Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
166 changes: 159 additions & 7 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ on:
- agent-hypervisor
- agent-sre
- agent-compliance
- agent-runtime
- agent-lightning
- agent-governance-dotnet
- all

Expand All @@ -24,14 +26,28 @@ permissions:
attestations: write

jobs:
publish-python:
# -------------------------------------------------------------------
# Build Python packages and attest provenance.
#
# IMPORTANT: Actual PyPI publishing is done via the ADO pipeline
# (pipelines/pypi-publish.yml) using ESRP Release. GitHub Actions
# Trusted Publishers are NOT compliant for Microsoft PyPI publishing.
# See: docs/internal/pypi-publishing.md
# -------------------------------------------------------------------
build-python:
if: ${{ github.event_name == 'release' || github.event.inputs.package != 'agent-governance-dotnet' }}
runs-on: ubuntu-latest
environment: pypi
strategy:
fail-fast: false
matrix:
package: [agent-os, agent-mesh, agent-hypervisor, agent-sre, agent-compliance]
package:
- agent-os
- agent-mesh
- agent-hypervisor
- agent-sre
- agent-compliance
- agent-runtime
- agent-lightning
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

Expand All @@ -49,16 +65,92 @@ jobs:
working-directory: packages/${{ matrix.package }}
run: python -m build

- name: Validate build artifacts
working-directory: packages/${{ matrix.package }}
run: |
echo "=== Built artifacts for ${{ matrix.package }} ==="
ls -la dist/
# At least one wheel is required by Microsoft Python team policy
if ! ls dist/*.whl 1>/dev/null 2>&1; then
echo "::error::No wheel (.whl) found for ${{ matrix.package }} — at least one wheel is required"
exit 1
fi

- name: Attest build provenance
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
with:
subject-path: packages/${{ matrix.package }}/dist/*

- name: Publish ${{ matrix.package }} to PyPI
uses: pypa/gh-action-pypi-publish@ed0c53931b1dc9bd32cbe73a98c7f6766f8a527e # v1.13.0
- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6db9a6b7e75b195db6a6b2be22da8 # v4.6.2
with:
name: pypi-${{ matrix.package }}
path: packages/${{ matrix.package }}/dist/
retention-days: 30

# -------------------------------------------------------------------
# Build npm packages, pack .tgz, and upload artifacts.
#
# IMPORTANT: Actual npm publishing is done via the ADO pipeline
# (pipelines/npm-publish.yml) using ESRP Release. GitHub Actions
# is NOT compliant for Microsoft npm publishing.
# See: PUBLISHING.md
# -------------------------------------------------------------------
build-npm:
if: ${{ github.event_name == 'release' || github.event.inputs.package == 'all' }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- name: agentmesh-copilot-governance
path: packages/agentmesh-integrations/copilot-governance
- name: agentmesh-mastra
path: packages/agentmesh-integrations/mastra-agentmesh
- name: agentmesh-api
path: packages/agent-mesh/services/api
- name: agentmesh-mcp-proxy
path: packages/agent-mesh/packages/mcp-proxy
- name: agentmesh-sdk
path: packages/agent-mesh/sdks/typescript
- name: agent-os-copilot-extension
path: packages/agent-os/extensions/copilot
- name: agentos-mcp-server
path: packages/agent-os/extensions/mcp-server
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
with:
node-version: "20"

- name: Install dependencies
working-directory: ${{ matrix.path }}
run: npm ci --ignore-scripts 2>/dev/null || npm install

- name: Build ${{ matrix.name }}
working-directory: ${{ matrix.path }}
run: npm run build

- name: Pack ${{ matrix.name }}
working-directory: ${{ matrix.path }}
run: |
mkdir -p tgz-output
npm pack --pack-destination tgz-output
echo "=== Packed ==="
ls -la tgz-output/

- name: Attest build provenance
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
with:
packages-dir: packages/${{ matrix.package }}/dist/
skip-existing: true
subject-path: ${{ matrix.path }}/tgz-output/*.tgz

- name: Upload build artifacts
uses: actions/upload-artifact@ea165f8d65b6db9a6b7e75b195db6a6b2be22da8 # v4.6.2
with:
name: npm-${{ matrix.name }}
path: ${{ matrix.path }}/tgz-output/*.tgz
retention-days: 30

publish-nuget:
if: ${{ github.event_name == 'release' || github.event.inputs.package == 'agent-governance-dotnet' || github.event.inputs.package == 'all' }}
Expand All @@ -71,6 +163,11 @@ jobs:
with:
dotnet-version: "8.0.x"

- name: Install NuGet CLI
run: |
curl -o /usr/local/bin/nuget.exe https://dist.nuget.org/win-x86-commandline/latest/nuget.exe
echo 'alias nuget="mono /usr/local/bin/nuget.exe"' >> ~/.bashrc

- name: Build .NET SDK
working-directory: packages/agent-governance-dotnet
run: dotnet build --configuration Release
Expand All @@ -83,11 +180,63 @@ jobs:
working-directory: packages/agent-governance-dotnet
run: dotnet pack src/AgentGovernance/AgentGovernance.csproj --configuration Release --no-build --output ./nupkg

# ----------------------------------------------------------------
# ESRP Signing — Authenticode sign DLLs + NuGet package signing
# Requires ESRP onboarding (https://aka.ms/esrp-onboarding)
# Key code CP-401405 is the Microsoft NuGet signing certificate.
# ----------------------------------------------------------------
- name: Authenticode sign assemblies (ESRP)
if: ${{ env.ESRP_AAD_ID != '' }}
env:
ESRP_AAD_ID: ${{ secrets.ESRP_AAD_ID }}
ESRP_AAD_SECRET: ${{ secrets.ESRP_AAD_SECRET }}
run: |
echo "Submitting DLLs for Authenticode signing via ESRP..."
# Sign all packable DLLs before NuGet packing
# This step uses ESRP client or Azure Trusted Signing
# See: https://aka.ms/esrp-onboarding for setup
find packages/agent-governance-dotnet -name '*.dll' -path '*/Release/*' | head -20
echo "::warning::ESRP Authenticode signing must be configured. See https://aka.ms/esrp-onboarding"

- name: Sign NuGet package (ESRP)
if: ${{ env.ESRP_AAD_ID != '' }}
env:
ESRP_AAD_ID: ${{ secrets.ESRP_AAD_ID }}
ESRP_AAD_SECRET: ${{ secrets.ESRP_AAD_SECRET }}
run: |
echo "Submitting NuGet packages for signing via ESRP..."
# ESRP NuGet signing uses:
# KeyCode: CP-401405
# OperationCode: NuGetSign + NuGetVerify
# Alternatively, use dotnet nuget sign with Azure Trusted Signing:
# dotnet nuget sign ./nupkg/*.nupkg \
# --certificate-store-name My \
# --certificate-fingerprint "$CERT_FINGERPRINT" \
# --timestamper http://timestamp.digicert.com
echo "::warning::ESRP NuGet signing must be configured. See https://aka.ms/esrp-onboarding"

- name: Validate NuGet package metadata
working-directory: packages/agent-governance-dotnet
run: |
echo "=== Validating Microsoft NuGet compliance ==="
for pkg in ./nupkg/*.nupkg; do
echo "--- Package: $pkg ---"
dotnet nuget verify "$pkg" --all 2>/dev/null || echo "(Unsigned package — signing required before production publish)"
# Inspect package metadata
unzip -p "$pkg" '*.nuspec' | head -30
done

- name: Attest build provenance
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
with:
subject-path: packages/agent-governance-dotnet/nupkg/*.nupkg

- name: Attest symbol package provenance
uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2
with:
subject-path: packages/agent-governance-dotnet/nupkg/*.snupkg
continue-on-error: true

- name: Publish to NuGet
working-directory: packages/agent-governance-dotnet
env:
Expand All @@ -97,4 +246,7 @@ jobs:
echo "::warning::NUGET_API_KEY not set, skipping NuGet publish"
exit 0
fi
# Push both .nupkg and .snupkg (symbol package)
dotnet nuget push ./nupkg/*.nupkg --api-key "$NUGET_API_KEY" --source https://api.nuget.org/v3/index.json --skip-duplicate
echo "=== Verifying published package signature ==="
echo "Run: NuGet.exe verify -Signatures <pkg> -CertificateFingerprint 3F9001EA83C560D712C24CF213C3D312CB3BFF51EE89435D3430BD06B5D0EECE;AA12DA22A49BCE7D5C1AE64CC1F3D892F150DA76140F210ABD2CBFFCA2C18A27;566A31882BE208BE4422F7CFD66ED09F5D4524A5994F50CCC8B05EC0528C1353"
29 changes: 29 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,8 +5,37 @@ All notable changes to this project will be documented in this file.
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/),
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

> [!IMPORTANT]
> All releases to date are **community preview releases** for testing and evaluation.
> They are not official Microsoft-signed releases. Official signed packages are coming
> in a future release.

## [Unreleased]

## [2.2.0] - 2026-03-17

### Added
- ESRP Release ADO pipeline for PyPI publishing (`pipelines/pypi-publish.yml`)
- ESRP Release ADO pipeline for npm publishing (`pipelines/npm-publish.yml`)
- npm build + pack job in GitHub Actions publish workflow
- Community preview disclaimers across all READMEs, release notes, and package descriptions
- `PUBLISHING.md` guide covering PyPI, npm, and NuGet publishing requirements
- `agent-runtime` re-export wrapper package (`src/agent_runtime/__init__.py`)
- `RELEASE_NOTES_v2.2.0.md`

### Changed
- GitHub Actions `publish.yml` no longer publishes to PyPI (build + attest only)
- Python package author updated to `Microsoft Corporation` with team DL (all 7 packages)
- npm packages renamed to `@microsoft` scope (from `@agentmesh`, `@agent-os`, unscoped)
- npm package author set to `Microsoft Corporation` (all 9 packages)
- All package descriptions prefixed with `Community Edition`
- License corrected to MIT where mismatched (agent-mesh classifier, 2 npm packages)

### Fixed
- `agent-runtime` build failure (invalid parent-directory hatch reference)
- Missing `License :: OSI Approved :: MIT License` classifier in 3 Python packages
- Incorrect repository URLs in 2 npm packages

## [2.1.0] - 2026-03-15

### 🚀 Highlights
Expand Down
129 changes: 129 additions & 0 deletions PUBLISHING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,129 @@
# Publishing Guide

> [!IMPORTANT]
> **Community Preview Releases** — All packages currently published from this repository
> are community preview releases for testing and evaluation only. They are **not** official
> Microsoft-signed releases. The ESRP Release pipelines described below have been set up
> proactively and will be activated when official publishing approval is obtained.

This document describes the requirements for publishing packages from the
Agent Governance Toolkit to public registries.

## Python Packages (PyPI)

### Published Packages

| Package | PyPI Name | Directory |
|---------|-----------|-----------|
| Agent OS Kernel | `agent-os-kernel` | `packages/agent-os` |
| AgentMesh Platform | `agentmesh-platform` | `packages/agent-mesh` |
| Agent Hypervisor | `agent-hypervisor` | `packages/agent-hypervisor` |
| Agent Runtime | `agent-runtime` | `packages/agent-runtime` |
| Agent SRE | `agent-sre` | `packages/agent-sre` |
| Agent Governance Toolkit | `agent-governance-toolkit` | `packages/agent-compliance` |
| Agent Lightning | `agent-lightning` | `packages/agent-lightning` |

### Publishing Method

All Python packages are published to PyPI via **ESRP Release** using an Azure
DevOps pipeline (`pipelines/pypi-publish.yml`).

> **⚠️ GitHub Actions Trusted Publishers are not used for PyPI publishing.**
> The GitHub Actions workflow (`.github/workflows/publish.yml`) builds and
> attests packages but does **not** publish them. Actual publishing goes
> through the ADO pipeline.

### Building Packages

```bash
# Install build tools
python -m pip install --upgrade pip build

# Build a specific package
cd packages/agent-os
python -m build
```

Each package produces:
- A wheel (`.whl`) — **required**
- A source distribution (`.tar.gz`) — recommended

### Package Metadata Requirements

All packages must include:
- **Author**: `Microsoft Corporation`
- **Contact email**: A team distribution list (not a personal email)
- **License**: MIT (with `License :: OSI Approved :: MIT License` classifier)
- **README**: `readme = "README.md"` in `pyproject.toml`

### Naming Conventions

- Do **not** start package names with `microsoft` or `windows` (reserved)
- If using `azure` branding, coordinate with the Azure SDK team
- All packages are published under the **microsoft** PyPI account

### Linux Wheels

For packages with native extensions targeting Linux, use `manylinux` tags
(e.g., `manylinux2014_x86_64`), **not** `linux_x86_64`.

## npm Packages

### Published Packages

All npm packages use the `@microsoft` scope.

| Package | npm Name | Directory |
|---------|----------|-----------|
| AgentMesh Copilot Governance | `@microsoft/agentmesh-copilot-governance` | `packages/agentmesh-integrations/copilot-governance` |
| AgentMesh Mastra | `@microsoft/agentmesh-mastra` | `packages/agentmesh-integrations/mastra-agentmesh` |
| AgentMesh API | `@microsoft/agentmesh-api` | `packages/agent-mesh/services/api` |
| AgentMesh MCP Proxy | `@microsoft/agentmesh-mcp-proxy` | `packages/agent-mesh/packages/mcp-proxy` |
| AgentMesh SDK | `@microsoft/agentmesh-sdk` | `packages/agent-mesh/sdks/typescript` |
| Agent OS Copilot Extension | `@microsoft/agent-os-copilot-extension` | `packages/agent-os/extensions/copilot` |
| AgentOS MCP Server | `@microsoft/agentos-mcp-server` | `packages/agent-os/extensions/mcp-server` |

The VS Code and Cursor extensions are published via their respective marketplaces,
not npm.

### Publishing Method

All npm packages are published via **ESRP Release** using an Azure DevOps
pipeline (`pipelines/npm-publish.yml`).

> **⚠️ GitHub Actions is not used for npm publishing.**
> The GitHub Actions workflow builds and packs `.tgz` files but does **not**
> publish them. Actual publishing goes through the ADO pipeline.

### Building & Packing

```bash
cd packages/agent-mesh/sdks/typescript
npm ci
npm run build
npm pack
```

### Package Metadata Requirements

All packages must include:
- **Scope**: `@microsoft` (ESRP reserved scope)
- **Author**: `Microsoft Corporation`
- **License**: `MIT`
- **Repository**: pointing to `microsoft/agent-governance-toolkit`
- **`private`**: must **not** be set to `true`

### Naming Conventions

- Use the `@microsoft` scope for all publishable packages
- Avoid "shipping the org chart" — scope should reflect product, not team structure

## .NET Packages (NuGet)

The .NET SDK (`packages/agent-governance-dotnet`) is published to NuGet with
ESRP Authenticode and NuGet signing.

## Contact

- Python packaging questions: python@microsoft.com
- ESRP Release support: esrprelpm@microsoft.com
Loading
Loading