chore: add release workflow using npm trusted publishing - #403
Draft
captbaritone wants to merge 3 commits into
Draft
captbaritone wants to merge 3 commits into
captbaritone wants to merge 3 commits into
Conversation
Publishes via GitHub Actions with OIDC provenance instead of a local npm token, following the pattern already used by graphql/graphql-js.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #403 +/- ##
=========================================
Coverage 100.00% 100.00%
=========================================
Files 21 21
Lines 748 748
Branches 48 48
=========================================
Hits 748 748 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
captbaritone
marked this pull request as draft
September 18, 2026 17:54
A tag can point at any commit, so a tag-triggered release bypasses branch protection entirely. Keying off the version in package.json means the published commit is always one that landed on main.
Merged
Every previous release body uses the gen-changelog format driven by the 'PR: *' labels, which --generate-notes would have abandoned. Generating in the build job means a PR missing its label fails before anything is published.
Member
|
Trusted publishing is now ready to go npm-side. I've only allowed for it to do "npm stage publish" right now (you need to approve the release via npm), we can change this if need be |
benjie
reviewed
Sep 22, 2026
Comment on lines
+22
to
+30
| uses: actions/checkout@v4 | ||
| with: | ||
| # gen-changelog.js shells out to 'git rev-list' against release tags, | ||
| # so it needs full history rather than the default shallow clone. | ||
| fetch-depth: 0 | ||
| persist-credentials: false | ||
|
|
||
| - name: Setup Node.js | ||
| uses: actions/setup-node@v4 |
Member
There was a problem hiding this comment.
These versions are a little old, I think v7 is latest?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds a
Releaseworkflow so publishing happens from CI with npm trusted publishing (OIDC) instead of a maintainer's local npm token. NoNPM_TOKENsecret is used or needed.How it works
Merging to
mainis the only gate. On every push tomainthe workflow reads the version frompackage.jsonand asks npm whether that version already exists. If it does, the run is a no-op. If it does not, it runs the test suite, builds the package, publishes it with provenance, creates thevX.Y.Ztag, and opens a GitHub release.So a release is simply a merged version bump — no tagging or
npm publishby hand. Because the decision is derived from npm's state rather than from the event, re-running a failed publish is safe.A version containing a
-publishes undernextrather thanlatest, so the pipeline can be rehearsed with something like0.11.1-rc.0.Why main-triggered rather than tag-triggered
A tag can point at any commit, including one that never landed on
main, and tags are not covered by branch protection. A tag-triggered release would let anyone with write access publish an unreviewed commit, bypassing whatever protectionmainhas. Keying offmainmeans the published commit is always one that went through the branch.Security notes
npm ci, so no dependency lifecycle scripts execute while the token is available. It only publishes the artifact the build job produced.permissions: {}at the top level, with each job granted the minimum it needs.main. Branch protection onmain(require a PR, require status checks; no required approvals needed) is what makes that boundary meaningful, and is worth adding alongside this.Notes
release.yml. No GitHub environment is required..node-versionis pinned tov24because trusted publishing needs npm >= 11.5.1. Node 22 still bundles npm 10.9.4, which is too old and would fail at publish time.CONTRIBUTING.mdnow documents thePR: *label requirement, sincegen-changelog.jsthrows on any merged PR missing one.Test plan
npm run testpasses (lint, tsc, 86 tests, prettier, cspell)bash -nnpm view