fix(ci): bump release version with npm version and pass the tag via env (PER-16501) - #125
Conversation
fb9c66a to
a14220b
Compare
|
The |
zeevmoney
left a comment
There was a problem hiding this comment.
Correct fix — npm version is JSON-aware and only mutates the top-level field, and it strips a leading v from the tag. One small nit.
There was a problem hiding this comment.
Pull request overview
This PR fixes the Node SDK publish workflow’s version-bump step to avoid corrupting package.json by replacing a greedy sed rewrite with npm version, and restores the previously corrupted scripts.version entry.
Changes:
- Replace the CI
sed-based version bump withnpm version ... --no-git-tag-version --allow-same-version --ignore-scriptsto only update the top-levelversionfield. - Restore
package.json’sscripts.versionback tostandard-version.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
package.json |
Restores scripts.version to standard-version so release tooling isn’t broken. |
.github/workflows/node_sdk_publish.yaml |
Uses npm version (JSON-aware) instead of a greedy sed substitution during publish. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
The publish workflow bumped the package version with a greedy sed that matched every "version": "..." entry in package.json, corrupting scripts.version (which the prepare-release lifecycle invokes via run-s). Use npm version, which is JSON-aware and only touches the top-level field, and restore the corrupted scripts.version back to "standard-version". A post-bump assertion fails the release if scripts.version is ever clobbered again. For the repo's bare-semver release tags the bump is equivalent; npm version additionally strips a stray leading "v" and validates semver (failing fast) where the old sed wrote the tag verbatim. Flags: --no-git-tag-version (no CI commit/tag), --allow-same-version (tolerate re-runs), --ignore-scripts (don't fire the version lifecycle in CI).
a14220b to
f6ec1b8
Compare
|
Thanks — pushed an update:
Rebased on |
…asking Brings in b296d1f (npm Trusted Publishing/OIDC) and fdbc28f (API-key masking). Resolves conflict by using npm version with env-variable tag passing to prevent shell injection. Restores scripts.version guard assertion from PR. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSoip6dghQ62bLQ6GBMwTA
Add semver validation to reject npm keywords like 'minor' or 'patch' that would be accepted by npm version but are not valid release tags. Normalize and validate the tag before bumping, then assert the final version matches. Move github.event.release.prerelease interpolation to env variable to avoid shell interpretation in conditionals. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSoip6dghQ62bLQ6GBMwTA
Co-Authored-By: Codex <noreply@openai.com> Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Summary
npm version <tag> --no-git-tag-version --allow-same-version --ignore-scriptsinstead ofsed.npm versionedits only the top-levelversion. Thesedalso rewrotescripts.version, which is2.5.2onmainand was2.7.6in the published 2.7.6 package.scripts.versiontostandard-version.env:instead of${{ }}insiderun:. Before this, a tag such asv2.7.6$(cmd)would runcmdin the publish job.semver.valid()before bumping, and checks the result afterwards. Thepackage.jsonversion must equal the normalized tag, andscripts.versionmust still bestandard-version.main(merged, not rebased); npm Trusted Publishing (OIDC) and the API-key masking are unchanged.Linear
Closes #89.
Details
Tag handling (
.github/workflows/node_sdk_publish.yaml)package.jsonversionv2.7.7,2.7.72.7.7v2.7.7-rc,2.7.7-rc.12.7.7-rc,2.7.7-rc.1; a GitHub prerelease publishes with--tag rcv2.7.7+build.12.7.7(npm drops build metadata)minor,patch,from-git,release-2.7.7,vv2.7.7,2.7, empty, shell syntaxpackage.jsonchanges--ignore-scriptsskips theversionlifecycle script, sostandard-versiondoesn't run during the release.Tests (
src/tests/unit/release-workflow.spec.ts, run byyarn test:unit)The tests read the
run:blocks for "Bump version at package.json" and "Publish package to NPM" from the workflow file itself and run them in temporary git repositories. They cover:scripts.version;Testing
yarn build: passesyarn lint: 0 errors (7 existing warnings)yarn test:unit: 78 passedyarn test:module-imports: 9 passedzizmor: reports no new findings compared withmainactionlint: its one warning (SC2086, an unquoted$GITHUB_ENVin the existing "Creation env" step) is also onmainNotes
semverpackage from the installed dependencies. It is present transitively, not as a direct dependency.yarn installruns earlier in the job.prepare-releasecallsdoc:htmlanddoc:publish, which don't exist.Original change by @Kyzgor; the merge with
main, the env/validation changes and the tests were added by the maintainers.🤖 Generated with Claude Code
https://claude.ai/code/session_01PSoip6dghQ62bLQ6GBMwTA