Skip to content

ci: enable trusted publishing releases - #1227

Open
Puppo wants to merge 1 commit into
fastify:mainfrom
Puppo:ci/trusted-publishing-release
Open

Puppo wants to merge 1 commit into
fastify:mainfrom
Puppo:ci/trusted-publishing-release

Conversation

@Puppo

@Puppo Puppo commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Adds a manually dispatched release workflow with patch, minor, and major choices, enabling approval-gated npm trusted publishing through the shared Fastify workflow.

The release job grants id-token: write and contents: write and pins fastify/workflows/.github/workflows/reusable-release.yml to b1a11bce713bc857e52b2231fec3c89071ad3135. The shared workflow uses the release environment, commits/pushes the version bump, publishes with npm provenance, and creates the GitHub Release. This JavaScript package needs no release build step.

Part of the JS-4 rollout batch, following the pilot in fastify/fastify-accepts#231.

Validation

Local validation with Node.js 24.21.0 and npm 11.19.0:

  • npm install --ignore-scripts --no-audit --no-fund passed.
  • npm run lint passed.
  • npm test passed.
  • Actionlint 1.7.12 passed; dispatch choices, permissions, reusable-workflow inputs, pinned SHA, and inherited release environment verified.
  • npm pack: verified index.js, types/index.d.ts, and unchanged package version 11.0.0.

Admin setup before the first release

These settings are not changed by this PR and remain unverified:

  • Configure the release environment with required reviewer team fastify/release and deployment access exclusively for branch main; check for extra branch/tag policies.
  • Confirm branch protection/rulesets allow the shared workflow to push the version commit using GITHUB_TOKEN.
  • Configure the npm GitHub Actions Trusted Publisher for @fastify/nextjs: label manual-gha-release, organization fastify, repository fastify-nextjs, workflow filename release.yml, environment release, Allow publish enabled.
  • After review, setup, and merge, validate one real release: approval gate/reviewer notifications, package contents/provenance, version commit, tag, and GitHub Release. Use manual Discord notification if necessary.

No version bump, npm publication, release dispatch, or administrative settings/access changes were performed while preparing this draft.

Additional validation notes:

  • The configured npm test builds the Next.js test/example application. This is independent of release packaging; no release:build hook was added.

@Puppo
Puppo marked this pull request as ready for review October 4, 2026 13:35
@ilteoood
ilteoood self-requested a review October 4, 2026 13:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants