Skip to content

chore(release): retire local npm publishing - #3381

Merged
thymikee merged 4 commits into
feat/release-protection-checkfrom
chore/retire-local-publish
Oct 11, 2026
Merged

thymikee merged 4 commits into
feat/release-protection-checkfrom
chore/retire-local-publish

Conversation

@thymikee

@thymikee thymikee commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

Retires local publishing now that release.yml (#3380) publishes:

  • Removes the version, postpublish, release:publish, and release:mark-dev scripts, and scripts/release-mark-dev.mjs.
  • release-workspace.mjs keeps only sync and pack.
  • A root npm publish now refuses to run.

Documentation:

  • CONTRIBUTING covers the nightly, stable (publish a GitHub release tagged vX.Y.Z targeting main), and dry-run channels, retries, the -dev invariant, and onboarding a new public package.
  • A new One-time repository setup section covers:
    • the npm-publish and release environments
    • the admin-only v* tag ruleset
    • the Actions settings, and keeping release immutability off
    • the gh api checks that confirm them, and npm trust
  • The installation docs add agent-device@nightly.

6 files.

Validation

At 9d7a69a9f5:

  • pnpm check:affected --run reports all runnable checks passed.

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Size Report

Metric Base Current Diff
Installed (including dependencies) 5.16 MB 5.16 MB -352 B
Package (unpacked) 5.16 MB 5.16 MB -352 B
Package (download) 1.55 MB 1.55 MB -21 B

Startup median (7 runs, lower is better):

Scenario Base Current Diff
CLI --version 28.6 ms 29.4 ms +0.8 ms
CLI --help 87.4 ms 88.4 ms +1.0 ms

@github-actions

github-actions Bot commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-10-11 09:49 UTC

@thymikee

Copy link
Copy Markdown
Member Author

This PR is ready at bc10e27, and I found no code problems. Not blocking: the publish and check paths in scripts/release-workspace.mjs are gone, so bindings only they used, such as rootPackage, may now be dead, and you can take or leave running the unused-code gate to drop them. Smoke Tests is still running, and the diff only touches release scripts, package.json lifecycle scripts, docs and a test comment, so none of it is on the device smoke route and any failure there is likely unrelated. There are no conflicts. I did not run any gate or the release dry run. Before merge, wait for Smoke Tests to finish green.

@thymikee thymikee added the ready-for-human Valid work that needs human implementation, judgment, or maintainer merge label Oct 10, 2026
@thymikee
thymikee force-pushed the chore/retire-local-publish branch from bc10e27 to d639c09 Compare October 10, 2026 17:27
@thymikee
thymikee removed this pull request from stack #3382 October 10, 2026 17:28
@thymikee
thymikee force-pushed the chore/retire-local-publish branch from d639c09 to c2a8364 Compare October 10, 2026 17:30
@thymikee
thymikee changed the base branch from feat/release-workflow to feat/release-protection-check October 10, 2026 17:30
@thymikee
thymikee added this pull request to stack #3389 October 10, 2026 17:30
@thymikee

Copy link
Copy Markdown
Member Author

I checked the dead-binding question. rootPackage still supplies the version and the plugin dependency check in checkPublishedDependencies, and every remaining function is called. Fallow reports no unused code on this layer.

This layer now also documents the stable flow (pnpm release:promote) and a One-time repository setup section, as #3380's review asked. The top tree is unchanged from the d639c09dd3 run where check:affected --run passed.

@thymikee
thymikee force-pushed the chore/retire-local-publish branch from c2a8364 to e957d78 Compare October 10, 2026 17:42
@thymikee
thymikee marked this pull request as ready for review October 10, 2026 19:08

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 6 files

Reply with feedback, questions, or to request a fix.

View guided diff | Turn on auto-fix | Re-trigger cubic

Comment thread CONTRIBUTING.md Outdated
Comment thread website/docs/docs/installation.md Outdated
Comment thread website/docs/docs/installation.md Outdated
@thymikee

Copy link
Copy Markdown
Member Author

Thanks for the update. The patch is unchanged since the earlier review of bc10e27, and at e957d78 I found no problems in the code. The only change since then is in CONTRIBUTING.md, so the earlier clean result still stands. I did not check the live repository settings (environments, rulesets) against the One-time repository setup steps. I also did not re-run fallow or check:affected for the no-dead-code claim.

Not blocking, and you can take or leave it: the edited line at https://github.com/callstack/agent-device/blob/e957d78/CONTRIBUTING.md#L110 runs well past the ~100-column wrap of the surrounding paragraph, so a rewrap would help.

The Cubic docs threads still apply. The P2 on the provenance guarantee versus the local 0.0.0 placeholder publish is at #3381 (comment). There are two P3 threads, on the cached nightly wording and on "once a day" wording, at #3381 (comment) and #3381 (comment). These are docs contradictions and wording, not behaviour defects.

Smoke Tests and Bundle Size were both cancelled as superseded runs and have no failed step. This PR touches release scripts, package.json scripts and docs, none of which are on the smoke-device route or in the bundled entry graph, so the cancellations do not point at this change. No conflicts. Before merge, the cancelled Smoke Tests and Bundle Size runs need to re-run green on the latest push, and the P2 provenance thread needs a fix or a reply first, since the doc now contradicts itself. The two P3 threads can wait.

@thymikee thymikee removed the ready-for-human Valid work that needs human implementation, judgment, or maintainer merge label Oct 10, 2026
@thymikee
thymikee force-pushed the chore/retire-local-publish branch from e957d78 to d1ec5a4 Compare October 11, 2026 06:51

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

View guided diff | Turn on auto-fix | Re-trigger cubic

Comment thread CONTRIBUTING.md Outdated
@thymikee
thymikee force-pushed the chore/retire-local-publish branch from d1ec5a4 to c190b01 Compare October 11, 2026 06:55
Removes the npm version and publish hooks and release-mark-dev.mjs, refuses a
local npm publish from the root, and documents the release channels and the
one-time onboarding of a new public package.
@thymikee
thymikee force-pushed the chore/retire-local-publish branch from c190b01 to 9d7a69a Compare October 11, 2026 07:01
@thymikee

Copy link
Copy Markdown
Member Author

The code in 9d7a69a looks good, and the docs fixes from the earlier review (#3381 (comment)) are now in. The Stable bullet in CONTRIBUTING.md separates the 20-minute CI wait from the release-environment approval, the provenance section names the 0.0.0 placeholder exception, and the Nightly bullet matches the workflow and plan logic. CI is green with 40 checks and none failing, and the docs-only change touches no code route. There are no conflicts, and nothing else stands between this PR and merge.

The three review threads from the other reviewer are fixed at this head, so please resolve them: the Stable bullet wording (#3381 (comment)), the provenance wording and the Nightly wording.

I did not check the live GitHub settings (environments, rulesets, npm trust) against the One-time repository setup steps, so please confirm those before the first release through the new workflow.

@thymikee thymikee added the ready-for-human Valid work that needs human implementation, judgment, or maintainer merge label Oct 11, 2026
@thymikee
thymikee merged commit ab33587 into main Oct 11, 2026
40 checks passed
@thymikee
thymikee deleted the chore/retire-local-publish branch October 11, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-human Valid work that needs human implementation, judgment, or maintainer merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant