Skip to content

feat: publish SDK and CLI with provenance - #1065

Merged
p3ris0n merged 5 commits into
BCPathway:mainfrom
Ayfataan:feature/970-npm-provenance
Sep 29, 2026
Merged

p3ris0n merged 5 commits into
BCPathway:mainfrom
Ayfataan:feature/970-npm-provenance

Conversation

@Ayfataan

Copy link
Copy Markdown
Contributor

Summary

  • add a main-only Release workflow that runs on merged changes and publishes the SDK and CLI to npm with provenance using GitHub OIDC
  • configure Changesets to manage version bumps and update the root changelog on merged main-branch changes
  • make the SDK and CLI packages public and publish-configured, while removing the stale token-based publish jobs
  • ensure the release automation only runs on main and never on pull requests

Validation

  • npm run build --workspace @bc-forge/sdk
  • npm run build --workspace @bc-forge/cli
  • npx changeset status
  • git diff --check

Closes #970

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Ayfataan Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@p3ris0n p3ris0n left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

This is the right shape for #970, and I am not merging it.

What matches the issue:

  • .github/workflows/release.yml runs only on push to main. There is no pull_request trigger, so pull requests do not publish.
  • The publish commands use npm publish --provenance, the workflow sets id-token: write, and the old NPM_TOKEN publish workflows are removed. No npm token is committed.
  • Changesets is the versioning tool. .changeset/README.md says so, and .changeset/initial-public-release.md is a real changeset for @bc-forge/sdk and @bc-forge/cli.
  • SDK and CLI are public (publishConfig.access: public, CLI private: false). SDK is published before the CLI, which now depends on @bc-forge/sdk ^0.1.0.

What does not meet the acceptance criteria yet:

  1. The release job installs Node 20. @changesets/cli@3.0.3 declares node: ^22.11 || ^24 || >=26. On Node 20 the version step will not run, so Changesets never writes CHANGELOG.md or bumps the version. Pin the release job to Node 22.11 or newer.
  2. The action's publish script calls npm publish for both workspaces whenever main has no pending changeset. After the first successful publish, every later push to main publishes the same version again and the workflow fails. Run changeset publish with provenance enabled (npm config set provenance true, or NPM_CONFIG_PROVENANCE=true) so a push with nothing new to release does not fail.

CI is also still in progress (Smart Contracts (Rust) and SDK Bindings Staleness). Holding merge until the release job can actually version, write the changelog, and publish once.

p3ris0n
p3ris0n previously approved these changes Sep 29, 2026

@p3ris0n p3ris0n left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

The release job is Node 22 and publishes with changeset publish plus provenance, so a push with no pending changeset does not republish. Approving once CI is green.

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>

@p3ris0n p3ris0n left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review

This covers #970.

.github/workflows/release.yml runs only on push to main, uses Node 22, and publishes through changesets/action with id-token: write and npm config set provenance true. There is no pull-request publish trigger and no committed npm token. The old NPM_TOKEN publish workflows are removed. Changesets is documented in .changeset/README.md, and .changeset/initial-public-release.md is the changeset that versions @bc-forge/sdk and @bc-forge/cli and writes their changelogs on the release commit. changeset publish no-ops when nothing is pending, so later pushes to main do not republish the same version.

CI is green and the branch merges cleanly. Approving and merging.

@p3ris0n
p3ris0n merged commit dc13c55 into BCPathway:main Sep 29, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Publish the SDK and CLI to npm with provenance and a changelog

2 participants