Skip to content

ci: drop the npm publish step; releases are distributed via git - #52

Merged
code-yeongyu merged 1 commit into
mainfrom
ci/publish-is-git-only
Oct 3, 2026
Merged

code-yeongyu merged 1 commit into
mainfrom
ci/publish-is-git-only

Conversation

@code-yeongyu

@code-yeongyu code-yeongyu commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Fixes #51.

  • Removed: the Publish to npm step, whose skip with exit 0 made every release look like a green publish (v0.1.4: "NODE_AUTH_TOKEN is not configured; skipping npm publish."). Also removed are id-token: write and the registry-url that only the publish used.
  • Why npm isn't the channel: the unscoped npm name belongs to another project, and docs: install from GitHub instead of npm #42 made pi install git:github.com/code-yeongyu/pi-apply-patch the documented install, which resolves the release tag.
  • Added: on a release event, the run fails when the tag is not v<package.json version>. A mismatched tag is the one release mistake that would ship the wrong code through git installs.
  • Added: a job summary stating the version is distributed via git and how to install it.
  • Kept: the build verification (frozen install, check, tests, npm pack --dry-run).

Verification

  • actionlint clean, and the YAML parses with exactly the expected steps and permissions: {contents: read}.
  • Tag check exercised both ways: v0.1.3 and v9.9.9 against package.json 0.1.4 fail with the error annotation. v0.1.4 is the matching case and passes the same comparison.
  • CHANGELOG entry under [Unreleased]. The released [0.1.4] section is untouched.

Review in cubic

The publish step skipped npm publish with exit 0 when no token was set, so
every release run showed a green publish that never happened. npm cannot be
this package's channel (the unscoped name belongs to another project, and
#42 made git the documented install path), so the step and the unused
id-token permission are removed. The workflow still verifies the build, now
fails when the release tag does not match package.json, and states the
distribution in the job summary.

Fixes #51
@code-yeongyu

Copy link
Copy Markdown
Owner Author

Lead review: PASS. Drops the npm step + id-token/registry-url (least privilege), adds a fail-closed tag==package.json version check on release (tag passed via env, not interpolated into the script), and a job summary stating git distribution. CI green on da25820. Merging with the repo's admin bypass.

@code-yeongyu
code-yeongyu merged commit 21760de into main Oct 3, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release workflow reports a green npm publish that never happens

1 participant