You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 661e563
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: CONTRIBUTING.md
+5-1Lines changed: 5 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -97,7 +97,7 @@ or republish historical packages.
97
97
98
98
## Release
99
99
100
-
Before the first release, create the GitHub `release` Environment with required reviewers and a deployment-branch rule limited to `main`. Add a tag ruleset for `refs/tags/v*` that blocks updates and deletions and allows creation only by the release automation identity. Using npm 12.0.0 or newer, replace the existing npm trust entry so it requires the same Environment:
100
+
Before the first release, create the GitHub `release` Environment with required reviewers and a deployment-branch rule limited to `main`. Add a tag ruleset for `refs/tags/v*` that blocks updates and deletions and allows creation only by the release automation identity. Using npm 12.0.1 or newer, replace the existing npm trust entry so it requires the same Environment:
101
101
102
102
```bash
103
103
npm trust list qca-sdk --registry https://registry.npmjs.org
@@ -123,6 +123,10 @@ Do not dispatch the workflow until all settings are active.
123
123
124
124
npm versions are immutable. Never reuse or overwrite one: fix forward with a new release pull request and version, and deprecate an unusable version when necessary. A safe rerun must use the same SHA, version, and `batch_id`; it verifies the existing registry tarball without uploading it again.
125
125
126
+
The release workflow pins npm `12.0.2`; npm `12.0.0` omitted a required `sigstore` dependency and cannot publish packages ([upstream fix](https://github.com/npm/cli/pull/9740)). Preflight runs `npm publish --dry-run` on the packed artifact to check the publishing command before tag creation. This checks CLI loading and package handling; trusted-publishing authorization is still checked during the actual upload.
127
+
128
+
If a workflow-only fix is needed after the release tag was created, merge that fix into `main`, then start a new workflow run from `main` with the original version, tagged commit SHA, and `batch_id`. Re-running the old workflow run uses its original workflow revision and will not pick up the fix. The existing tag must remain unchanged; validation permits the original commit when that version's tag already points to it.
129
+
126
130
## Pull requests
127
131
128
132
Complete the pull request template, include exact verification commands and results, and identify public API, documentation, integration-test, and cross-SDK effects. Do not combine unrelated refactors with behavior changes.
0 commit comments