This repository publishes one npm package, react-native-ease. The example and
documentation site are not published to npm. Keep this document aligned with
the Release workflow.
Start from reviewed, current main. Check npm before choosing a version; a Git
tag or GitHub release does not prove that a package was published.
git fetch origin --tags
npm view react-native-ease dist-tags --json
npm view react-native-ease versions --jsonUse semantic versions. Prereleases such as X.Y.Z-beta.N publish to next;
stable versions publish to latest.
Run the package checks before starting release-it:
yarn install --immutable
yarn format:write
yarn lint
yarn test
yarn build
rm -rf artifacts
mkdir artifacts
npm pack --pack-destination artifacts
node scripts/check-package.mjs artifacts/react-native-ease-X.Y.Z.tgz
node scripts/check-release.mjs vX.Y.ZCI also builds the Android, iOS, and tvOS examples. Device behavior affected by the release still needs device validation.
-
Run
yarn release X.Y.Zfrom currentmain.release-itcreates the release commit and immutablevX.Y.Ztag, pushes them, and creates the GitHub release. It does not publish to npm locally. -
The tag starts the Release workflow. It reruns the complete CI suite for the exact tag, builds and validates the npm tarball, and rejects a tag that differs from
package.jsonor is not contained inorigin/main. -
Review the checks and approve the protected
releaseenvironment. The publish job downloads and publishes the exact tarball verified by the package job with npm provenance. -
Confirm the package version, integrity, and dist-tag:
npm view react-native-ease@X.Y.Z version dist.integrity --json npm view react-native-ease dist-tags --json
The workflow safely skips an already-published version only when the registry's integrity matches the candidate tarball. A rerun for an older version does not move a newer dist-tag backward.
- If authentication fails, verify the npm publisher's organization, repository, workflow filename, and environment. Do not add a long-lived npm token as a workaround.
- Retry a failed publish with
gh run rerun RUN_ID --failed. This reuses the inspected tarball, retained for seven days, without repeating native CI. - npm processing can take several minutes. The workflow allows approximately ten minutes for verification after acceptance. If verification times out, inspect the exact npm version before retrying with the same artifact.
- If the artifact has expired, rerun all jobs. A rerun uses the original workflow revision, including its checkout and scripts. Merging a workflow fix does not update an existing run.
- Never move an already-published tag. npm versions cannot be overwritten; publish a new version for corrections to a published package.
- An existing version is skipped only when its integrity matches the saved
tarball. This does not change
latestornext.
Adding this workflow does not publish anything. Publication requires a matching
v* tag push, successful CI, and approval of the protected release environment.