Skip to content

Publish npm tarballs from published Copilot CLI releases - #5000

Open
devm33 wants to merge 3 commits into
mainfrom
copilot/publish-npm-on-release
Open

devm33 wants to merge 3 commits into
mainfrom
copilot/publish-npm-on-release

Conversation

@devm33

@devm33 devm33 commented Sep 29, 2026 •

Copy link
Copy Markdown
Member

Why

npm publishing should be triggered by the published GitHub release in github/copilot-cli, with an explicit-tag manual recovery path. npm auth uses trusted publishing (OIDC), not an npm token. The runtime repository's internal feed and ancillary release jobs remain separate; its public release is published only after assets are complete.

What changed

  • Run on release: published, or manually on main with an explicit published release tag. Always check out the trusted script from main, never the release tag.
  • Download only npm-github-copilot-${VERSION}.tgz (umbrella) and npm-github-copilot-${VERSION}-${PLATFORM}.tgz (eight platform subpackages: darwin-arm64, darwin-x64, linux-arm64, linux-x64, linuxmusl-arm64, linuxmusl-x64, win32-arm64, win32-x64). Existing github-copilot-*.tgz launcher bundles remain untouched and are never published to npm.
  • Require all nine new assets. Validate the canonical tag/prerelease flag, names and SHA-256 digests, package identity and version, platform metadata, and exact launcher dependencies before any publish; manual recovery of a legacy-only release fails closed. Disable npm lifecycle scripts and publish platforms before the umbrella.
  • Compare previously published versions with npm dist.integrity for safe partial reruns. Use a version-specific npm tag for an older missing version instead of moving latest or prerelease backward. Fail explicitly when a stale dist-tag needs npm-admin repair rather than silently skipping it.
  • Document trusted-publisher configuration for all nine packages, exact workflow filename, and cutover prerequisites.

Validation

  • node --test test/publish-npm-release.test.mjs (13 passing contract tests using real test tarballs and stubbed GitHub/npm boundaries, including mixed legacy/new assets, legacy-only rejection, and mislabeled new assets).
  • Node syntax checks, YAML trigger/permission parsing, and git diff --check.
  • Confirmed the real published v1.0.90-4 release has no npm-github-copilot-*.tgz assets and is rejected before downloading or publishing.

Required setup / cutover blocker

Configure npm trusted publishing with direct npm publish permission for all nine @github/copilot* packages, using repository github/copilot-cli and workflow filename publish-npm.yml. The runtime release artifact producer must attach the nine actual npm package tarballs under the new npm-github-copilot- asset names while preserving existing assets. Do not cut over runtime npm publication until this PR is merged, all nine npm trusted publishers are configured, and the new release assets are present.

Add a trusted-publishing workflow for published releases with explicit-tag recovery, preflight asset validation, and integrity-checked idempotent reruns. Document npm trusted-publisher setup and the current release-asset blocker.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 23fc3b8d-7678-46d3-9fe7-875d8311b526
@devm33
devm33 requested review from a team and a balanced review from Copilot September 29, 2026 18:58
Select only newly prefixed publishable npm tarballs, leave legacy launcher archives untouched, and reject old releases without the complete new asset set. Cover mixed and legacy-only release fixtures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 23fc3b8d-7678-46d3-9fe7-875d8311b526

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The dist-tag recheck has a race that can still move a channel backward during concurrent external publication.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Adds secure npm publication from GitHub release tarballs with validation and recovery safeguards.

Changes:

  • Adds an OIDC-based release publishing workflow.
  • Validates package assets, metadata, integrity, and dist-tags.
  • Adds contract tests and cutover documentation.
File Description
.github/​workflows/​publish-npm.yml Defines the trusted publishing workflow.
script/​publish-npm-release.mjs Validates and publishes nine npm packages.
test/​publish-npm-release.test.mjs Tests validation, recovery, and publishing behavior.
README.md Documents setup and cutover requirements.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +170 to +174
const tags = JSON.parse(run("npm", ["view", item.name, "dist-tags", "--json", "--registry", "https://registry.npmjs.org"]));
if (item.tag === channel && tags[channel] && compareVersions(tags[channel], version) > 0) {
item.tag = `release-${version.replaceAll(".", "-")}`;
}
run("npm", ["publish", item.file, "--ignore-scripts", "--access", "public", "--tag", item.tag, "--registry", "https://registry.npmjs.org"]);
Require an operator-confirmed cutover before publishing with channel tags; document retirement and draining of the old publisher and correct the recheck comment.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 23fc3b8d-7678-46d3-9fe7-875d8311b526
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants