Skip to content

ci: release automation — CI, OIDC npm publish, version-sync gate - #4

Merged
voidhrithik merged 5 commits into
mainfrom
ci/release-automation
Jun 25, 2026
Merged

voidhrithik merged 5 commits into
mainfrom
ci/release-automation

Conversation

@voidhrithik

@voidhrithik voidhrithik commented Jun 25, 2026 •

Copy link
Copy Markdown
Contributor

What this adds

A release pipeline so versioning + publishing stop being manual and can't drift the way v0.1.1 did.

  • .github/workflows/ci.yml — on every PR and push to main, across Node 20 & 22: version-sync → typecheck → lint → test → build. Least-privilege (contents: read), cancels superseded runs.
  • .github/workflows/release.yml — on a v* tag: re-checks the tag against all version files, then publishes to npm via OIDC trusted publishing (provenance, no stored token) and cuts a GitHub release. The tag is read as a quoted env var, never interpolated into a shell step.
  • scripts/check-version-sync.mjs — asserts package.json, marketplace.json, and plugin.json (and the release tag) agree. This is the guard for the three-file drift that blocked the v0.1.1 plugin upgrade.
  • scripts/bump-version.mjs — pnpm bump <version> bumps all three at once.
  • .github/dependabot.yml — weekly GitHub Actions + npm updates.
  • package.json — pinned packageManager, check:version + bump scripts, lint now covers scripts/.

One-time setup (after merge)

npm trusted publisher (no tokens stored): npmjs.com → roboto-mem → Settings → Trusted Publishers → GitHub Actions → repository robotostudio/roboto-mem, workflow release.yml, environment release. Optionally create a release Environment for an approval gate.

New release flow

pnpm bump 0.1.2
git commit -am "chore(release): v0.1.2" && git tag v0.1.2
git push && git push origin v0.1.2

CI gates, publishes with provenance, cuts the release. No npm login, no NPM_TOKEN, no drift.

Verification

Locally: lint clean, typecheck, 185 tests, build — all green. Bump round-trips across all three files; the version gate passes when synced and fails on a mismatched tag. This PR's own CI run exercises ci.yml.

Summary by CodeRabbit

  • New Features
    • Added Dependabot weekly update checks for GitHub Actions and npm dependencies (capped pull request limit).
    • Introduced automated CI for pull requests and pushes to main (version check, typecheck, lint, tests, build).
    • Added a Release workflow for v* tags that verifies versions, publishes npm packages (OIDC/provenance), and creates GitHub releases idempotently.
    • Added check:version and bump tooling to keep version values aligned across project files.
  • Tests
    • Made git author/committer metadata deterministic during tests.

- .github/workflows/ci.yml: version-sync + typecheck + lint + test + build on PRs and main (Node 20 & 22), least-privilege perms, cancel-in-progress concurrency
- .github/workflows/release.yml: on a v* tag, gate then publish to npm via OIDC trusted publishing (provenance, no stored token) and cut a GitHub release; tag flows in as a quoted env var, never interpolated into a shell step
- scripts/check-version-sync.mjs: asserts package.json, marketplace.json, and plugin.json (and the release tag) agree — guards the three-file drift that blocked the v0.1.1 plugin upgrade
- scripts/bump-version.mjs: bump all three at once via 'pnpm bump <version>'
- .github/dependabot.yml: weekly github-actions + npm updates
- package.json: pin packageManager, add check:version + bump scripts, extend lint to scripts/
@coderabbitai

coderabbitai Bot commented Jun 25, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: 394326aa-57e3-4dc4-b02c-fca6c54024bb

📥 Commits

Reviewing files that changed from the base of the PR and between 75e0fbf and a5353a7.

📒 Files selected for processing (1)
  • vitest.config.ts

📝 Walkthrough

Walkthrough

Adds pnpm version pinning, version-sync and bump scripts, Dependabot scheduling, a CI workflow for pull requests and main pushes, and a release workflow that validates versions, publishes to npm with provenance, and creates GitHub releases for tagged versions.

Changes

Version and release automation

Layer / File(s) Summary
Tooling baseline
.github/dependabot.yml, package.json, vitest.config.ts
packageManager is pinned to pnpm@10.32.1, lint now includes scripts, Dependabot checks github-actions and npm weekly, and test runs set git author/committer identity.
Version scripts
scripts/check-version-sync.mjs, scripts/bump-version.mjs, package.json
New CLIs verify or update version fields across package.json and the .claude-plugin manifests, and package.json adds scripts to run them.
CI workflow
.github/workflows/ci.yml
A new CI workflow runs on pull requests and pushes to main with Node 20 and 22, pnpm install, version sync checks, typecheck, lint, tests, and build.
Release workflow
.github/workflows/release.yml
The release workflow triggers on v* tags, verifies version alignment, uploads the build artifact, publishes to npm with provenance, and creates GitHub releases with generated notes.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~45 minutes

Poem

I’m a rabbit with a versioned springy gait,
I hop through checks before I ship the crate.
With pnpm neat and tags held tight,
I nibble releases into the night. 🐰

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main additions: CI, release automation, OIDC npm publishing, and version-sync validation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/release-automation

Warning

Review ran into problems

🔥 Problems

These MCP integrations need to be re-authenticated in the Integrations settings: Linear


Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 6

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/ci.yml:
- Around line 25-30: The workflow uses floating action tags for
actions/checkout, pnpm/action-setup, and actions/setup-node, and checkout still
persists credentials. Update the .github/workflows/ci.yml job to pin each action
reference to a full commit SHA, and set persist-credentials to false on the
actions/checkout step to disable credential persistence.

In @.github/workflows/release.yml:
- Around line 25-27: The release workflow job is over-permissioned because
validation steps and publishing/release creation share the same permissions.
Split the current job in release.yml so install, lint, typecheck, and
prepublishOnly run in a read-only validation job, then move npm publish and
GitHub release creation into a separate publish job that is the only one granted
id-token: write and contents: write; use the existing workflow structure to
identify the publish-related steps and keep the rest read-only.
- Around line 56-62: The release workflow publishes to npm before confirming the
GitHub release can be created, which risks consuming the version if gh release
create fails. Update the release job around the Publish to npm and Create GitHub
release steps so it preflights for an existing release using gh release view (or
equivalent) before npm publish, and only proceeds to npm publish when the GitHub
release is confirmed safe to create.
- Around line 29-33: The release workflow is using mutable action tags for
actions/checkout, pnpm/action-setup, and actions/setup-node, which should be
pinned for a publish/release job. Update the workflow to reference immutable
commit SHAs for those action uses, keeping the same steps in the release job so
the behavior stays unchanged while the versions are locked down.
- Line 29: The checkout step in the release workflow is leaving GitHub token
credentials persisted for the rest of the job. Update the existing
actions/checkout usage to disable persisted credentials by setting
persist-credentials to false so later steps cannot reuse the token. Make this
change on the checkout step itself and keep the rest of the workflow unchanged.
- Around line 39-41: The release workflow currently upgrades npm with a floating
latest tag, which makes trusted publishing depend on future npm changes. Update
the Upgrade npm for OIDC trusted publishing step in the release workflow to
install a fixed compatible npm 11.x version instead of npm@latest, using the
existing release job step as the place to pin it.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro

Run ID: d0796cca-9dc6-4a28-94f5-e0a5a4223c5d

📥 Commits

Reviewing files that changed from the base of the PR and between 3a7be4d and b963d22.

📒 Files selected for processing (6)
  • .github/dependabot.yml
  • .github/workflows/ci.yml
  • .github/workflows/release.yml
  • package.json
  • scripts/bump-version.mjs
  • scripts/check-version-sync.mjs

Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/release.yml Outdated
Comment thread .github/workflows/release.yml
Comment thread .github/workflows/release.yml
Comment thread .github/workflows/release.yml Outdated
Comment thread .github/workflows/release.yml Outdated
promote and e2e tests spawn 'git commit' in clones that have no local identity. GitHub runners set no identity and disable auto-detect, so those commits exited 1 — the tests failed only in CI, not locally where git auto-derives an identity. Set GIT_AUTHOR_*/GIT_COMMITTER_* via vitest test.env so the suite is self-contained anywhere. Verified: full 185-test suite passes with global + system git identity removed.
- pin all actions to commit SHAs (+ persist-credentials: false on checkouts)
- split release into a read-only verify job and a minimal privileged publish job (least-privilege OIDC), passing the built dist as an artifact
- publish with --ignore-scripts; pin npm to 11.5.1 for OIDC trusted publishing
- idempotent publish (skip if version already on the registry) and idempotent GitHub release
- publish job re-validates the tag against all version sources before shipping, so the token-holding job self-validates
Favor readable, Dependabot-maintained major version tags over SHA pins. All other hardening (persist-credentials, verify/publish split, OIDC provenance, npm pin, idempotency, publish-job version re-check) is unchanged.
Replace the placeholder author/committer with Hrithik <hrithik@robotostudio.com> so promote/e2e test commits are attributed to the maintainer.
@voidhrithik
voidhrithik merged commit c5c631e into main Jun 25, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant