Repository navigation
chore(release): retire local npm publishing - #3381
Conversation
Size Report
Startup median (7 runs, lower is better):
|
|
|
This PR is ready at bc10e27, and I found no code problems. Not blocking: the publish and check paths in scripts/release-workspace.mjs are gone, so bindings only they used, such as rootPackage, may now be dead, and you can take or leave running the unused-code gate to drop them. Smoke Tests is still running, and the diff only touches release scripts, package.json lifecycle scripts, docs and a test comment, so none of it is on the device smoke route and any failure there is likely unrelated. There are no conflicts. I did not run any gate or the release dry run. Before merge, wait for Smoke Tests to finish green. |
bc10e27 to
d639c09
Compare
d639c09 to
c2a8364
Compare
|
I checked the dead-binding question. This layer now also documents the stable flow ( |
c2a8364 to
e957d78
Compare
There was a problem hiding this comment.
All reported issues were addressed across 6 files
Reply with feedback, questions, or to request a fix.
View guided diff | Turn on auto-fix | Re-trigger cubic
|
Thanks for the update. The patch is unchanged since the earlier review of bc10e27, and at e957d78 I found no problems in the code. The only change since then is in CONTRIBUTING.md, so the earlier clean result still stands. I did not check the live repository settings (environments, rulesets) against the One-time repository setup steps. I also did not re-run fallow or check:affected for the no-dead-code claim. Not blocking, and you can take or leave it: the edited line at https://github.com/callstack/agent-device/blob/e957d78/CONTRIBUTING.md#L110 runs well past the ~100-column wrap of the surrounding paragraph, so a rewrap would help. The Cubic docs threads still apply. The P2 on the provenance guarantee versus the local 0.0.0 placeholder publish is at #3381 (comment). There are two P3 threads, on the cached nightly wording and on "once a day" wording, at #3381 (comment) and #3381 (comment). These are docs contradictions and wording, not behaviour defects. Smoke Tests and Bundle Size were both cancelled as superseded runs and have no failed step. This PR touches release scripts, package.json scripts and docs, none of which are on the smoke-device route or in the bundled entry graph, so the cancellations do not point at this change. No conflicts. Before merge, the cancelled Smoke Tests and Bundle Size runs need to re-run green on the latest push, and the P2 provenance thread needs a fix or a reply first, since the doc now contradicts itself. The two P3 threads can wait. |
e957d78 to
d1ec5a4
Compare
There was a problem hiding this comment.
All reported issues were addressed across 2 files (changes from recent commits).
Reply with feedback, questions, or to request a fix.
View guided diff | Turn on auto-fix | Re-trigger cubic
d1ec5a4 to
c190b01
Compare
Removes the npm version and publish hooks and release-mark-dev.mjs, refuses a local npm publish from the root, and documents the release channels and the one-time onboarding of a new public package.
…fix nightly wording
c190b01 to
9d7a69a
Compare
|
The code in 9d7a69a looks good, and the docs fixes from the earlier review (#3381 (comment)) are now in. The Stable bullet in CONTRIBUTING.md separates the 20-minute CI wait from the release-environment approval, the provenance section names the 0.0.0 placeholder exception, and the Nightly bullet matches the workflow and plan logic. CI is green with 40 checks and none failing, and the docs-only change touches no code route. There are no conflicts, and nothing else stands between this PR and merge. The three review threads from the other reviewer are fixed at this head, so please resolve them: the Stable bullet wording (#3381 (comment)), the provenance wording and the Nightly wording. I did not check the live GitHub settings (environments, rulesets, npm trust) against the One-time repository setup steps, so please confirm those before the first release through the new workflow. |
Summary
Retires local publishing now that
release.yml(#3380) publishes:version,postpublish,release:publish, andrelease:mark-devscripts, andscripts/release-mark-dev.mjs.release-workspace.mjskeeps onlysyncandpack.npm publishnow refuses to run.Documentation:
vX.Y.Ztargetingmain), and dry-run channels, retries, the-devinvariant, and onboarding a new public package.npm-publishandreleaseenvironmentsv*tag rulesetgh apichecks that confirm them, and npm trustagent-device@nightly.6 files.
Validation
At
9d7a69a9f5:pnpm check:affected --runreports all runnable checks passed.