Publish #243
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| package: | |
| description: "Which package set to publish" | |
| required: true | |
| type: choice | |
| options: | |
| - bailian-cli | |
| - knowledge-studio-cli | |
| - bailian-kb-dsh | |
| mode: | |
| description: "Publish mode" | |
| required: true | |
| type: choice | |
| options: | |
| - channel | |
| - stable | |
| channel: | |
| description: "Required when mode=channel. npm dist-tag only (lowercase, digits, dashes), e.g. mcp / plugin / sync-release. bailian-cli binary CDN always overwrites sync-release.json; knowledge-studio-cli and bailian-kb-dsh are npm-only." | |
| required: false | |
| type: string | |
| concurrency: | |
| group: publish-${{ inputs.package }}-${{ inputs.mode }}-${{ inputs.channel }} | |
| cancel-in-progress: false | |
| jobs: | |
| publish-stable: | |
| if: inputs.mode == 'stable' && inputs.package != 'bailian-kb-dsh' | |
| name: publish stable (${{ inputs.package }}) to npm + binary + tag | |
| runs-on: ubuntu-latest | |
| environment: production # Required Reviewers gate | |
| permissions: | |
| contents: write # push tag + create GitHub Release with binary assets | |
| id-token: write # OIDC for npm Trusted Publishing + provenance | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: pnpm/action-setup@v6 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: "24" | |
| cache: pnpm | |
| registry-url: "https://registry.npmjs.org/" | |
| - name: Install gitleaks | |
| run: | | |
| set -euo pipefail | |
| GITLEAKS_VERSION=8.21.2 | |
| curl -sSfL \ | |
| "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \ | |
| | sudo tar -xz -C /usr/local/bin gitleaks | |
| gitleaks version | |
| - name: Ensure zip and tar (per-platform binary archives) | |
| run: sudo apt-get update && sudo apt-get install -y zip | |
| # bun build --compile leaves an invalid darwin linker signature. rcodesign | |
| # re-signs those Mach-O files on the Linux runner (binary-codesign.mjs). | |
| - name: Install rcodesign (ad-hoc sign darwin binaries) | |
| run: | | |
| set -euo pipefail | |
| RCODESIGN_VERSION=0.29.0 | |
| asset="apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl.tar.gz" | |
| curl -fsSL -o "/tmp/${asset}" \ | |
| "https://github.com/indygreg/apple-platform-rs/releases/download/apple-codesign/${RCODESIGN_VERSION}/${asset}" | |
| tar -xzf "/tmp/${asset}" -C /tmp | |
| sudo install -m 755 \ | |
| "/tmp/apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl/rcodesign" \ | |
| /usr/local/bin/rcodesign | |
| rcodesign --version | |
| - run: pnpm install --frozen-lockfile | |
| # Binary compile uses `bun build --compile` CLI (not Bun.build API). | |
| # Pin 1.3.14: 1.2.19 grows darwin-x64 LC_CODE_SIGNATURE.datasize past | |
| # __LINKEDIT and rcodesign panics; 1.3.12 truncates arm64 signatures. | |
| # Keep this pin in sync with any local smoke tests of binary-compile.mjs. | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: "1.3.14" | |
| - name: publish-stable | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # OSS release channel goes through the FC release function (presigned | |
| # upload + reconcile + manifest.json): this repo holds no OSS | |
| # credentials, the job only presents its GitHub OIDC token (requires | |
| # id-token: write above). The trigger URL is the shared | |
| # FC_TRIGGER_URL (same function serves publish-skills; actions are | |
| # routed by URL path); leave it unset to skip the OSS channel. | |
| # Bucket / prefix / allowlists live in the FC function. | |
| FC_TRIGGER_URL: ${{ vars.FC_TRIGGER_URL }} | |
| FC_RELEASE_AUDIENCE: ${{ vars.FC_RELEASE_AUDIENCE }} | |
| # Script order: git tag, then binary GitHub Release + OSS, then npm. | |
| # OSS upload can fail on a network blip; npm must not succeed first. | |
| run: node tools/release/publish-stable.mjs ${{ inputs.package == 'knowledge-studio-cli' && '--knowledge' || '' }} | |
| publish-channel: | |
| if: inputs.mode == 'channel' && inputs.package != 'bailian-kb-dsh' | |
| name: publish channel (${{ inputs.package }}) to npm + binary | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write # create prerelease GitHub Release with binary assets | |
| id-token: write # OIDC for npm Trusted Publishing + provenance | |
| steps: | |
| - name: Require channel input | |
| if: ${{ inputs.channel == '' }} | |
| run: | | |
| echo "::error::mode=channel requires the workflow input \"channel\" (npm dist-tag, e.g. mcp / plugin / sync-release). Leave mode=stable if you do not need a dist-tag." | |
| exit 1 | |
| - uses: actions/checkout@v6 | |
| - uses: pnpm/action-setup@v6 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: "24" | |
| cache: pnpm | |
| registry-url: "https://registry.npmjs.org/" | |
| - name: Install gitleaks | |
| run: | | |
| set -euo pipefail | |
| GITLEAKS_VERSION=8.21.2 | |
| curl -sSfL \ | |
| "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \ | |
| | sudo tar -xz -C /usr/local/bin gitleaks | |
| gitleaks version | |
| - name: Ensure zip and tar (per-platform binary archives) | |
| run: sudo apt-get update && sudo apt-get install -y zip | |
| # bun build --compile leaves an invalid darwin linker signature. rcodesign | |
| # re-signs those Mach-O files on the Linux runner (binary-codesign.mjs). | |
| - name: Install rcodesign (ad-hoc sign darwin binaries) | |
| run: | | |
| set -euo pipefail | |
| RCODESIGN_VERSION=0.29.0 | |
| asset="apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl.tar.gz" | |
| curl -fsSL -o "/tmp/${asset}" \ | |
| "https://github.com/indygreg/apple-platform-rs/releases/download/apple-codesign/${RCODESIGN_VERSION}/${asset}" | |
| tar -xzf "/tmp/${asset}" -C /tmp | |
| sudo install -m 755 \ | |
| "/tmp/apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl/rcodesign" \ | |
| /usr/local/bin/rcodesign | |
| rcodesign --version | |
| - run: pnpm install --frozen-lockfile | |
| # Binary compile uses `bun build --compile` CLI (not Bun.build API). | |
| # Pin 1.3.14: 1.2.19 grows darwin-x64 LC_CODE_SIGNATURE.datasize past | |
| # __LINKEDIT and rcodesign panics; 1.3.12 truncates arm64 signatures. | |
| # Keep this pin in sync with any local smoke tests of binary-compile.mjs. | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: "1.3.14" | |
| - name: publish-channel | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # OSS release channel — same FC-backed flow as stable; no OSS | |
| # credentials in this repo (see publish-stable env notes). | |
| FC_TRIGGER_URL: ${{ vars.FC_TRIGGER_URL }} | |
| FC_RELEASE_AUDIENCE: ${{ vars.FC_RELEASE_AUDIENCE }} | |
| # Script order: binary GitHub Release + OSS, then npm. | |
| # OSS upload can fail on a network blip; npm must not succeed first. | |
| run: node tools/release/publish-channel.mjs ${{ inputs.package == 'knowledge-studio-cli' && '--knowledge' || '' }} --channel "${{ inputs.channel }}" | |
| # bailian-kb-dsh is the dsh plugin (downstream host adapter): independent version, | |
| # tsc + tsdown build, npm-only. It shares this workflow's entry UI and setup steps | |
| # but NOT publish-stable.mjs / publish-channel.mjs — those broadcast one version | |
| # across the locked bl package set and produce binary artifacts, neither of which | |
| # applies here. See docs/agents/dsh-plugin.md. | |
| publish-kb-dsh: | |
| if: inputs.package == 'bailian-kb-dsh' | |
| name: publish ${{ inputs.mode }} (bailian-kb-dsh) to npm | |
| runs-on: ubuntu-latest | |
| # stable goes through the Required Reviewers gate, same as the bl stable job; | |
| # channel stays ungated so dist-tag drops need no approval. | |
| environment: ${{ inputs.mode == 'stable' && 'production' || '' }} | |
| permissions: | |
| contents: write # push the bailian-kb-dsh-v<version> tag (stable only) | |
| id-token: write # OIDC for npm Trusted Publishing + provenance | |
| steps: | |
| - name: Require channel input | |
| if: ${{ inputs.mode == 'channel' && inputs.channel == '' }} | |
| run: | | |
| echo "::error::mode=channel requires the workflow input \"channel\" (npm dist-tag, e.g. mcp / plugin). Leave mode=stable if you do not need a dist-tag." | |
| exit 1 | |
| - uses: actions/checkout@v6 | |
| - uses: pnpm/action-setup@v6 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: "24" | |
| cache: pnpm | |
| registry-url: "https://registry.npmjs.org/" | |
| - name: Install gitleaks | |
| run: | | |
| set -euo pipefail | |
| GITLEAKS_VERSION=8.21.2 | |
| curl -sSfL \ | |
| "https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \ | |
| | sudo tar -xz -C /usr/local/bin gitleaks | |
| gitleaks version | |
| - run: pnpm install --frozen-lockfile | |
| - name: publish-kb-dsh | |
| run: node tools/release/publish-kb-dsh.mjs ${{ inputs.mode == 'channel' && format('--channel "{0}"', inputs.channel) || '' }} |