Skip to content

feat(release): automate cross-platform npm publication - #36

Merged
hyfdev merged 10 commits into
mainfrom
codex/align-napi-platforms
Aug 18, 2026
Merged

hyfdev merged 10 commits into
mainfrom
codex/align-napi-platforms

Conversation

@hyfdev

@hyfdev hyfdev commented Aug 16, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • align @taffyjs/node with the 13 native targets maintained by the pinned napi-rs package template while keeping ordinary CI limited to Linux x64 GNU and Windows x64 MSVC runtime tests
  • license TaffyJS under MIT and stage 17 public packages as two independent exact-version groups: 15 Core packages and 2 Yoga packages
  • add manually dispatched Publish Core and Publish Yoga workflows that run publication-only builds and Wasm verification, plan versions, assemble and install final tarballs, publish through npm Trusted Publishing, and create GitHub Releases with generated notes
  • add a resumable one-time npm bootstrap that creates 0.0.0-bootstrap.0 placeholders and configures OIDC trust; the first stable release for each group is 0.0.1

Release model

Source manifests remain private at 0.0.0; only verified staging manifests become public. Core keeps Node, Wasm, and all 13 native binding packages on one exact version. Yoga and Yoga Wasm share a separate version and retain exact dependencies on the latest complete Core release.

Ordinary CI runs native tests only on Linux x64 GNU and Windows x64 MSVC, plus Node and Rust static checks on Linux. It does not build macOS, Wasm, or release artifacts. Dispatching one workflow from main is the only normal human release step. Both publication workflows run the complete Wasm package graph before assembly; Core publication additionally builds the full 13-target native matrix.

Build and assembly jobs have read-only repository access and no npm identity; only the final publish job receives id-token: write. Publication is resumable by tarball integrity, rejects conflicting registry bytes or tag identities, and creates the GitHub tag and release only after the complete npm group passes its registry smoke test.

Validation

  • pnpm exec vp run check
  • pnpm exec vp run check:wasm
  • pnpm exec vp run check:release
  • actionlint 1.7.12 over every workflow
  • local native, Wasm, Yoga, and Yoga Wasm builds
  • assembled all 17 stable tarballs; verified exact package and native artifact sets, MIT contents, exact dependencies, loader versions, and repeatable integrity
  • installed Core and Yoga bundles in fresh npm consumers with NAPI_RS_ENFORCE_VERSION_CHECK=1
  • npm publish --dry-run --json --access public for all 17 stable tarballs
  • bootstrap tarball dry-run plus npm Trusted Publishing configuration dry-run

Adversarial review

Two independent reviewers examined the package/platform path and the publication/security path in each of two full rounds. Findings included a staged loader version mismatch, remote tag identity and retry gaps, unsafe bootstrap partial-failure behavior, GitHub Release recovery, and workflow-dispatch shell injection. The final CI-boundary delta received an additional two-reviewer check; its structural gate was strengthened against commented or detached verification jobs and retested with the original bypass variants. Every finding is closed.

No npm package, Trusted Publisher, tag, or GitHub Release was created by this PR. The remaining external proof is the first real GitHub-hosted publication run, including npm OIDC and the FreeBSD VM artifact transfer.

@hyfdev
hyfdev force-pushed the codex/align-napi-platforms branch from 0deef1f to 8f3112e Compare August 18, 2026 08:01
@hyfdev hyfdev changed the title feat(node): align native targets with napi-rs feat(release): automate cross-platform npm publication Aug 18, 2026
@hyfdev
hyfdev marked this pull request as ready for review August 18, 2026 12:25
Copilot AI lite review requested due to automatic review settings August 18, 2026 12:25
@hyfdev
hyfdev merged commit 5a0900a into main Aug 18, 2026
6 checks passed
@hyfdev
hyfdev removed the request for review from Copilot August 18, 2026 12:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant