Repository navigation
⚙️ setup: restore default package build channels - #13
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No blocking issues remain; the scoped changes preserve publication safeguards, with live publishing verification pending an authorized merge.
Review effort: Balanced
Findings: None
What changed in this PR
Restores development package publishing through Build Flow while preserving regular release safeguards.
Changes:
- Inherits default
devpublishing and restricts package uploads to push events. - Updates channel, installation, and recovery guidance, including preserving
latest.
| File | Description |
|---|---|
| README.md | Documents package channels and installation. |
| docs/RELEASING.md | Explains publication gates, verification, and recovery. |
| CONTRIBUTING.md | Clarifies publishing behavior by branch. |
| AGENTS.md | Aligns development and regular release instructions. |
| .github/workflows/build-flow.yml | Restores development publishing with push-only uploads. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
warengonzaga
left a comment
There was a problem hiding this comment.
Clean Workflow review completed at 497f11f091d3cd8d0fe66ebd97ae9d7a5c909cf8, against dev a53efd7552a351183f1fbdeb1fae364d04d32719.
No actionable findings remain. The caller inherits development publication while its push-only package gate preserves PR/manual validation. The immutable action pins, OIDC permissions, both-registry selection, and main release gates are unchanged. Development recovery explicitly retains the dev dist-tag.
Validation: executed the pinned orchestrator policy for dev/main pushes, PRs, and manual runs on both branches, and the actual package version detector; verified the primitive's disabled-publish exit precedes uploads. Parsed workflow comparison and diff checks passed. Build Flow CI passed on Node 22/24/26; current CodeQL analysis passed with zero findings. Copilot completed with no findings. No unresolved review threads or merge conflicts.
The neutral CodeQL comparison warning references the old build.yml scan configuration; the current build-flow.yml analysis completed successfully. Live npm/GitHub Packages development publication remains unverified until an authorized dev merge. This is a review comment, not self-approval or a merge.
🔀 Pull Request BuildPre-release package for testing PR changes 📦 Package Information
📥 Installation InstructionsNPM Registrynpm install @wgtechlabs/mdd-engine@0.1.0-pr.cab0713
npm install @wgtechlabs/mdd-engine@pr # Use dist-tagGitHub Packagesnpm install @wgtechlabs/mdd-engine@0.1.0-pr.cab0713
npm install @wgtechlabs/mdd-engine@pr # Use dist-tag🔒 Security Audit✅ No vulnerabilities found This package was built automatically by the Package Build Flow action. |
warengonzaga
left a comment
There was a problem hiding this comment.
Clean Workflow review completed for e9dc270f546248295cdede674da5cb0b44b69c9c against dev a53efd7552a351183f1fbdeb1fae364d04d32719.
No actionable findings remain in the five-file change. All default publication channels are inherited. Bun auto-detection, Node 22/24/26 validation, strict commands, smoke/audit gates, both registries, npm OIDC, and main release sequencing remain intact. Seven event/policy/version scenarios and the actual pinned CI profile resolver passed locally; independent specialist review found no issues. No unresolved review threads or merge conflicts.
Build Flow run 37460018547 passed current-head CI and CodeQL (zero findings), then published 0.1.0-pr.cab0713 to npm and GitHub Packages. npm public metadata independently confirms the version/tag; latest remains 0.1.0. Tarball integrity and all compiled files match the validated build; registry provenance identifies build-flow.yml, PR test-merge cab07132c735d44b79b2d2df768c7a1c021f5d70, and this run. The automatic PR installation comment is verified.
Limits: GitHub Packages upload succeeded, but independent package visibility lookup is blocked by the local credential lacking read:packages. Dev/manual/main channels have policy/version coverage but have not run under this revision. Copilot's prior review covers the older head; it did not automatically rerun and no review is pending. The neutral CodeQL comparison warning still references obsolete build.yml; current build-flow.yml analysis is successful. This is a review comment, not self-approval or a merge.
The caller currently disables development, PR, and manual package publication despite Build Flow enabling those channels by default. Inherit the publishing defaults so eligible dev pushes and promotion PRs publish
dev, PRs targeting dev publishpr, other PRs targeting main publishpatch, and manual runs publishwip. Main pushes retain planned regular releases underlatest.Remove redundant inputs for registry selection, OIDC, releases, Bun auto-detection, and the runtime already governed by the Node matrix/version files. Keep the project-specific package opt-in, Node 22/24/26 matrix, Bun version check and strict commands, packed-package smoke test, dependency audit, and CodeQL source-analysis mode. Update contributor/agent instructions and release guidance with exact build channels, shared tag behavior, PR commit identity, and recovery without moving
latest.Validation: executed the actual pinned orchestrator policy and package version detector for seven push/PR/manual scenarios, and the pinned CI profile resolver. All expected channels passed; automatic detection still selects Bun with the same Node matrix and validation commands. Immutable pins, workflow triggers, and permissions are unchanged; no engine source or dependency changes. Independent review and diff checks passed. Build Flow run 37460018547 passed CI on Node 22/24/26 and CodeQL with zero findings, then successfully uploaded
0.1.0-pr.cab0713to both registries. npm public metadata confirmsprpoints to that version andlatestremains0.1.0; its tarball integrity, packaged files, and provenance match the validated build and PR test-merge commit. The automatic installation comment is verified. GitHub Packages upload is confirmed by the runner; an independent visibility lookup requiresread:packages, which this local GitHub credential lacks. Other channels were verified through the pinned policy/version logic and await their own eligible events.