Skip to content

ci: harden trusted npm publication - #2

Merged
ardasevinc merged 3 commits into
mainfrom
ci/harden-npm-publish
Jul 17, 2026
Merged

ci: harden trusted npm publication#2
ardasevinc merged 3 commits into
mainfrom
ci/harden-npm-publish

Conversation

@ardasevinc

@ardasevinc ardasevinc commented Jul 17, 2026

Copy link
Copy Markdown
Owner

Summary\n\n- pin npm 11.17.0 for deterministic trusted publishing\n- correctly distinguish absent npm versions during immutable-version preflight\n- verify published SHA-1 and SHA-512 registry digests\n- smoke the exact launcher and native package from the public registry\n\n## Verification\n\n- actionlint .github/workflows/*.yml\n- git diff --check\n- exercised the absent-version branch against npm\n

Summary by CodeRabbit

  • Bug Fixes

    • Improved release consistency by standardizing the npm tooling used during publishing.
    • Added verification to ensure published package artifacts exactly match the release contents.
    • Added post-release checks confirming the published package can be installed and its command-line interface starts correctly.
  • Chores

    • Strengthened automated release safeguards to detect packaging or registry discrepancies before completion.

@coderabbitai

coderabbitai Bot commented Jul 17, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@ardasevinc, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 51 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 6db8f3ce-1c15-4fd7-b382-ed25d2f521f8

📥 Commits

Reviewing files that changed from the base of the PR and between 75b3938 and 4eaf67f.

📒 Files selected for processing (3)
  • .github/workflows/publish.yml
  • internal/stageinput/input.go
  • internal/stageinput/input_test.go
📝 Walkthrough

Walkthrough

The CI and publishing workflows pin npm 11.17.0, disable package-manager caching, tighten preflight integrity handling, verify registry checksums after publishing, and smoke-test the exact published package.

Changes

npm publishing controls

Layer / File(s) Summary
Pin npm across workflows
.github/workflows/ci.yml, .github/workflows/publish.yml
Disables npm package-manager caching and installs npm 11.17.0 globally in the relevant jobs.
Tighten preflight integrity checks
.github/workflows/publish.yml
Uses successful npm view metadata retrieval as the condition for integrity comparison.
Verify published registry artifacts
.github/workflows/publish.yml
Retries registry metadata retrieval, compares shasum and integrity with local values, and smoke-tests the exact published package.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant PublishWorkflow
  participant NpmRegistry
  participant SmokeEnvironment
  PublishWorkflow->>NpmRegistry: Fetch published dist metadata with retries
  NpmRegistry-->>PublishWorkflow: Return shasum and integrity
  PublishWorkflow->>PublishWorkflow: Compare registry values with local tarball values
  PublishWorkflow->>SmokeEnvironment: Install mattermost-cli at the published version
  SmokeEnvironment->>SmokeEnvironment: Run mm --version and mm --help
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the main change: hardening trusted npm publication in CI workflows.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/harden-npm-publish

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/publish.yml:
- Around line 129-133: Update the npm view invocation in the publish retry loop
to include the --prefer-online option, ensuring each attempt fetches the package
state from the registry instead of using cached responses. Preserve the existing
retry, error suppression, and sleep behavior in the loop.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: f4a9ca86-88a1-4f76-9a2e-972c19924f10

📥 Commits

Reviewing files that changed from the base of the PR and between 17ad658 and 75b3938.

📒 Files selected for processing (2)
  • .github/workflows/ci.yml
  • .github/workflows/publish.yml

Comment thread .github/workflows/publish.yml
@ardasevinc
ardasevinc merged commit 60b7300 into main Jul 17, 2026
3 checks passed
@ardasevinc
ardasevinc deleted the ci/harden-npm-publish branch July 17, 2026 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant