Skip to content

ci: harden trusted npm releases - #12

Merged
rogerchappel merged 2 commits into
mainfrom
agent/oss-ce1e88d3efd7-release-publishing
Aug 17, 2026
Merged

rogerchappel merged 2 commits into
mainfrom
agent/oss-ce1e88d3efd7-release-publishing

Conversation

@rogerchappel

Copy link
Copy Markdown
Owner

Summary

  • publish tagged releases to npm through GitHub OIDC trusted publishing
  • require the release tag, package manifest, and single packed tarball to have the same identity
  • pass one explicitly validated tarball to both npm publish and gh release create, removing the unchecked *.tgz handoff
  • enforce ordering and publication requirements with automated release-contract tests
  • document the supported npm install path and recovery behavior for partial release failures

Evidence

The existing v0.1.0 GitHub release had no corresponding npm package. The release workflow packed an artifact and created a GitHub release but never invoked npm publish; releasebox.config.json also explicitly disabled npm publication.

Commits

  • 08b450d ci: harden trusted npm releases
  • 2869f3d docs: document npm release and recovery

Verification

  • npm ci
  • npm run release:contract
  • npm run release:check
  • positive artifact validation using GITHUB_REF_NAME=v0.1.0
  • negative artifact validation using GITHUB_REF_NAME=v9.9.9 (expected rejection)
  • bash scripts/validate.sh
  • git diff --check origin/main..HEAD
  • commit author/committer identity checked for every proposed commit

Release setup

Before a tag can publish, the npm package must configure this repository and .github/workflows/release.yml as a trusted publisher. No npm token is read by the workflow.

@rogerchappel
rogerchappel merged commit 2972894 into main Aug 17, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant