ci: publish to npm from a GitHub workflow - #10
Conversation
Same flow as @currents/cmd and @currents/playwright: a manual workflow_dispatch picks the npm tag, and npm trusted publishing (OIDC) authenticates, so no npm token is stored. alpha and beta need a matching version suffix. The unit tests run before publishing. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@baz review |
|
| Topic | Details | ||||||
|---|---|---|---|---|---|---|---|
| Release validation | Add a manual release flow supporting alpha, beta, and latest, validating package versions and running unit tests before publication.Modified files (1)
Latest Contributors(1)
| ||||||
| Trusted npm publish | Publish the package through npm trusted publishing with OIDC, restricting id-token: write permission to the dependent publish job.Modified files (1)
Latest Contributors(1)
|
Only the publish job gets id-token: write, and it runs checkout, setup-node and npm publish with scripts off. Installing dependencies and the unit tests move to a test job without it, so a dev dependency cannot request the OIDC token npm trusted publishing accepts. The version check compares the first prerelease identifier exactly: beta needs 1.1.0-beta.N, 1.0.0-betafoo no longer passes, and latest rejects any prerelease. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
latest takes only X.Y.Z, and alpha or beta only X.Y.Z-alpha.N or X.Y.Z-beta.N, so 1.1.0-beta and 1.1.0-beta.foo no longer pass. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
Adds a "Publish NPM Package" workflow so
@currents/commit-infois published from GitHub, like@currents/cmdand@currents/playwright. Today it is published by hand withnpm publish.workflow_dispatchwith an npm tag:alpha,betaorlatest.alphaandbetaneed a matching-alpha.N/-beta.Nversion, andlatestrejects any prerelease.testchecks the version, installs dependencies and runs the unit tests, with read-only permissions.publishruns after it and is the only job withid-token: write. It runs checkout, setup-node andnpm publish --ignore-scripts, and no dependency code, since the package has no build step.workflow_dispatchonly works for a workflow on the default branch, so this needs to merge before #9 can publish its beta.Before the first run,
@currents/commit-infoneeds a trusted publisher on npmjs.com (package settings → Trusted Publisher → GitHub Actions): organizationcurrents-dev, repositorycommit-info, workflowpublish.yaml.Not run yet: it can only run after merge.
Refs ENG-934
🤖 Generated with Claude Code
https://claude.ai/code/session_01LdJrRhBLEH9Uwt97JMGVTR
Summary by CodeRabbit
alpha,beta, orlatestchannels available.