| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Add a trusted-publishing workflow for published releases with explicit-tag recovery, preflight asset validation, and integrity-checked idempotent reruns. Document npm trusted-publisher setup and the current release-asset blocker. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 23fc3b8d-7678-46d3-9fe7-875d8311b526
Select only newly prefixed publishable npm tarballs, leave legacy launcher archives untouched, and reject old releases without the complete new asset set. Cover mixed and legacy-only release fixtures. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 23fc3b8d-7678-46d3-9fe7-875d8311b526
There was a problem hiding this comment.
The dist-tag recheck has a race that can still move a channel backward during concurrent external publication.
Review effort: Balanced
Findings: 1
Adds secure npm publication from GitHub release tarballs with validation and recovery safeguards.
Changes:
| File | Description |
|---|---|
| .github/workflows/publish-npm.yml | Defines the trusted publishing workflow. |
| script/publish-npm-release.mjs | Validates and publishes nine npm packages. |
| test/publish-npm-release.test.mjs | Tests validation, recovery, and publishing behavior. |
| README.md | Documents setup and cutover requirements. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Sorry, something went wrong.
| const tags = JSON.parse(run("npm", ["view", item.name, "dist-tags", "--json", "--registry", "https://registry.npmjs.org"])); | ||
| if (item.tag === channel && tags[channel] && compareVersions(tags[channel], version) > 0) { | ||
| item.tag = `release-${version.replaceAll(".", "-")}`; | ||
| } | ||
| run("npm", ["publish", item.file, "--ignore-scripts", "--access", "public", "--tag", item.tag, "--registry", "https://registry.npmjs.org"]); |
Require an operator-confirmed cutover before publishing with channel tags; document retirement and draining of the old publisher and correct the recheck comment. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 23fc3b8d-7678-46d3-9fe7-875d8311b526
| Back | FazBrowse Home | New Git URL |
Why
npm publishing should be triggered by the published GitHub release in github/copilot-cli, with an explicit-tag manual recovery path. npm auth uses trusted publishing (OIDC), not an npm token. The runtime repository's internal feed and ancillary release jobs remain separate; its public release is published only after assets are complete.
What changed
Validation
Required setup / cutover blocker
Configure npm trusted publishing with direct npm publish permission for all nine @github/copilot* packages, using repository github/copilot-cli and workflow filename publish-npm.yml. The runtime release artifact producer must attach the nine actual npm package tarballs under the new npm-github-copilot- asset names while preserving existing assets. Do not cut over runtime npm publication until this PR is merged, all nine npm trusted publishers are configured, and the new release assets are present.