chore(release): publish v2.27.1 from the verified PR #85 merge #136
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # One-shot release orchestration. This file is changed only on the temporary | |
| # automation/release-v2.27.1-pr85 branch; master keeps its release-triggered flow. | |
| name: Publish Package to npmjs | |
| on: | |
| push: | |
| branches: | |
| - automation/release-v2.27.1-pr85 | |
| concurrency: | |
| group: publish-react-native-update-cli-v2.27.1 | |
| cancel-in-progress: false | |
| permissions: | |
| contents: read | |
| env: | |
| GH_REPO: reactnativecn/react-native-update-cli | |
| RELEASE_TAG: v2.27.1 | |
| PUBLISH_VERSION: v2.27.1 | |
| RELEASE_SHA: 51e2d32193516c82c37cdaac97ee60b1c3935941 | |
| jobs: | |
| build: | |
| if: github.repository == 'reactnativecn/react-native-update-cli' && github.ref == 'refs/heads/automation/release-v2.27.1-pr85' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| actions: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| ref: 51e2d32193516c82c37cdaac97ee60b1c3935941 | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Verify merged source and successful CI | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| set -euo pipefail | |
| test "$(git rev-parse HEAD)" = "$RELEASE_SHA" | |
| test "$(gh api "repos/$GH_REPO/actions/runs/35805733878" --jq '.head_sha + " " + .conclusion')" = "$RELEASE_SHA success" | |
| test "$(gh api "repos/$GH_REPO/releases/latest" --jq '.tag_name')" = "v2.27.0" | |
| test -z "$(git ls-remote --tags origin "refs/tags/$RELEASE_TAG")" | |
| - name: Verify npm version is available | |
| run: | | |
| python3 - <<'PY' | |
| import json, urllib.request | |
| with urllib.request.urlopen('https://registry.npmjs.org/react-native-update-cli', timeout=30) as response: | |
| metadata = json.load(response) | |
| assert metadata['dist-tags']['latest'] == '2.27.0', metadata['dist-tags'] | |
| assert '2.27.1' not in metadata['versions'], '2.27.1 already exists; do not overwrite' | |
| print('npm latest is 2.27.0; 2.27.1 is available') | |
| PY | |
| - uses: oven-sh/setup-bun@v2 | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version: '24.x' | |
| - run: bun install --frozen-lockfile | |
| - name: Prepare publish version | |
| run: bun scripts/prepublish.ts | |
| - name: Verify package version matches release tag | |
| run: | | |
| set -euo pipefail | |
| test "$(node -p "require('./package.json').version")" = "${RELEASE_TAG#v}" | |
| - name: Build package | |
| run: bun run build | |
| - name: Set up Node.js 18 for runtime verification | |
| uses: actions/setup-node@v7 | |
| with: | |
| node-version: '18.17.0' | |
| - name: Verify built CLI with Node.js 18 | |
| run: | | |
| set -euo pipefail | |
| node --version | |
| node lib/bin.js -v | |
| node lib/bin-cresc.js -v | |
| node -e "const m = require('./lib/exports.js'); if (!m) process.exit(1)" | |
| node -e "const d = require('./lib/diff.js'); if (!d.diffCommands) process.exit(1)" | |
| - name: Set up Node.js for npm publishing | |
| uses: actions/setup-node@v7 | |
| with: | |
| node-version: '24.x' | |
| registry-url: 'https://registry.npmjs.org' | |
| - name: Verify publishable package contents | |
| run: npm pack --dry-run --ignore-scripts | |
| - name: Publish to npm | |
| run: npm publish --ignore-scripts --provenance --access public --tag latest | |
| release: | |
| needs: build | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: write | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| RELEASE_NOTES: | | |
| ## English | |
| ### Fixes | |
| - Fix false Hermes base rejections when `DefineOwnById` changes operand width and the pretty disassembly truncates property names, including non-ASCII names. Full property names remain checked by the binary/raw audit. (#85) | |
| - Compare `CacheNewObject` shapes by their ordered, fully decoded property keys instead of physical table indices. Registers and cache indices remain significant; undecodable references fail safely. (#85) | |
