Skip to content

chore(release): add CI and publish workflows, cut 0.0.2 - #5

Merged
amanmibra merged 1 commit into
mainfrom
chore/ci-publish-and-0-0-2
Sep 16, 2026
Merged

amanmibra merged 1 commit into
mainfrom
chore/ci-publish-and-0-0-2

Conversation

@buildbyjithu

@buildbyjithu buildbyjithu commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Follow-up to #4, which merged and published nothing — because nothing here publishes.

What was wrong

The repository had no .github directory at all. No CI, no release workflow. main had 22 files and zero workflows, so merging a pull request updated the branch and did nothing else.

npm agreed from the other side: one version, 0.0.1, hand-published on 2026-09-12, and no git tags or GitHub Releases since. The published tarball has no dist/agents/vapi.js — so what npm install deeptrust-ai returns today predates both the VAPI adapter (#2) and the ElevenLabs end-of-call fix (#4), with nothing signalling that the registry was behind.

What this adds

ci.yml — type check and test suite on every pull request and on main, across Node 20 and 22. Both already existed; neither was a gate. #4 merged without its own tests ever running in CI.

publish.yml — publishes on a GitHub Release using an NPM_TOKEN repository secret, and refuses a release whose tag does not match package.json rather than shipping a version nobody meant to cut. prepack still runs build and test, so a broken tree cannot reach the registry either way. No --provenance: it needs a public repository and this one is private.

scripts/sync-version.mjs — src/version.ts was a second copy of the version number kept by hand. It goes on the wire as the User-Agent, so drift misreports which client made a request, and a duplicate like that drifts the first time someone bumps in a hurry. It cannot simply be imported from package.json — tsconfig sets rootDir: src and package.json is outside it — so prebuild generates it, and CI asserts the committed file is in step.

0.0.2 — npm refuses to republish an existing version, so #4 could not have shipped without a bump regardless of automation.

Verified

--check against a stale src/version.ts:
  src/version.ts is stale: package.json says 0.0.2. → exit 1

npm run check:   ℹ pass 42   ℹ fail 0
npm pack:        dist/agents/vapi.js  13.9kB   ← absent from published 0.0.1
                 dist/version.js → export const VERSION = "0.0.2";

To ship after merging

Cut a GitHub Release tagged v0.0.2. That triggers the publish. It needs an NPM_TOKEN secret on the repository — an automation token from the npm account that owns deeptrust-ai — which I could not add and have not checked for. If it is missing the run fails at the publish step with ENEEDAUTH, harmlessly.

One judgment call for you

engines claims node >= 18, but 18 is end-of-life so the matrix is 20 and 22. Either add 18 to the matrix and hold the claim, or narrow engines to >= 20. I did not want to pick that for you — happy to do either.

🤖 Generated with Claude Code


Devin Review

The repository had no .github directory at all. Nothing ran on a pull
request and nothing published on merge, so main had carried unpublished
work since 0.0.1 went out by hand on 2026-09-12 -- the VAPI adapter and
the ElevenLabs end-of-call fix were both on main and neither was on npm,
with no signal that the registry was behind.

ci.yml runs the type check and the test suite on every pull request and
on main, across Node 20 and 22. The suite and the build already existed;
neither was a gate, so a red tree could reach main and only fail later at
publish time when prepack finally ran them.

publish.yml publishes on a GitHub Release, using the NPM_TOKEN secret. It
refuses a release whose tag does not match package.json rather than
shipping a version nobody meant to cut. No --provenance: it requires a
public repository and this one is private. prepack still runs build and
test, so a broken tree cannot reach the registry either way.

src/version.ts is now generated from package.json by prebuild instead of
being a second copy of the version number maintained by hand. It goes on
the wire as the User-Agent, so drift misreports which client made a
request, and a hand-kept duplicate drifts the first time someone bumps in
a hurry. It cannot simply be imported -- tsconfig sets rootDir to src and
package.json sits outside it -- so it is written before each build, and
CI asserts the committed file is in step.

Version bumped to 0.0.2 so there is something to publish: npm refuses to
republish 0.0.1, so the fix cannot ship without it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Devin Review: 1 bug

Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)

Devin Review

@amanmibra
amanmibra merged commit 9a8f4b1 into main Sep 16, 2026
5 checks passed
@amanmibra
amanmibra deleted the chore/ci-publish-and-0-0-2 branch September 16, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants