Repository navigation
chore(release): unify on shared toolchain, drop npm publishing - #129
Merged
Merged
Conversation
Delete this repo's local release tooling and consume the shared toolchain (systemfsoftware/pnpm-release-management) via its reusable workflows, pinned at tools-ref prm/toolchain. - release.yml becomes a thin caller of the shared reusable release workflow; changeset-check.yml a thin caller of the shared changeset gate - release.jsonc describes the version surfaces (package.json manifest, Cargo.toml [workspace.package], npm launcher package.json, flake.nix) and the platform distribution targets - remove the npm publish path entirely: the OIDC id-token permission, the registry-url setup, the --registry https://registry.npmjs.org install flag, and the local plan/version/tag/release/publish/verify scripts - git tags remain the release record and GitHub Releases the published artifact; distribution is this repository's Nix flake, built from source, at the tag - tools gate drops the probes for the deleted scripts and keeps check-versions and check-matrix; check-matrix now asserts ci.yml drives the platform matrix - delete the vestigial nix/release-hashes.json, which no flake output reads, and the solution doc for the removed npm-publish pipeline; rewrite the publishing narrative in the changeset, concepts, contributing, agents and readme docs publishConfig, changesets, GitHub Releases and the Nix flake are kept
The changeset gate requires an intent naming the publishable package; this is tooling and CI only, so the intent bumps nothing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
comment-checker carried its own copy of the release tooling — a bespoke
release.ymlwith an npm-publish job (OIDCid-token: write, aregistry-urlNode setup,pnpm install --registry https://registry.npmjs.org,pnpm publish --provenance) and ~12 local release/publish scripts. The shared toolchain (systemfsoftware/pnpm-release-management, Phase A, trunkprm/toolchain) now owns that lifecycle for every repo, and distribution is the Nix flake — nothing is consumed from the npm registry.What changed
.github/workflows/release.ymlnow callssystemfsoftware/pnpm-release-management/.github/workflows/release.yml@prm/toolchain(tools-ref: prm/toolchain); a newchangeset-check.ymlcalls the shared changeset gate the same way.release.jsoncdescribes this repo to the shared tooling: thesurfacesversion strategy overpackage.json(manifest),Cargo.toml[workspace.package], the npm launcherpackage.json, andflake.nix; plus thedistributiontargets (the five launcher platform packages).id-token: write, theregistry-urlsetup (and the now-unused input on thesetup-pnpm-nodecomposite), the--registry https://registry.npmjs.orginstall flag (now plainpnpm install --frozen-lockfile), and the local scriptsplan-release,release-version,create-or-update-release-pr,tag-released-packages,create-github-release,sync-root-version,publish-platform-stages,check-publish,publish-and-setup-npm-trust,verify-root-publish,verify-release-digests, plus the orphaneddistribution-setlib.toolsgate drops the probes for the deleted scripts and keepscheck-versions+check-matrix;check-matrixnow assertsci.yml(not the thinrelease.yml) drives the platform rehearsal matrix.ci.yml(rust-gate, js-gate, platform rehearsal, tools, mutation,nix flake check) is unchanged otherwise.nix/release-hashes.json(no flake output reads it — the flake builds from source) and the solution doc describing the removed npm-publish pipeline; rewrote the publishing narrative in.changeset/README.md,CONCEPTS.md,CONTRIBUTING.md,AGENTS.md,README.md.Kept:
publishConfig(incl. inert provenance), changesets, GitHub Releases, the Nix flake.Behavior change worth calling out
The reusable release workflow cuts GitHub Releases from the authored changelog; it does not build or attach cross-platform binaries. Combined with npm publishing being removed, the single distribution channel is the Nix flake (source build) at the tag, which is the stated goal (
Nix flakes = distribution).release.jsoncstill declares thedistributiontargets so the plan and changeset gate know the full publishable set.Verification
Local (this environment):
deno task lint(17 files),deno check tools/*.ts(8 scripts),deno task check-matrix→ok, and YAML +release.jsoncparse clean.flake.nixhas no reference to the removednix/dir, so flake evaluation is unaffected;nix flake checkand actionlint run in CI (the local sandbox cannot provision the Nix store or a container).Issue link
no linked issue: tracked as a Kiro Crew work item
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.