Files
airship/.github/workflows/release.yml
T
Nayan 8e076ada1a fix(ci): publish with npm so npmjs.com renders the README
v0.2.2 shipped a tarball with a correct README.md inside and a package
page that still read "This package does not have a README". npmjs.com
does not read the README out of the tarball — it renders the `readme`
field of the manifest, which the publishing client attaches. pnpm does
not attach it.

Captured both clients against a local registry to be sure:

  pnpm publish  readme absent, workspace:* rewritten to 0.0.0
  npm publish   readme 18732 bytes, workspace:* left as-is

Neither does both halves, so: pack with pnpm, publish that tarball with
npm. npm takes the non-directory path through #getManifest, which reads
it with fullReadJson and picks the readme up out of the tarball; the
deps are already rewritten by then. Provenance is unaffected — it is
computed from the tarball bytes, not the spec type.

verify-tarball.sh now takes the tarball to inspect, so CI asserts the
exact bytes it publishes rather than a second one packed for the check,
and packs with pnpm when called bare so a local run matches CI.

verify-published-readme.sh is the guard that would have caught this:
it asks the registry, after publishing, whether the page has a README.
The tarball was never the problem, so no amount of looking inside it
would have helped.
2026-08-11 06:13:16 +05:30

81 lines
3.0 KiB
YAML

name: Release
run-name: "Release · ${{ github.ref_name }}"
# Publishes @airshiplabs/cli to npm when a cli-v* tag is pushed. Cut the release
# with `make release` (bumps apps/cli/package.json, commits, tags) then push the
# tag — see scripts/release.sh.
#
# This lane is for locally-cut releases only. publish.yml pushes its tag with
# GITHUB_TOKEN, and GitHub does not fire workflows from GITHUB_TOKEN-authored
# pushes, so a CI-cut release never lands here and the two never both publish.
on:
push:
tags: ["cli-v*"]
permissions:
contents: read
id-token: write # npm provenance attestation
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
cache: pnpm
registry-url: "https://registry.npmjs.org"
- run: pnpm install --frozen-lockfile
- name: Verify the tag matches apps/cli's version
run: |
TAG="${GITHUB_REF_NAME#cli-v}"
PKG=$(node -p "require('./apps/cli/package.json').version")
if [ "$TAG" != "$PKG" ]; then
echo "::error::Tag cli-v$TAG does not match @airshiplabs/cli version $PKG (cut releases with 'make release')"
exit 1
fi
# `pnpm publish` does NOT build the package. apps/cli has no prepack,
# prepare or prepublishOnly hook, and the npm lifecycle never invokes a
# plain `build` script — so nothing here builds unless this step does.
# Skip it and `files: ["dist"]` matches an empty directory, npm reports a
# clean publish, and the tarball ships a package.json and a LICENSE.
# v0.2.0 went out exactly that way.
- name: Build the CLI
run: pnpm turbo run build --filter=@airshiplabs/cli
# Pack with pnpm, publish that exact tarball with npm. Neither tool does
# both halves: only `pnpm pack` rewrites the `workspace:*` devDependencies
# into real versions, and only `npm publish` sends the `readme` field —
# which is what npmjs.com renders the package page from. `pnpm publish`
# drops it, so v0.2.2 shipped a correct tarball behind a page that still
# read "This package does not have a README".
- name: Pack the tarball
id: pack
working-directory: apps/cli
run: |
TGZ="$RUNNER_TEMP/airshiplabs-cli.tgz"
pnpm pack --out "$TGZ"
echo "tgz=$TGZ" >> "$GITHUB_OUTPUT"
# Looks inside the tarball it is about to publish, not a second one packed
# for the check. `publish --dry-run` cannot stand in here — it packs the
# same empty tarball and exits 0.
- name: Verify the tarball is complete
run: bash scripts/verify-tarball.sh "${{ steps.pack.outputs.tgz }}"
- name: Publish to npm
run: npm publish "${{ steps.pack.outputs.tgz }}" --access public --provenance
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: The npm page has a README
run: bash scripts/verify-published-readme.sh