Skip to content

commy plugin: release 0.14.2 (#90) #8

commy plugin: release 0.14.2 (#90)

commy plugin: release 0.14.2 (#90) #8

Workflow file for this run

name: Release
# Fires on a pushed `commy-vX.Y.Z` tag and does two things in order:
#
# 1. verify-tag — re-check that the tag matches the plugin manifest version,
# so the tag can't drift from the six-site lockstep group
# (clients/claude-code/manifests.test.ts) that ci.yml already enforces on
# the tagged commit.
# 2. publish-npm — build the `@codeforbreakfast/commy-mcp` node bundle and
# publish it to npm via OIDC trusted publishing (no NPM_TOKEN). Gated on
# verify-tag, so a mismatched tag never reaches the registry.
#
# Trusted publishing means npm trusts THIS workflow (org/repo/filename), not a
# stored token: each run mints a short-lived signed OIDC token the registry
# verifies against the package's trusted-publisher config. Because the repo and
# package are public, npm attaches a provenance attestation automatically — no
# `--provenance` flag, no secret to rotate or leak. Configure the publisher
# once at npmjs.com → package settings → Trusted Publisher (GitHub Actions,
# org `CodeForBreakfast`, repo `commy`, workflow `release.yml`).
#
# The curated GitHub Release is still cut LOCALLY by the `release-plugin`
# maintainer skill once this workflow is green — this workflow does not author a
# Release (auto-generated commit-log notes are exactly what the curated Release
# replaces).
on:
push:
tags:
- 'commy-v*'
permissions:
contents: read
jobs:
verify-tag:
runs-on: ubuntu-24.04
steps:
# SHA-pinned like ci.yml; Renovate (.github/renovate.json5) bumps it.
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Verify tag matches plugin manifest
env:
TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
version="${TAG#commy-v}"
manifest="$(jq -r .version clients/claude-code/.claude-plugin/plugin.json)"
if [ "$version" != "$manifest" ]; then
echo "::error::Tag ${TAG} (version ${version}) does not match plugin.json version ${manifest} — release the bump through the release-plugin skill so the lockstep group and tag agree." >&2
exit 1
fi
echo "Tag ${TAG} matches plugin.json version ${manifest}; the curated GitHub Release is cut locally by the release-plugin skill."
publish-npm:
needs: verify-tag
runs-on: ubuntu-24.04
permissions:
contents: read
id-token: write # mint the OIDC token npm verifies for trusted publishing
steps:
# SHA-pinned like ci.yml; Renovate (.github/renovate.json5) bumps them.
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: DeterminateSystems/nix-installer-action@ef8a148080ab6020fd15196c2084a2eea5ff2d25 # v22
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: '24.18.0'
registry-url: 'https://registry.npmjs.org'
# Build the publishable bundle with the flake-pinned bun, the same way
# ci.yml runs the gate — `bun run pack:npm` stages the node-target,
# dependency-inlined server.js plus a generated package.json (version read
# from plugin.json) at packages/mcp/dist.
- name: Stage the npm package
run: nix develop .#ci --command bash -euo pipefail -c 'bun install --frozen-lockfile && bun run pack:npm'
# Trusted publishing (OIDC) needs npm >= 11.5.1; Node 24 still ships npm
# 10.x, so upgrade the publish CLI explicitly. Pinned to an exact version
# rather than `@latest`: a publish run is exactly when grabbing the newest
# release blind would defeat the supply-chain caution this repo's pinning
# buys — and any npm >= 11.5.1 satisfies OIDC, so this floor never needs
# to move on its own. Bump it deliberately when a newer npm is wanted.
- name: Upgrade npm for trusted publishing
run: npm install -g npm@11.17.0
# No NODE_AUTH_TOKEN: with id-token write + a registered trusted publisher,
# npm exchanges the OIDC token itself and attaches provenance by default.
- name: Publish to npm via OIDC trusted publishing
run: npm publish packages/mcp/dist