ci: add publish.yml, wire release-please to dispatch it - #21
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Claude finished @mark-brannan's task in 3m 46s —— View job Independent review —
|
|
Claude finished @mark-brannan's task in 3m 1s —— View job Independent review — round 2 (post-synchronize)
What changed since the last review round: commit What I checked: full diff against What I ran:
Credential/secret check: none found. Still open, non-blocking (flagged in the prior review round, unchanged in this diff): No new or blocking issues. The dispatch-and-wait loop in Note: the top-level summary is normally also posted via |
release-please cut tags and GitHub Releases but nothing published to npm. publish.yml uses OIDC trusted publishing (no stored token); release-please.yml dispatches it via workflow_dispatch after a release, matching mark-brannan/colregs's already-working pattern. Prerequisite before the first tagged release publishes: register the trusted publisher on npmjs.com (package settings -> Trusted publishers -> GitHub Actions, repo mark-brannan/wire-wright, workflow publish.yml). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Matches test.yml's checkout, which sets persist-credentials: false with the rationale that nothing in the job writes to the repository and the token should not outlive the step. The same holds here -- release-please owns the tag and the Release -- and permissions are already contents: read, so this closes the remaining gap rather than opening anything. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
b0c739a to
0229246
Compare
|
Claude finished @mark-brannan's task in 1m 38s —— View job Independent review — round 3 (post-synchronize)
What's actually new in this diff vs. the last review round: nothing in What I checked:
What I ran:
One thing I can't verify from here: the actual dispatch/wait mechanics now live entirely in the external reusable workflow ( No new or blocking issues. Nothing to add as inline comments this round — the two open threads from earlier rounds are already closed (one fixed, one declined with reasoning on the thread). |
Summary
publish.yml: npm publish via OIDC trusted publishing (no stored token), triggered only byworkflow_dispatch, gated ongithub.ref_type == 'tag'and a tag/package.json version match.release-please.yml: addactions: write, dispatchpublish.ymlafter a release is created and wait for it to succeed. Same pattern as mark-brannan/colregs's already-workingrelease-please.yml/publish.ymlpair.Prerequisite (one-time, on npmjs.com)
Before the first tagged release can publish, register the trusted publisher for wire-wright: package settings -> Trusted publishers -> GitHub Actions -> repo
mark-brannan/wire-wright, workflowpublish.yml. Until that's set, the publish job fails authentication — the correct failure mode, not a bug.Test plan
python3 -c "import yaml; yaml.safe_load(...)") on both files🤖 Generated with Claude Code