chore: automate npm publishing with trusted provenance - #779
Merged
Merged
Conversation
This reverts commit b0d5d20.
Merged
janicduplessis
requested changes
Sep 28, 2026
| `release` environment, it publishes the saved tarball through npm trusted | ||
| publishing with provenance. Stable releases use `latest`; prereleases use `next`. | ||
|
|
||
| ## One-time setup |
Collaborator
There was a problem hiding this comment.
I think we can remove this, the agent doesn't need to know and it will already be setup
janicduplessis
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Publish npm releases from v* tags through GitHub Actions and npm trusted publishing, following the Hinges release flow. Package version remains 5.10.0; the separate version bump is in #780.
The workflow validates release metadata and the tarball, runs the existing JavaScript and Android/iOS checks on the same commit, then publishes after release-environment approval. There are no manual or dry-run triggers. Normal PR CI tests the release safeguards and inspects the package.
Retained safeguards beyond the Hinges flow:
Correct repository URL casing for provenance and document tagging and recovery in RELEASE.md. Local npm publication remains disabled in the existing release-it configuration.
Validation: nine release-safety tests, metadata validation, actionlint on all four affected workflows, Prettier, and git diff --check pass after simplification. Earlier validation also passed formatting, ESLint, TypeScript, 26 Jest tests, 11 snapshots, library build, and inspection of the 183-file tarball. Hosted CI runs on the updated head.
External setup is complete: npm trusted publisher appandflow/react-native-safe-area-context / release.yml / release with direct npm publish permission; GitHub release environment permits v* tags and requires approval. Merging this PR does not publish. The next intentional release will verify OIDC publication end to end.