions. publish runs after it and is the only job with id-token: write. It runs checkout, setup-node and npm publish --ignore-scripts, and no dependency code, since the package has no build step.
  • Authenticates with npm trusted publishing (OIDC), so no npm token is stored in the repo.

workflow_dispatch only works for a workflow on the default branch, so this needs to merge before #9 can publish its beta.

Before the first run, @currents/commit-info needs a trusted publisher on npmjs.com (package settings → Trusted Publisher → GitHub Actions): organization currents-dev, repository commit-info, workflow publish.yaml.

Not run yet: it can only run after merge.

Refs ENG-934

🤖 Generated with Claude Code

https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR

Summary by CodeRabbit

  • Chores
    • Package releases can now be published through a manually triggered release process, with alpha, beta, or latest channels available.
    • Release versions are checked against the selected channel, and unit tests run before publication. mismatches prevent the release from proceeding.

Same flow as @currents/cmd and @currents/playwright: a manual
workflow_dispatch picks the npm tag, and npm trusted publishing (OIDC)
authenticates, so no npm token is stored. alpha and beta need a matching
version suffix. The unit tests run before publishing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 31bdfd89-6cac-401c-b3be-468288c5e0f4

📥 Commits

Reviewing files that changed from the base of the PR and between 80ffa78 and 32984cc.

📒 Files selected for processing (1)
  • .github/workflows/publish.yaml
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@agoldis

agoldis commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor Author

@baz review

@baz-reviewer

baz-reviewer Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review this PR on Baz

Baz Summary

Add a manually triggered GitHub Actions workflow to validate, test, and publish @currents/commit-info to npm. Use channel-specific version checks and npm trusted publishing via OIDC, with test and publish jobs isolating release permissions.

Topics

TopicDetails
Release validation Add a manual release flow supporting alpha, beta, and latest, validating package versions and running unit tests before publication.
Modified files (1)
  • .github/workflows/publish.yaml
Latest Contributors(1)
UserCommitDate
agoldis@gmail.comci: match the whole ve...September 23, 2026
Trusted npm publish Publish the package through npm trusted publishing with OIDC, restricting id-token: write permission to the dependent publish job.
Modified files (1)
  • .github/workflows/publish.yaml
Latest Contributors(1)
UserCommitDate
agoldis@gmail.comci: match the whole ve...September 23, 2026

Merger  Activate to get a short verdict whether this PR is good to go or not

Skills  Activate Skill Maintainer to keep your skills up to date

Planner  This PR would have been improved with Baz Planner - Try it now

Comment thread .github/workflows/publish.yaml
Comment thread .github/workflows/publish.yaml Outdated
Comment thread .github/workflows/publish.yaml Outdated
Only the publish job gets id-token: write, and it runs checkout, setup-node
and npm publish with scripts off. Installing dependencies and the unit
tests move to a test job without it, so a dev dependency cannot request
the OIDC token npm trusted publishing accepts.

The version check compares the first prerelease identifier exactly: beta
needs 1.1.0-beta.N, 1.0.0-betafoo no longer passes, and latest rejects any
prerelease.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
Comment thread .github/workflows/publish.yaml Outdated
latest takes only X.Y.Z, and alpha or beta only X.Y.Z-alpha.N or
X.Y.Z-beta.N, so 1.1.0-beta and 1.1.0-beta.foo no longer pass.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
@agoldis
agoldis merged commit 6d428d6 into master Sep 23, 2026
5 checks passed
@agoldis
agoldis deleted the agoldis/publish-workflow branch September 23, 2026 23:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant