ci: migrate the release pipeline to Changesets - #585
Conversation
This reverts commit 8c84164.
|
📦 Preview published under the Install the exact version — npm i @lifi/types@0.0.0-preview-97f0520 |
|
…eck, and warn on a missing tag
|
📦 Preview published under the Install the exact version(s) — npm i @lifi/types@0.0.0-preview-e7e3988 |
Which Linear task is linked to this PR?
Part of EXBE-617
Why was it implemented this way?
Moves releases from standard-version to Changesets with the same setup as lifinance/sdk (without the Linear sync). The workflow and the preview action are the SDK files, adapted for one package.
publish.yaml(same file name, so npm trusted publishing keeps working): push tomain→ Verify (tests.yaml) → chore: version packages PR → publish with provenance,vX.Y.Ztag and GitHub Release. Version/Release run only onmain.release-previewlabel publishes0.0.0-preview-<sha>to thepreviewdist-tag and comments the install command. Thealpha/betaflow retires..npmrctopnpm-workspace.yaml;@lifi/*is exempt from the 24-hour release-age rule.version)./changesetcommand,changesetandreleaseskills, CLAUDE.md. Removed the straylaunchJoband the build-output check inprepublishOnly(CI always builds before publishing).Differences from the SDK: one package (
package.jsoninstead ofpackages/*), no pre mode, the preview publishes with the samechangeset:publishscript as a real release, the Version job also requiresmain, and checkouts do not persist the token.Security note (follow-up, not in this PR): npm trusted publishing is bound only to the file name
publish.yaml, and the preview job runs PR code withid-token: write. So anyone with write access can publish from a branch — the same as the old tag flow and the SDK. Hardening options: a protected GitHub environment bound in the npm trusted-publisher settings, and branch rules that require thecheckstatus.After merge: add a changeset (
pnpm changesetor/changeset) to every PR that changes the published package. No changeset → no release.Part 2 of 2 (part 1: #584).
Checklist before requesting a review
pnpm changeset), or this PR does not change the published package.