Skip to content

release: verify tokenless publishing with RC2 - #5

Merged
MuncleUscles merged 1 commit into
v0.1-devfrom
fix/verify-tokenless-rc2
Sep 9, 2026
Merged

MuncleUscles merged 1 commit into
v0.1-devfrom
fix/verify-tokenless-rc2

Conversation

@MuncleUscles

@MuncleUscles MuncleUscles commented Sep 9, 2026 •

Copy link
Copy Markdown
Member

Problem and outcome

Complete the user-requested end-to-end verification of npm trusted publishing with coordinated 0.1.0-rc.2 artifacts. No package API changes.

Delivery context

Single-repository follow-up to merged #4 (6f64319). No cross-repository dependencies. All three npm trusted publishers are configured for this repository, publish.yml, and Publish environment, allowing direct publication.

Implementation and validation

  • Bump core, React, Vue and adapter peer pins/lockfile to 0.1.0-rc.2.
  • Remove the stale release.sh requirement for the deleted branch-token workflow; preserve CI, upstream version, package availability, clean head, and tag checks.
  • Add regression coverage for the helper's tokenless path.
  • Passed typecheck, build, 60 tests, all three pack checks, actionlint, bash syntax check, and git diff --check.

Landing and verification

User explicitly requested completing verification after #4 merged. Land this exact single-PR cut after CI, then publish tag v0.1.0-rc.2 through the existing OIDC-only workflow. Verify all three registry versions/gitHeads/provenance and a successful workflow. Retire the obsolete GitHub secret and disallow bypass-token publishing after success. No full cross-repository E2E needed for release metadata/helper-only changes. Existing RC1 artifacts and tag remain unchanged.

Verified release evidence

  • Merged release commit: 6956f94a8f7d6ab5e144124db7fdab018cbd8f4f.
  • OIDC-only tag workflow 34343142807 succeeded, publishing all three 0.1.0-rc.2 packages.
  • All three registry gitHeads match the release commit; rc points to RC2; _npmUser is GitHub Actions <npm-oidc-no-reply@github.com>; each exposes SLSA provenance.
  • Independent install with lifecycle scripts disabled succeeded. npm audit signatures verified 259 registry signatures and 50 attestations across the installed dependency tree.
  • Removed the obsolete NPM_TOKEN from GitHub's Publish environment and verified the environment secret list is empty.
  • Final npm package setting changes to disallow bypass-token publishing are awaiting maintainer 2FA confirmations.

Prepare coordinated 0.1.0-rc.2 packages without API changes and remove the release helper's obsolete branch-token workflow gate. Retain CI, upstream, package, tag, and owning-branch validation; add a regression test for the OIDC release path.
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 31eca3db-16b1-49df-8121-f12bc3cff41c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@MuncleUscles MuncleUscles self-assigned this Sep 9, 2026
@MuncleUscles
MuncleUscles merged commit 6956f94 into v0.1-dev Sep 9, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant