Skip to content

feat(release)!: replace release workflow with publish action - #536

Merged
neilime merged 1 commit into
mainfrom
feat/release-publish-action
Sep 30, 2026
Merged

neilime merged 1 commit into
mainfrom
feat/release-publish-action

Conversation

@neilime

@neilime neilime commented Sep 30, 2026

Copy link
Copy Markdown
Member

Package publication currently requires a reusable workflow job. Replace it with actions/publish so consumers can run package checks, publish the validated tarball, and create a GitHub release in the order their project needs.

Changes

  • Add a Publish action that validates its inputs, downloads exactly one package tarball, and runs npm publish with registry, access, tag, provenance, and dry-run options.
  • Replace the release workflow test with Ubuntu and Windows publish dry runs, covering default and prerelease tags plus invalid-input failures.
  • Update ci-github-publish to the verified 0.29.0 commit and use its has-changes output in the documented release workflow.
  • Rewrite the release guide around one complete workflow, with setup, no-change skipping, manual force, version preparation, and recovery instructions.

Breaking change and migration

.github/workflows/release.yml is removed. Existing callers must move publication into a job using hoverkraft-tech/ci-github-nodejs/actions/publish:

  • Configure runs-on and permissions on the caller job.
  • Move publishing inputs to the action step and quote provenance and dry-run as strings.
  • Pass the optional github-token through the action input instead of a reusable-workflow secret.
  • Use the ci-github-publish release actions when GitHub release orchestration is needed.

The release guide and Publish action README include the migration and authentication details.

Validation

  • Super Linter passed across the clean PR worktree, with Trivy disabled as configured in this repository's CI.
  • actionlint passed for the changed workflows and the complete workflow in the release guide.
  • All 16 local checks of the embedded action scripts passed: input validation, direct and nested tarball discovery, ambiguous artifacts, npm arguments, and execution failures. npm execution was mocked; no package was published.
  • Formatting, whitespace, and release-guide local links and anchors passed.

The new Ubuntu/Windows integration matrix will run in PR CI; it was not executed locally.

Publish CI-produced package tarballs from a composite action so callers
can control validation and GitHub release ordering in their own jobs.
Add Linux and Windows dry-run coverage, pin ci-github-publish to 0.29.0,
and document setup, release planning, authentication, and recovery.

BREAKING CHANGE: remove .github/workflows/release.yml. Callers must use
actions/publish in a job, set runner and permissions on that job, pass
github-token as an action input, and quote boolean inputs as strings.
@github-actions

Copy link
Copy Markdown
Contributor

Super-linter summary

Language Validation result
BIOME_FORMAT Pass ✅
BIOME_LINT Pass ✅
CHECKOV Pass ✅
GITHUB_ACTIONS Pass ✅
GITHUB_ACTIONS_ZIZMOR Pass ✅
GITLEAKS Pass ✅
GIT_MERGE_CONFLICT_MARKERS Pass ✅
JSCPD Pass ✅
MARKDOWN Pass ✅
MARKDOWN_PRETTIER Pass ✅
NATURAL_LANGUAGE Pass ✅
PRE_COMMIT Pass ✅
SPELL_CODESPELL Pass ✅
YAML Pass ✅
YAML_PRETTIER Pass ✅

All files and directories linted successfully

For more information, see the GitHub Actions workflow run

Powered by Super-linter

@github-actions

Copy link
Copy Markdown
Contributor

Code Coverage Report

Coverage Results

Coverage

Metric Covered Total Percentage
Lines 2 2 100.00%
Functions 1 1 100.00%

Overall: 100.00% 🟢
🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩🟩

@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (9fdfd11) to head (722c54a).

Additional details and impacted files
@@            Coverage Diff            @@
##              main      #536   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            1         1           
  Lines            3         3           
=========================================
  Hits             3         3           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@neilime
neilime merged commit 3de6ecc into main Sep 30, 2026
87 checks passed
@neilime
neilime deleted the feat/release-publish-action branch September 30, 2026 17:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant