Repository navigation
ci: release automation — CI, OIDC npm publish, version-sync gate - #4
Conversation
- .github/workflows/ci.yml: version-sync + typecheck + lint + test + build on PRs and main (Node 20 & 22), least-privilege perms, cancel-in-progress concurrency - .github/workflows/release.yml: on a v* tag, gate then publish to npm via OIDC trusted publishing (provenance, no stored token) and cut a GitHub release; tag flows in as a quoted env var, never interpolated into a shell step - scripts/check-version-sync.mjs: asserts package.json, marketplace.json, and plugin.json (and the release tag) agree — guards the three-file drift that blocked the v0.1.1 plugin upgrade - scripts/bump-version.mjs: bump all three at once via 'pnpm bump <version>' - .github/dependabot.yml: weekly github-actions + npm updates - package.json: pin packageManager, add check:version + bump scripts, extend lint to scripts/
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Run ID: 📒 Files selected for processing (1)
📝 WalkthroughWalkthroughAdds pnpm version pinning, version-sync and bump scripts, Dependabot scheduling, a CI workflow for pull requests and main pushes, and a release workflow that validates versions, publishes to npm with provenance, and creates GitHub releases for tagged versions. ChangesVersion and release automation
Estimated code review effort🎯 4 (Complex) | ⏱️ ~45 minutes Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Warning Review ran into problems🔥 ProblemsThese MCP integrations need to be re-authenticated in the Integrations settings: Linear Comment |
There was a problem hiding this comment.
Actionable comments posted: 6
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/ci.yml:
- Around line 25-30: The workflow uses floating action tags for
actions/checkout, pnpm/action-setup, and actions/setup-node, and checkout still
persists credentials. Update the .github/workflows/ci.yml job to pin each action
reference to a full commit SHA, and set persist-credentials to false on the
actions/checkout step to disable credential persistence.
In @.github/workflows/release.yml:
- Around line 25-27: The release workflow job is over-permissioned because
validation steps and publishing/release creation share the same permissions.
Split the current job in release.yml so install, lint, typecheck, and
prepublishOnly run in a read-only validation job, then move npm publish and
GitHub release creation into a separate publish job that is the only one granted
id-token: write and contents: write; use the existing workflow structure to
identify the publish-related steps and keep the rest read-only.
- Around line 56-62: The release workflow publishes to npm before confirming the
GitHub release can be created, which risks consuming the version if gh release
create fails. Update the release job around the Publish to npm and Create GitHub
release steps so it preflights for an existing release using gh release view (or
equivalent) before npm publish, and only proceeds to npm publish when the GitHub
release is confirmed safe to create.
- Around line 29-33: The release workflow is using mutable action tags for
actions/checkout, pnpm/action-setup, and actions/setup-node, which should be
pinned for a publish/release job. Update the workflow to reference immutable
commit SHAs for those action uses, keeping the same steps in the release job so
the behavior stays unchanged while the versions are locked down.
- Line 29: The checkout step in the release workflow is leaving GitHub token
credentials persisted for the rest of the job. Update the existing
actions/checkout usage to disable persisted credentials by setting
persist-credentials to false so later steps cannot reuse the token. Make this
change on the checkout step itself and keep the rest of the workflow unchanged.
- Around line 39-41: The release workflow currently upgrades npm with a floating
latest tag, which makes trusted publishing depend on future npm changes. Update
the Upgrade npm for OIDC trusted publishing step in the release workflow to
install a fixed compatible npm 11.x version instead of npm@latest, using the
existing release job step as the place to pin it.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: ASSERTIVE
Plan: Pro
Run ID: d0796cca-9dc6-4a28-94f5-e0a5a4223c5d
📒 Files selected for processing (6)
.github/dependabot.yml.github/workflows/ci.yml.github/workflows/release.ymlpackage.jsonscripts/bump-version.mjsscripts/check-version-sync.mjs
promote and e2e tests spawn 'git commit' in clones that have no local identity. GitHub runners set no identity and disable auto-detect, so those commits exited 1 — the tests failed only in CI, not locally where git auto-derives an identity. Set GIT_AUTHOR_*/GIT_COMMITTER_* via vitest test.env so the suite is self-contained anywhere. Verified: full 185-test suite passes with global + system git identity removed.
- pin all actions to commit SHAs (+ persist-credentials: false on checkouts) - split release into a read-only verify job and a minimal privileged publish job (least-privilege OIDC), passing the built dist as an artifact - publish with --ignore-scripts; pin npm to 11.5.1 for OIDC trusted publishing - idempotent publish (skip if version already on the registry) and idempotent GitHub release - publish job re-validates the tag against all version sources before shipping, so the token-holding job self-validates
Favor readable, Dependabot-maintained major version tags over SHA pins. All other hardening (persist-credentials, verify/publish split, OIDC provenance, npm pin, idempotency, publish-job version re-check) is unchanged.
Replace the placeholder author/committer with Hrithik <hrithik@robotostudio.com> so promote/e2e test commits are attributed to the maintainer.
What this adds
A release pipeline so versioning + publishing stop being manual and can't drift the way v0.1.1 did.
.github/workflows/ci.yml— on every PR and push tomain, across Node 20 & 22: version-sync → typecheck → lint → test → build. Least-privilege (contents: read), cancels superseded runs..github/workflows/release.yml— on av*tag: re-checks the tag against all version files, then publishes to npm via OIDC trusted publishing (provenance, no stored token) and cuts a GitHub release. The tag is read as a quoted env var, never interpolated into a shell step.scripts/check-version-sync.mjs— assertspackage.json,marketplace.json, andplugin.json(and the release tag) agree. This is the guard for the three-file drift that blocked the v0.1.1 plugin upgrade.scripts/bump-version.mjs—pnpm bump <version>bumps all three at once..github/dependabot.yml— weekly GitHub Actions + npm updates.package.json— pinnedpackageManager,check:version+bumpscripts, lint now coversscripts/.One-time setup (after merge)
npm trusted publisher (no tokens stored): npmjs.com →
roboto-mem→ Settings → Trusted Publishers → GitHub Actions → repositoryrobotostudio/roboto-mem, workflowrelease.yml, environmentrelease. Optionally create areleaseEnvironment for an approval gate.New release flow
CI gates, publishes with provenance, cuts the release. No
npm login, noNPM_TOKEN, no drift.Verification
Locally: lint clean, typecheck, 185 tests, build — all green. Bump round-trips across all three files; the version gate passes when synced and fails on a mismatched tag. This PR's own CI run exercises
ci.yml.Summary by CodeRabbit
main(version check, typecheck, lint, tests, build).v*tags that verifies versions, publishes npm packages (OIDC/provenance), and creates GitHub releases idempotently.check:versionandbumptooling to keep version values aligned across project files.