ci(0.83): Update dependencies and revert some Copilot changes - #3109
Merged
Saad Najmi (Saadnajmi) merged 9 commits intoSep 29, 2026
Merged
Saad Najmi (Saadnajmi) merged 9 commits into
Saad Najmi (Saadnajmi) merged 9 commits into
Conversation
Danny van Velzen (dannyvv)
approved these changes
Sep 28, 2026
Saad Najmi (Saadnajmi)
force-pushed
the
saadnajmi/ci-updates
branch
from
September 28, 2026 22:11
805c5df to
2f7efe5
Compare
This reverts commit 1717529.
Replaces the ADO-based npm publish pipeline with a GitHub Actions workflow that uses npm Trusted Publishing (OIDC) for the main publish step — no stored npm token required for `npm publish`. - **`.github/workflows/microsoft-npm-publish.yml`** — New workflow triggered on `*-stable` branch pushes. Runs in an `npm-publish` GitHub environment (add protection rules there). Uses `id-token: write` + `--provenance` so yarn exchanges a GitHub OIDC token directly with npmjs.com rather than a stored secret. The `npm dist-tag add` step (applying additional dist-tags) still requires a `NPM_TOKEN` secret since OIDC doesn't cover that operation. - **`.ado/scripts/configure-publish.mts`** — Added `enablePublishingOnGitHubActions()` that writes `publish_react_native_macos=1` to `GITHUB_OUTPUT`, so the new workflow can gate its publish steps on this output. Previously only the ADO `##vso[task.setvariable...]` signal was emitted. - **`.ado/scripts/apply-additional-tags.mjs`** — Token can now come from `NODE_AUTH_TOKEN` env var as a fallback to `--token`. When using the env-var path (GHA), the token is not passed as a CLI argument — `actions/setup-node` has already wired `NODE_AUTH_TOKEN` into `.npmrc`, so `npm dist-tag add` picks it up from there. The `--token` CLI arg path (ADO) is unchanged. 1. **npmjs.com**: add a Trusted Publisher for `react-native-macos` and `@react-native-macos/virtualized-lists` — repo `microsoft/react-native-macos`, workflow `microsoft-npm-publish.yml`, environment `npm-publish` 2. **GitHub repo Settings → Environments**: create the `npm-publish` environment with desired approval rules 3. **GitHub secret**: add `NPM_TOKEN` to that environment (granular automation token scoped to the two packages, used only for dist-tag operations) 4. **ADO**: once verified, disable `.ado/publish.yml` --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This reverts commit 0585c6b, but onyl changes to microsoft-pr.yml
Saad Najmi (Saadnajmi)
force-pushed
the
saadnajmi/ci-updates
branch
from
September 29, 2026 20:31
03e63c4 to
6ea4ba4
Compare
Saad Najmi (Saadnajmi)
merged commit Sep 29, 2026
66de84c
into
microsoft:0.83-stable
23 of 26 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary:
Publish of 0.83.0 failed and I'm out of AI credits, so time to take matters into my own hands:
maina while ago (I guess we redid some work)Test Plan:
As with many yml changes.. hope for the best.