Repository navigation
chore(release): add CI and publish workflows, cut 0.0.2 - #5
Merged
Merged
Conversation
The repository had no .github directory at all. Nothing ran on a pull request and nothing published on merge, so main had carried unpublished work since 0.0.1 went out by hand on 2026-09-12 -- the VAPI adapter and the ElevenLabs end-of-call fix were both on main and neither was on npm, with no signal that the registry was behind. ci.yml runs the type check and the test suite on every pull request and on main, across Node 20 and 22. The suite and the build already existed; neither was a gate, so a red tree could reach main and only fail later at publish time when prepack finally ran them. publish.yml publishes on a GitHub Release, using the NPM_TOKEN secret. It refuses a release whose tag does not match package.json rather than shipping a version nobody meant to cut. No --provenance: it requires a public repository and this one is private. prepack still runs build and test, so a broken tree cannot reach the registry either way. src/version.ts is now generated from package.json by prebuild instead of being a second copy of the version number maintained by hand. It goes on the wire as the User-Agent, so drift misreports which client made a request, and a hand-kept duplicate drifts the first time someone bumps in a hurry. It cannot simply be imported -- tsconfig sets rootDir to src and package.json sits outside it -- so it is written before each build, and CI asserts the committed file is in step. Version bumped to 0.0.2 so there is something to publish: npm refuses to republish 0.0.1, so the fix cannot ship without it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
🔍 Devin Review: 1 bug
Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
amanmibra
approved these changes
Sep 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #4, which merged and published nothing — because nothing here publishes.
What was wrong
The repository had no
.githubdirectory at all. No CI, no release workflow.mainhad 22 files and zero workflows, so merging a pull request updated the branch and did nothing else.npm agreed from the other side: one version,
0.0.1, hand-published on 2026-09-12, and no git tags or GitHub Releases since. The published tarball has nodist/agents/vapi.js— so whatnpm install deeptrust-aireturns today predates both the VAPI adapter (#2) and the ElevenLabs end-of-call fix (#4), with nothing signalling that the registry was behind.What this adds
ci.yml— type check and test suite on every pull request and onmain, across Node 20 and 22. Both already existed; neither was a gate. #4 merged without its own tests ever running in CI.publish.yml— publishes on a GitHub Release using anNPM_TOKENrepository secret, and refuses a release whose tag does not matchpackage.jsonrather than shipping a version nobody meant to cut.prepackstill runs build and test, so a broken tree cannot reach the registry either way. No--provenance: it needs a public repository and this one is private.scripts/sync-version.mjs—src/version.tswas a second copy of the version number kept by hand. It goes on the wire as the User-Agent, so drift misreports which client made a request, and a duplicate like that drifts the first time someone bumps in a hurry. It cannot simply be imported frompackage.json—tsconfigsetsrootDir: srcandpackage.jsonis outside it — soprebuildgenerates it, and CI asserts the committed file is in step.0.0.2— npm refuses to republish an existing version, so #4 could not have shipped without a bump regardless of automation.Verified
To ship after merging
Cut a GitHub Release tagged
v0.0.2. That triggers the publish. It needs anNPM_TOKENsecret on the repository — an automation token from the npm account that ownsdeeptrust-ai— which I could not add and have not checked for. If it is missing the run fails at the publish step withENEEDAUTH, harmlessly.One judgment call for you
enginesclaimsnode >= 18, but 18 is end-of-life so the matrix is 20 and 22. Either add 18 to the matrix and hold the claim, or narrowenginesto>= 20. I did not want to pick that for you — happy to do either.🤖 Generated with Claude Code