Skip to content

chore: automate npm publishing with trusted provenance - #779

Merged
MeliValesca merged 7 commits into
mainfrom
chore/automate-npm-publishing
Sep 28, 2026
Merged

MeliValesca merged 7 commits into
mainfrom
chore/automate-npm-publishing

Conversation

@MeliValesca

@MeliValesca MeliValesca commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Publish npm releases from v* tags through GitHub Actions and npm trusted publishing, following the Hinges release flow. Package version remains 5.10.0; the separate version bump is in #780.

The workflow validates release metadata and the tarball, runs the existing JavaScript and Android/iOS checks on the same commit, then publishes after release-environment approval. There are no manual or dry-run triggers. Normal PR CI tests the release safeguards and inspects the package.

Retained safeguards beyond the Hinges flow:

  • Save the inspected tarball for seven days so publish retries use the same bytes without repeating native CI.
  • Verify registry integrity and provenance; skip an identical published version and fail on a conflict without moving newer dist-tags backward.
  • Allow ten minutes for npm processing after acceptance, based on the delay encountered during the previous library release.

Correct repository URL casing for provenance and document tagging and recovery in RELEASE.md. Local npm publication remains disabled in the existing release-it configuration.

Validation: nine release-safety tests, metadata validation, actionlint on all four affected workflows, Prettier, and git diff --check pass after simplification. Earlier validation also passed formatting, ESLint, TypeScript, 26 Jest tests, 11 snapshots, library build, and inspection of the 183-file tarball. Hosted CI runs on the updated head.

External setup is complete: npm trusted publisher appandflow/react-native-safe-area-context / release.yml / release with direct npm publish permission; GitHub release environment permits v* tags and requires approval. Merging this PR does not publish. The next intentional release will verify OIDC publication end to end.

@MeliValesca MeliValesca changed the title chore: automate npm publishing with trusted provenance chore: prepare 5.10.1 with automated npm publishing Sep 28, 2026
@MeliValesca MeliValesca changed the title chore: prepare 5.10.1 with automated npm publishing chore: automate npm publishing with trusted provenance Sep 28, 2026
Comment thread RELEASE.md Outdated
`release` environment, it publishes the saved tarball through npm trusted
publishing with provenance. Stable releases use `latest`; prereleases use `next`.

## One-time setup

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can remove this, the agent doesn't need to know and it will already be setup

@MeliValesca
MeliValesca merged commit 71b53b6 into main Sep 28, 2026
8 checks passed
@MeliValesca
MeliValesca deleted the chore/automate-npm-publishing branch September 28, 2026 21:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants