ci: release from Bitborg with npm staged publishing #1

Sammanfogat
supernaut sammanfogade 3 incheckningar från ci/forgejo-release in i main 2026-09-26 12:27:20 +00:00
Ägare

Moves CI and releases from GitHub Actions to Forgejo Actions on Bitborg.

  • Workflows move to .forgejo/workflows and run on the ci runner.
  • changesets/action only talks to the GitHub API. A script now opens the release PR through the Forgejo API.
  • npm trusted publishing does not accept Forgejo, and 2FA-bypass tokens are being deprecated. CI stages the version with the NPM_TOKEN user secret. A maintainer approves it on npm with 2FA.
  • publishConfig.provenance is removed, because provenance cannot be generated from Forgejo.
  • Package URLs point at Bitborg.

npm already has 2.0.0, but main is at 1.1.0 with no v2.0.0 tag. The published tarball matches the current build. The pending changesets produce 2.0.0, so the first release tags v2.0.0 without staging.

See RELEASING.md for the new loop.

Moves CI and releases from GitHub Actions to Forgejo Actions on Bitborg. - Workflows move to `.forgejo/workflows` and run on the `ci` runner. - `changesets/action` only talks to the GitHub API. A script now opens the release PR through the Forgejo API. - npm trusted publishing does not accept Forgejo, and 2FA-bypass tokens are being deprecated. CI stages the version with the `NPM_TOKEN` user secret. A maintainer approves it on npm with 2FA. - `publishConfig.provenance` is removed, because provenance cannot be generated from Forgejo. - Package URLs point at Bitborg. npm already has 2.0.0, but `main` is at 1.1.0 with no `v2.0.0` tag. The published tarball matches the current build. The pending changesets produce 2.0.0, so the first release tags `v2.0.0` without staging. See `RELEASING.md` for the new loop.
supernaut lade till 2 incheckningar 2026-09-26 12:02:36 +00:00
Move workflows to .forgejo/workflows and run them on the Bitborg `ci`
runner. Replace changesets/action, which only speaks the GitHub API,
with a script that opens the release PR through the Forgejo API.

npm trusted publishing and provenance do not accept Forgejo, so publish
with an NPM_TOKEN secret and drop publishConfig.provenance. Push the
tag that changeset publish creates. Point package URLs at Bitborg.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
ci: stage npm releases for 2FA approval
Alla kontroller lyckades
CI / ci (pull_request) Successful in 22s
6998ed8856
npm is deprecating 2FA-bypass tokens for publishing. Stage the version
with a plain granular token instead, and let a maintainer approve it on
npm with 2FA. Tag on stage, and tag without staging when the version is
already on npm, which covers 2.0.0.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
supernaut tvångsskickade ci/forgejo-release från 6998ed8856
Alla kontroller lyckades
CI / ci (pull_request) Successful in 22s
till f430baa31a
Alla kontroller lyckades
CI / ci (pull_request) Successful in 23s
2026-09-26 12:04:06 +00:00
Jämför
supernaut lade till 1 incheckning 2026-09-26 12:09:03 +00:00
ci: pin Node on the Bitborg runner
Alla kontroller lyckades
CI / ci (pull_request) Successful in 47s
b36d884bd1
Bitborg runs jobs directly on a VM with an undocumented Node version. Pin the volta version with setup-node so corepack is always present.
supernaut sammanfogade incheckning f280a9e4bc till main 2026-09-26 12:27:20 +00:00
supernaut tog bort grenen ci/forgejo-release 2026-09-26 12:27:21 +00:00
supernaut refererade denna ändringsförfrågan från en incheckning 2026-09-26 12:27:22 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Inga etiketter
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
supernaut/legend-state-persist-azure-functions-plugin!1
Ingen beskrivning angiven.