| - Use neutral account renewal notice prefixes in English and Chinese, without changing the message body or placeholders. (#85) | |
| ### Test tooling | |
| - Require all requested positive fuzz comparisons, zero compilation failures, and at least one effective planted difference before a run can succeed. Keep unsuccessful samples for diagnosis. (#85) | |
| - Mutate actual JavaScript string tokens rather than quote-matching regex results, avoiding invalid source around escaped quotes. Reject missing, empty or invalid `--rounds` values with exit code `2` before creating output or invoking the compiler. (#85) | |
| ### Validation and compatibility | |
| - The merged source commit passed all seven CI jobs, including HBC 96 and HBC 98 compiler regressions, 50 seeded fuzz rounds per compiler, Node.js 18.17 runtime checks, and the publish dry run. The compiler matrix uses `react-native@0.77.3`, `hermes-compiler@250829098.0.16` and `hermes-compiler@250829098.0.17`. | |
| - Update-package formats, server protocols and the Node.js `>=18.17.0` requirement are unchanged. Both verification passes and the plain-compilation fallback remain in place. The dedicated `CacheNewObject` tests use synthetic binary fixtures; broader unknown-opcode auditing remains a separate follow-up. | |
| **Full changelog:** https://github.com/reactnativecn/react-native-update-cli/compare/v2.27.0...v2.27.1 | |
| ## 中文 | |
| ### 修复 | |
| - 修复 `DefineOwnById` 操作数宽度变化、pretty 反汇编截断属性名时错误拒绝正常 Hermes base 的问题,包括非 ASCII 属性名。完整属性名仍由二进制/raw 核对检查。 (#85) | |
| - `CacheNewObject` 按有序、完整解码的属性键比较 shape,不再直接比较物理表索引。寄存器和 cache 索引仍参与比较,无法解码的引用会安全失败。 (#85) | |
| - 英文和中文的账号续费提示使用中性通知前缀,不改变消息正文或占位符。 (#85) | |
| ### 测试工具 | |
| - fuzz 必须完成全部请求的正例比较、没有编译失败,并至少检查一个有效的植入差异,才能返回成功。保留未成功的样本用于诊断。 (#85) | |
| - 按真实 JavaScript 字符串 token 进行变异,替代匹配引号的正则,避免在转义引号附近生成非法源码。`--rounds` 缺值、空值或非法值在创建输出或调用编译器前以退出码 `2` 拒绝。 (#85) | |
| ### 验证与兼容性 | |
| - 合并后的源码提交通过全部七项 CI 任务,包括 HBC 96 和 HBC 98 编译器回归、每种编译器 50 轮固定种子 fuzz、Node.js 18.17 运行时检查和发布预演。编译器矩阵使用 `react-native@0.77.3`、`hermes-compiler@250829098.0.16` 和 `hermes-compiler@250829098.0.17`。 | |
| - 更新包格式、服务端协议及 Node.js `>=18.17.0` 要求均未改变。保留两轮校验和普通编译回退。`CacheNewObject` 专项测试使用合成二进制样本,更全面的未知 opcode 审计仍是独立的后续工作。 | |
| **完整变更:** https://github.com/reactnativecn/react-native-update-cli/compare/v2.27.0...v2.27.1 | |
| steps: | |
| - name: Verify npm publication | |
| run: | | |
| python3 - <<'PY' | |
| import json, time, urllib.request | |
| for attempt in range(12): | |
| with urllib.request.urlopen('https://registry.npmjs.org/react-native-update-cli/latest', timeout=30) as response: | |
| package = json.load(response) | |
| if package['version'] == '2.27.1': | |
| print(json.dumps({'name': package['name'], 'version': package['version'], 'dist': package['dist']}, indent=2)) | |
| break | |
| time.sleep(5) | |
| else: | |
| raise SystemExit('npm latest did not resolve to 2.27.1') | |
| PY | |
| - name: Publish bilingual GitHub Release at the merged commit | |
| run: | | |
| set -euo pipefail | |
| printf '%s\n' "$RELEASE_NOTES" > "$RUNNER_TEMP/release-notes.md" | |
| gh release create "$RELEASE_TAG" --repo "$GH_REPO" --target "$RELEASE_SHA" --title "$RELEASE_TAG" --notes-file "$RUNNER_TEMP/release-notes.md" --latest | |
| gh release view "$RELEASE_TAG" --repo "$GH_REPO" --json tagName,isDraft,isPrerelease,url,body | |
| test "$(gh api "repos/$GH_REPO/git/ref/tags/$RELEASE_TAG" --jq '.object.sha')" = "$RELEASE_SHA" | |
| - name: Remove the one-shot orchestration branch | |
| run: | | |
| set -euo pipefail | |
| test "$GITHUB_REF" = 'refs/heads/automation/release-v2.27.1-pr85' | |
| test "$(gh api "repos/$GH_REPO/git/ref/heads/automation/release-v2.27.1-pr85" --jq '.object.sha')" = "$GITHUB_SHA" | |
| gh api --method DELETE "repos/$GH_REPO/git/refs/heads/automation/release-v2.27.1-pr85" |