v0.2.2 shipped a tarball with a correct README.md inside and a package page that still read "This package does not have a README". npmjs.com does not read the README out of the tarball — it renders the `readme` field of the manifest, which the publishing client attaches. pnpm does not attach it. Captured both clients against a local registry to be sure: pnpm publish readme absent, workspace:* rewritten to 0.0.0 npm publish readme 18732 bytes, workspace:* left as-is Neither does both halves, so: pack with pnpm, publish that tarball with npm. npm takes the non-directory path through #getManifest, which reads it with fullReadJson and picks the readme up out of the tarball; the deps are already rewritten by then. Provenance is unaffected — it is computed from the tarball bytes, not the spec type. verify-tarball.sh now takes the tarball to inspect, so CI asserts the exact bytes it publishes rather than a second one packed for the check, and packs with pnpm when called bare so a local run matches CI. verify-published-readme.sh is the guard that would have caught this: it asks the registry, after publishing, whether the page has a README. The tarball was never the problem, so no amount of looking inside it would have helped.
81 lines
3.0 KiB
YAML
81 lines
3.0 KiB
YAML
name: Release
|
|
|
|
run-name: "Release · ${{ github.ref_name }}"
|
|
|
|
# Publishes @airshiplabs/cli to npm when a cli-v* tag is pushed. Cut the release
|
|
# with `make release` (bumps apps/cli/package.json, commits, tags) then push the
|
|
# tag — see scripts/release.sh.
|
|
#
|
|
# This lane is for locally-cut releases only. publish.yml pushes its tag with
|
|
# GITHUB_TOKEN, and GitHub does not fire workflows from GITHUB_TOKEN-authored
|
|
# pushes, so a CI-cut release never lands here and the two never both publish.
|
|
on:
|
|
push:
|
|
tags: ["cli-v*"]
|
|
|
|
permissions:
|
|
contents: read
|
|
id-token: write # npm provenance attestation
|
|
|
|
jobs:
|
|
publish:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: pnpm
|
|
registry-url: "https://registry.npmjs.org"
|
|
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
- name: Verify the tag matches apps/cli's version
|
|
run: |
|
|
TAG="${GITHUB_REF_NAME#cli-v}"
|
|
PKG=$(node -p "require('./apps/cli/package.json').version")
|
|
if [ "$TAG" != "$PKG" ]; then
|
|
echo "::error::Tag cli-v$TAG does not match @airshiplabs/cli version $PKG (cut releases with 'make release')"
|
|
exit 1
|
|
fi
|
|
|
|
# `pnpm publish` does NOT build the package. apps/cli has no prepack,
|
|
# prepare or prepublishOnly hook, and the npm lifecycle never invokes a
|
|
# plain `build` script — so nothing here builds unless this step does.
|
|
# Skip it and `files: ["dist"]` matches an empty directory, npm reports a
|
|
# clean publish, and the tarball ships a package.json and a LICENSE.
|
|
# v0.2.0 went out exactly that way.
|
|
- name: Build the CLI
|
|
run: pnpm turbo run build --filter=@airshiplabs/cli
|
|
|
|
# Pack with pnpm, publish that exact tarball with npm. Neither tool does
|
|
# both halves: only `pnpm pack` rewrites the `workspace:*` devDependencies
|
|
# into real versions, and only `npm publish` sends the `readme` field —
|
|
# which is what npmjs.com renders the package page from. `pnpm publish`
|
|
# drops it, so v0.2.2 shipped a correct tarball behind a page that still
|
|
# read "This package does not have a README".
|
|
- name: Pack the tarball
|
|
id: pack
|
|
working-directory: apps/cli
|
|
run: |
|
|
TGZ="$RUNNER_TEMP/airshiplabs-cli.tgz"
|
|
pnpm pack --out "$TGZ"
|
|
echo "tgz=$TGZ" >> "$GITHUB_OUTPUT"
|
|
|
|
# Looks inside the tarball it is about to publish, not a second one packed
|
|
# for the check. `publish --dry-run` cannot stand in here — it packs the
|
|
# same empty tarball and exits 0.
|
|
- name: Verify the tarball is complete
|
|
run: bash scripts/verify-tarball.sh "${{ steps.pack.outputs.tgz }}"
|
|
|
|
- name: Publish to npm
|
|
run: npm publish "${{ steps.pack.outputs.tgz }}" --access public --provenance
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: The npm page has a README
|
|
run: bash scripts/verify-published-readme.sh
|