feat: publish SDK and CLI with provenance - #1065
Conversation
|
@Ayfataan Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
p3ris0n
left a comment
There was a problem hiding this comment.
Review
This is the right shape for #970, and I am not merging it.
What matches the issue:
.github/workflows/release.ymlruns only onpushtomain. There is nopull_requesttrigger, so pull requests do not publish.- The publish commands use
npm publish --provenance, the workflow setsid-token: write, and the oldNPM_TOKENpublish workflows are removed. No npm token is committed. - Changesets is the versioning tool.
.changeset/README.mdsays so, and.changeset/initial-public-release.mdis a real changeset for@bc-forge/sdkand@bc-forge/cli. - SDK and CLI are public (
publishConfig.access: public, CLIprivate: false). SDK is published before the CLI, which now depends on@bc-forge/sdk^0.1.0.
What does not meet the acceptance criteria yet:
- The release job installs Node 20.
@changesets/cli@3.0.3declaresnode: ^22.11 || ^24 || >=26. On Node 20 the version step will not run, so Changesets never writesCHANGELOG.mdor bumps the version. Pin the release job to Node 22.11 or newer. - The action's
publishscript callsnpm publishfor both workspaces whenevermainhas no pending changeset. After the first successful publish, every later push tomainpublishes the same version again and the workflow fails. Runchangeset publishwith provenance enabled (npm config set provenance true, orNPM_CONFIG_PROVENANCE=true) so a push with nothing new to release does not fail.
CI is also still in progress (Smart Contracts (Rust) and SDK Bindings Staleness). Holding merge until the release job can actually version, write the changelog, and publish once.
…lish Co-authored-by: Cursor <cursoragent@cursor.com>
p3ris0n
left a comment
There was a problem hiding this comment.
Review
The release job is Node 22 and publishes with changeset publish plus provenance, so a push with no pending changeset does not republish. Approving once CI is green.
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
p3ris0n
left a comment
There was a problem hiding this comment.
Review
This covers #970.
.github/workflows/release.yml runs only on push to main, uses Node 22, and publishes through changesets/action with id-token: write and npm config set provenance true. There is no pull-request publish trigger and no committed npm token. The old NPM_TOKEN publish workflows are removed. Changesets is documented in .changeset/README.md, and .changeset/initial-public-release.md is the changeset that versions @bc-forge/sdk and @bc-forge/cli and writes their changelogs on the release commit. changeset publish no-ops when nothing is pending, so later pushes to main do not republish the same version.
CI is green and the branch merges cleanly. Approving and merging.
Summary
Validation
Closes #970