Skip to content

ci(release): Isolate trusted npm publishing - #7

Merged
stickerdaniel merged 2 commits into
mainfrom
release/split-0.3.1
Sep 27, 2026
Merged

stickerdaniel merged 2 commits into
mainfrom
release/split-0.3.1

Conversation

@stickerdaniel

@stickerdaniel stickerdaniel commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Problem

Tag releases install dependencies and run package code in the same job that holds npm's OIDC publishing permission. Version 0.3.0 also predates the ChatGPT.app 26.814 fix already on main.

Solution

I split the workflow into verification, a read-only release gate, and an isolated publish job. It publishes the tarball CI tested when a new version reaches main. This PR bumps Browserjack to 0.3.1.

Verification

I ran npm ci, BROWSERJACK_RELEASE_GATE_TEST=required npm run verify (71 tests), both package smoke modes, a tarball publish dry run, and the gate on the real tarball. Mutations of the publish command, npm-view decision, and tar warning guard fail the new tests. Publishing awaits the npm Trusted Publisher configuration.

Document Before After
Changelog Changelog before Changelog after
Contributing Contributing before Contributing after

Note

Isolate npm publishing behind a verified release gate in release.yml

  • Replaces tag-triggered publishing with main-branch pushes, selected PRs, and manual dispatch. Publishing now goes through a three-job pipeline: verify packages and tests on macOS, release-gate validates the tarball's metadata, archive contents, and checksum, and publish runs with only OIDC trusted-publishing permission and no source checkout or npm token.
  • The gate queries npm and authorizes publication only on an explicit E404; an existing matching version suppresses publishing and other responses fail the gate.
  • Adds an actionlint workflow for workflow-file changes, release instructions in CONTRIBUTING.md, a changelog entry, and version bumps to 0.3.1 across package.json and the plugin manifest.
  • pack-check.sh writes the tarball and a SHA-256 sidecar into BROWSERJACK_ARTIFACT_DIR when set.
  • Adds release-workflow.test.mjs with boundary assertions, mutation tests, and gate-script tests covering registry responses, archive safety, and metadata mismatches.
  • Behavioral Change: version tags no longer trigger publishing; releases publish from main-branch pushes or manual dispatch only.

Macroscope summarized 574060c.

@socket-security

socket-security Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addedyaml@​2.9.110010010090100

View full report

Comment thread .github/workflows/release.yml
@stickerdaniel
stickerdaniel marked this pull request as ready for review September 27, 2026 14:36
Copilot AI lite review requested due to automatic review settings September 27, 2026 14:36

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@macroscopeapp

macroscopeapp Bot commented Sep 27, 2026

Copy link
Copy Markdown

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This PR substantially changes production release behavior by replacing tag-triggered publishing with main-branch/manual npm publication and introducing isolated OIDC credentials, artifact transfer, and release gating. Because it changes deployment infrastructure and performs an irreversible public package publication, human review is warranted.

Notes:

  • All code in this push has already been reviewed. Approvability was decided on eligibility alone.

You can add or adjust custom eligibility rules. Learn more.

@stickerdaniel
stickerdaniel merged commit dffa72f into main Sep 27, 2026
13 checks passed
@stickerdaniel
stickerdaniel deleted the release/split-0.3.1 branch September 27, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants