Skip to content

chore(release): unify on shared toolchain, drop npm publishing - #129

Merged
ryanleecode merged 3 commits into
masterfrom
chore/unify-release-tooling
Oct 6, 2026
Merged

ryanleecode merged 3 commits into
masterfrom
chore/unify-release-tooling

Conversation

@kiro-systemf

@kiro-systemf kiro-systemf Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Problem

comment-checker carried its own copy of the release tooling — a bespoke release.yml with an npm-publish job (OIDC id-token: write, a registry-url Node setup, pnpm install --registry https://registry.npmjs.org, pnpm publish --provenance) and ~12 local release/publish scripts. The shared toolchain (systemfsoftware/pnpm-release-management, Phase A, trunk prm/toolchain) now owns that lifecycle for every repo, and distribution is the Nix flake — nothing is consumed from the npm registry.

What changed

  • Thin callers. .github/workflows/release.yml now calls systemfsoftware/pnpm-release-management/.github/workflows/release.yml@prm/toolchain (tools-ref: prm/toolchain); a new changeset-check.yml calls the shared changeset gate the same way.
  • release.jsonc describes this repo to the shared tooling: the surfaces version strategy over package.json (manifest), Cargo.toml [workspace.package], the npm launcher package.json, and flake.nix; plus the distribution targets (the five launcher platform packages).
  • npm publish path removed entirely. Gone: the OIDC id-token: write, the registry-url setup (and the now-unused input on the setup-pnpm-node composite), the --registry https://registry.npmjs.org install flag (now plain pnpm install --frozen-lockfile), and the local scripts plan-release, release-version, create-or-update-release-pr, tag-released-packages, create-github-release, sync-root-version, publish-platform-stages, check-publish, publish-and-setup-npm-trust, verify-root-publish, verify-release-digests, plus the orphaned distribution-set lib.
  • Git tags stay the release record; GitHub Releases stay the published artifact. Distribution is this repository's Nix flake, built from source, at the tag.
  • Gates kept green. The tools gate drops the probes for the deleted scripts and keeps check-versions + check-matrix; check-matrix now asserts ci.yml (not the thin release.yml) drives the platform rehearsal matrix. ci.yml (rust-gate, js-gate, platform rehearsal, tools, mutation, nix flake check) is unchanged otherwise.
  • Docs rewritten; no tombstones. Deleted the vestigial nix/release-hashes.json (no flake output reads it — the flake builds from source) and the solution doc describing the removed npm-publish pipeline; rewrote the publishing narrative in .changeset/README.md, CONCEPTS.md, CONTRIBUTING.md, AGENTS.md, README.md.

Kept: publishConfig (incl. inert provenance), changesets, GitHub Releases, the Nix flake.

Behavior change worth calling out

The reusable release workflow cuts GitHub Releases from the authored changelog; it does not build or attach cross-platform binaries. Combined with npm publishing being removed, the single distribution channel is the Nix flake (source build) at the tag, which is the stated goal (Nix flakes = distribution). release.jsonc still declares the distribution targets so the plan and changeset gate know the full publishable set.

Verification

Local (this environment): deno task lint (17 files), deno check tools/*.ts (8 scripts), deno task check-matrix → ok, and YAML + release.jsonc parse clean. flake.nix has no reference to the removed nix/ dir, so flake evaluation is unaffected; nix flake check and actionlint run in CI (the local sandbox cannot provision the Nix store or a container).

Issue link

no linked issue: tracked as a Kiro Crew work item


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

kiro-systemf Bot added 3 commits October 6, 2026 18:20
Delete this repo's local release tooling and consume the shared toolchain
(systemfsoftware/pnpm-release-management) via its reusable workflows, pinned at
tools-ref prm/toolchain.

- release.yml becomes a thin caller of the shared reusable release workflow;
  changeset-check.yml a thin caller of the shared changeset gate
- release.jsonc describes the version surfaces (package.json manifest,
  Cargo.toml [workspace.package], npm launcher package.json, flake.nix) and the
  platform distribution targets
- remove the npm publish path entirely: the OIDC id-token permission, the
  registry-url setup, the --registry https://registry.npmjs.org install flag,
  and the local plan/version/tag/release/publish/verify scripts
- git tags remain the release record and GitHub Releases the published artifact;
  distribution is this repository's Nix flake, built from source, at the tag
- tools gate drops the probes for the deleted scripts and keeps check-versions
  and check-matrix; check-matrix now asserts ci.yml drives the platform matrix
- delete the vestigial nix/release-hashes.json, which no flake output reads, and
  the solution doc for the removed npm-publish pipeline; rewrite the publishing
  narrative in the changeset, concepts, contributing, agents and readme docs

publishConfig, changesets, GitHub Releases and the Nix flake are kept
The changeset gate requires an intent naming the publishable package; this is
tooling and CI only, so the intent bumps nothing
@ryanleecode
ryanleecode merged commit 31f2400 into master Oct 6, 2026
13 checks passed
@ryanleecode
ryanleecode deleted the chore/unify-release-tooling branch October 6, 2026 23:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant