Skip to content

Commit 661e563

Browse files
authored
fix(release): use npm with working provenance dependencies (#10)
1 parent 3bb65a7 commit 661e563

2 files changed

Lines changed: 16 additions & 5 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ on:
88
required: true
99
type: string
1010
commit_sha:
11-
description: 'Full 40-character lowercase SHA of the current main commit'
11+
description: 'Full 40-character lowercase SHA of current main, or the existing release tag commit when resuming'
1212
required: true
1313
type: string
1414
batch_id:
@@ -25,6 +25,7 @@ concurrency:
2525

2626
env:
2727
NODE_VERSION: '22.x'
28+
NPM_VERSION: '12.0.2'
2829
NPM_REGISTRY: 'https://registry.npmjs.org'
2930
PACKAGE_NAME: 'qca-sdk'
3031

@@ -69,7 +70,7 @@ jobs:
6970
registry-url: ${{ env.NPM_REGISTRY }}
7071

7172
- name: Use trusted-publishing npm version
72-
run: npm install --global npm@12.0.0
73+
run: npm install --global "npm@$NPM_VERSION"
7374

7475
- name: Validate release version and commit
7576
run: |
@@ -220,6 +221,12 @@ jobs:
220221
echo "tarball_name=$tarball_name" >> "$GITHUB_OUTPUT"
221222
echo "tarball_sha256=$tarball_sha256" >> "$GITHUB_OUTPUT"
222223
224+
- name: Smoke-test npm publishing without uploading
225+
env:
226+
TARBALL_NAME: ${{ steps.pack.outputs.tarball_name }}
227+
DIST_TAG: ${{ steps.release-meta.outputs.dist_tag }}
228+
run: npm publish "./$TARBALL_NAME" --dry-run --ignore-scripts --registry "$NPM_REGISTRY" --tag "$DIST_TAG" --access public --provenance
229+
223230
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
224231
with:
225232
name: ${{ steps.pack.outputs.artifact_name }}
@@ -276,7 +283,7 @@ jobs:
276283
registry-url: ${{ env.NPM_REGISTRY }}
277284

278285
- name: Use trusted-publishing npm version
279-
run: npm install --global npm@12.0.0
286+
run: npm install --global "npm@$NPM_VERSION"
280287

281288
- id: state
282289
name: Revalidate main, tag, and registry
@@ -391,7 +398,7 @@ jobs:
391398
registry-url: ${{ env.NPM_REGISTRY }}
392399

393400
- name: Use verification npm version
394-
run: npm install --global npm@12.0.0
401+
run: npm install --global "npm@$NPM_VERSION"
395402

396403
- name: Wait for and verify registry artifact
397404
env:

‎CONTRIBUTING.md‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -97,7 +97,7 @@ or republish historical packages.
9797

9898
## Release
9999

100-
Before the first release, create the GitHub `release` Environment with required reviewers and a deployment-branch rule limited to `main`. Add a tag ruleset for `refs/tags/v*` that blocks updates and deletions and allows creation only by the release automation identity. Using npm 12.0.0 or newer, replace the existing npm trust entry so it requires the same Environment:
100+
Before the first release, create the GitHub `release` Environment with required reviewers and a deployment-branch rule limited to `main`. Add a tag ruleset for `refs/tags/v*` that blocks updates and deletions and allows creation only by the release automation identity. Using npm 12.0.1 or newer, replace the existing npm trust entry so it requires the same Environment:
101101

102102
```bash
103103
npm trust list qca-sdk --registry https://registry.npmjs.org
@@ -123,6 +123,10 @@ Do not dispatch the workflow until all settings are active.
123123

124124
npm versions are immutable. Never reuse or overwrite one: fix forward with a new release pull request and version, and deprecate an unusable version when necessary. A safe rerun must use the same SHA, version, and `batch_id`; it verifies the existing registry tarball without uploading it again.
125125

126+
The release workflow pins npm `12.0.2`; npm `12.0.0` omitted a required `sigstore` dependency and cannot publish packages ([upstream fix](https://github.com/npm/cli/pull/9740)). Preflight runs `npm publish --dry-run` on the packed artifact to check the publishing command before tag creation. This checks CLI loading and package handling; trusted-publishing authorization is still checked during the actual upload.
127+
128+
If a workflow-only fix is needed after the release tag was created, merge that fix into `main`, then start a new workflow run from `main` with the original version, tagged commit SHA, and `batch_id`. Re-running the old workflow run uses its original workflow revision and will not pick up the fix. The existing tag must remain unchanged; validation permits the original commit when that version's tag already points to it.
129+
126130
## Pull requests
127131

128132
Complete the pull request template, include exact verification commands and results, and identify public API, documentation, integration-test, and cross-SDK effects. Do not combine unrelated refactors with behavior changes.

0 commit comments

Comments
 (0)