Skip to content

ci(0.83): Update dependencies and revert some Copilot changes - #3109

Merged
Saad Najmi (Saadnajmi) merged 9 commits into
microsoft:0.83-stablefrom
Saadnajmi:saadnajmi/ci-updates
Sep 29, 2026
Merged

Saad Najmi (Saadnajmi) merged 9 commits into
microsoft:0.83-stablefrom
Saadnajmi:saadnajmi/ci-updates

Conversation

@Saadnajmi

Copy link
Copy Markdown
Collaborator

Summary:

Publish of 0.83.0 failed and I'm out of AI credits, so time to take matters into my own hands:

  • Update to Node 26, Yarn 4.18, and Changesets v3 just to have the nice / supported versions for critical path code
  • Revert the AI generated publishing scripts in favor of the ones we landed on main a while ago (I guess we redid some work)
  • Keep one change from Copilot, use env vars to pass access / registry to the publish command instead of setting and unsetting in discrete yml steps

Test Plan:

As with many yml changes.. hope for the best.

@Saadnajmi
Saad Najmi (Saadnajmi) requested a review from a team as a code owner September 28, 2026 21:06
@Saadnajmi Saad Najmi (Saadnajmi) changed the title Saadnajmi/ci updates ci(0.83): Update dependencies and revert some Copilot changes Sep 28, 2026
Comment thread .github/workflows/microsoft-pr.yml Outdated
Replaces the ADO-based npm publish pipeline with a GitHub Actions
workflow that uses npm Trusted Publishing (OIDC) for the main publish
step — no stored npm token required for `npm publish`.

- **`.github/workflows/microsoft-npm-publish.yml`** — New workflow
triggered on `*-stable` branch pushes. Runs in an `npm-publish` GitHub
environment (add protection rules there). Uses `id-token: write` +
`--provenance` so yarn exchanges a GitHub OIDC token directly with
npmjs.com rather than a stored secret. The `npm dist-tag add` step
(applying additional dist-tags) still requires a `NPM_TOKEN` secret
since OIDC doesn't cover that operation.

- **`.ado/scripts/configure-publish.mts`** — Added
`enablePublishingOnGitHubActions()` that writes
`publish_react_native_macos=1` to `GITHUB_OUTPUT`, so the new workflow
can gate its publish steps on this output. Previously only the ADO
`##vso[task.setvariable...]` signal was emitted.

- **`.ado/scripts/apply-additional-tags.mjs`** — Token can now come from
`NODE_AUTH_TOKEN` env var as a fallback to `--token`. When using the
env-var path (GHA), the token is not passed as a CLI argument —
`actions/setup-node` has already wired `NODE_AUTH_TOKEN` into `.npmrc`,
so `npm dist-tag add` picks it up from there. The `--token` CLI arg path
(ADO) is unchanged.

1. **npmjs.com**: add a Trusted Publisher for `react-native-macos` and
`@react-native-macos/virtualized-lists` — repo
`microsoft/react-native-macos`, workflow `microsoft-npm-publish.yml`,
environment `npm-publish`
2. **GitHub repo Settings → Environments**: create the `npm-publish`
environment with desired approval rules
3. **GitHub secret**: add `NPM_TOKEN` to that environment (granular
automation token scoped to the two packages, used only for dist-tag
operations)
4. **ADO**: once verified, disable `.ado/publish.yml`

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This reverts commit 0585c6b, but onyl changes to microsoft-pr.yml
@Saadnajmi
Saad Najmi (Saadnajmi) merged commit 66de84c into microsoft:0.83-stable Sep 29, 2026
23 of 26 checks passed
@Saadnajmi
Saad Najmi (Saadnajmi) deleted the saadnajmi/ci-updates branch September 29, 2026 21:05
@Saadnajmi
Saad Najmi (Saadnajmi) restored the saadnajmi/ci-updates branch September 29, 2026 21:05
@Saadnajmi
Saad Najmi (Saadnajmi) deleted the saadnajmi/ci-updates branch September 29, 2026 21:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants