ci: fix broken install, bump to Node 22/24, publish via OIDC - #18
Merged
Merged
Conversation
pnpm-workspace.yaml (added in 9ad1735) has no packages field, which pnpm 8 rejects outright - every CI run died at install, never reaching tests. - pin pnpm via packageManager (11.5.1); lockfile is v9, needs pnpm >=9 - test matrix 20 -> 22/24; checkout v7, setup-node v7, action-setup v6 - publish with npm trusted publishing (OIDC), drop NPM_TOKEN + .npmrc.ci - add typecheck script; scope tsconfig include to src to fix TS6059 - point types/exports at dist (types/ is never emitted) Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Reusable workflows cannot elevate permissions, and id-token is never granted by default - without this the OIDC publish would fail on the first release. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Path filters excluded .github and pnpm-*.yaml, so the workspace-config break landed on main without CI ever running. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
CI has been red since
9ad1735. It was never a test failure — every run died atpnpm install, before tests ran:pnpm-workspace.yamlwas added with only anallowBuilds:key. pnpm 8 (pinned in CI) rejects a workspace file with nopackages:field. Local pnpm 11 accepts it, so it only broke on push.Note: there are currently no test files in the repo, so
jest --passWithNoTestsexits 0 locally. Nothing was failing locally.Install chain
packageManager: pnpm@11.5.1. The lockfile is v9, so pnpm 8 would have failed--frozen-lockfileimmediately after the workspace error regardless.20→22, 24;checkout@v7,setup-node@v7,action-setup@v6. Clears the Node 20 runner deprecation warnings.@tsconfig/node20→@tsconfig/node22,@types/node ^22,engines: node >=22.OIDC publishing
Completes the work started on the (now deleted)
oidcbranch and wires it to the npmjs.org trusted-publisher config forservice_publish.yml.id-token: writeon the reusable workflow and on both caller jobs. Theoidcbranch only had the former. Per GitHub docs, reusable-workflow permissions "can only be maintained or reduced—not elevated", andid-tokenis never granted by default — so caller-side grants are required or the first release fails.oidcbranch also keptversion: 8. Verified against the shipped binaries that pnpm 10.34.5 has no OIDC support; only 11.x implements theACTIONS_ID_TOKEN_REQUEST_URLexchange..npmrc.ci: it injected an empty${NPM_TOKEN}and pointed at the legacyregistry.yarnpkg.commirror, which trusted publishing can't use.pnpm publish --dry-runnow resolves toregistry.npmjs.org.secrets: inherit— no workflow consumes a secret anymore.Incidental fixes
Path filters excluded CI config.
tests.ymlonly matched**.js/.ts/.tsx/.json, so.github/**andpnpm-*.yamlchanges never triggered CI — which is precisely how the broken workspace file reachedmainuntested. Added those paths; confirmed by watching a workflow-only commit trigger a run.Dangling type entrypoints.
types/is never emitted by the build, butpackage.jsonhad"types": "./types/index.d.ts", a./typesexport subpath, andtypesinfiles. Consumers onmoduleResolution: noderesolved to nothing. Repointed atdist/; verified withpnpm pack.tsc --noEmitwas broken.rootDir: ./srcconflicted with the default include glob (TS6059). Scopedincludetosrcand added atypecheckscript, now run in CI.Verification
--frozen-lockfileinstall → typecheck → test → build.pnpm packcontents match every path the manifest references.Not verified: the OIDC publish itself only runs on
v*tags, so it can't be exercised until the next release. Everything up to the publish step is verified.Follow-ups
NPM_TOKENrepo secret is now unused and can be deleted.🤖 Generated with Claude Code