Repository navigation
sdk: bump to 0.1.2 and finalize npm publish pipeline - #7642
Conversation
…nd PyPI) npm cmux 0.1.0-0.8.3 are taken by the CLI history and PyPI has 0.1.0-0.1.1, so 0.1.2 is the smallest version publishable on every registry. Being below npm's 0.8.3 it stays off the 'latest' tag, so 'npm i cmux' keeps installing the CLI and nothing breaks. Unified across all bindings.
…ng auth) Node 22 ships npm 10, which signs provenance but cannot authenticate the publish via OIDC trusted publishing, so the PUT is unauthenticated and 404s. npm 11.5.1+ does the OIDC token exchange for the publish.
npm refuses to implicitly move 'latest' to 0.1.2 (below the CLI's 0.8.3). Publishing under --tag sdk keeps 'npm i cmux' resolving the CLI (latest) while the SDK is installable via 'npm i cmux@sdk'.
npm --provenance rejects self-hosted runners (E422: only github-hosted runners are supported when publishing with provenance). Pin only the publish job to ubuntu-latest so the sigstore attestation verifies.
…ation) npm --provenance requires package.json repository.url to match the source repo (manaflow-ai/cmux) recorded in the sigstore attestation.
…uard npm --provenance only verifies on a github-hosted runner, so the npm publish job pins ubuntu-latest and carries a documented github-hosted-required marker. The self-hosted runner guard now skips runs-on lines with that marker; these publish jobs run only on dispatch and never enter the overflow rotation.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
📝 WalkthroughWalkthroughThis PR updates the SDK publish workflow to use a GitHub-hosted runner, upgrade npm, and publish under the ChangesSDK Publish Workflow and Guard
Package Version Bumps and Misc Config
Estimated code review effort: 3 (Moderate) | ~20 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 25✅ Passed checks (25 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Greptile SummaryBumps all SDK binding versions from 0.1.0 to 0.1.2 and finalizes the npm publish pipeline with OIDC trusted publishing and provenance attestation support.
Confidence Score: 5/5Safe to merge — all changes are version bumps, metadata additions, and CI pipeline fixes with no production code or Swift changes. The diff is entirely version bumps across binding manifests and lockfiles, npm publish workflow corrections, a targeted update to the self-hosted runner guard test, and a gitignore addition. The guard exemption mechanism is logically correct: the regex now captures trailing inline comments so the opt-out token is detectable and filterable. The --tag sdk publish strategy correctly preserves the CLI on latest. No Swift, runtime, or application logic is touched. No files require special attention. Important Files Changed
Sequence Diagram%%{init: {'theme': 'neutral'}}%%
sequenceDiagram
participant Dev as Developer
participant GHA as GitHub Actions
participant NPM as npm Registry (OIDC)
participant PyPI as PyPI (OIDC)
Dev->>GHA: "workflow_dispatch (confirm_npm_cmux=true)"
GHA->>GHA: version job — validate all bindings at 0.1.2
GHA->>GHA: bindings-e2e-typescript (self-hosted runner)
GHA->>GHA: publish job (ubuntu-latest / github-hosted-required)
GHA->>GHA: "npm install -g npm@^11.5.1"
GHA->>GHA: "npm ci && npm run build"
GHA->>NPM: npm publish --provenance --tag sdk
NPM-->>GHA: "cmux@sdk=0.1.2 published (OIDC token exchange)"
Note over NPM: latest=0.8.3 (CLI) unchanged, sdk=0.1.2 (SDK) new
Dev->>PyPI: (separate) trusted publish
PyPI-->>Dev: cmux 0.1.2 published
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
sequenceDiagram
participant Dev as Developer
participant GHA as GitHub Actions
participant NPM as npm Registry (OIDC)
participant PyPI as PyPI (OIDC)
Dev->>GHA: "workflow_dispatch (confirm_npm_cmux=true)"
GHA->>GHA: version job — validate all bindings at 0.1.2
GHA->>GHA: bindings-e2e-typescript (self-hosted runner)
GHA->>GHA: publish job (ubuntu-latest / github-hosted-required)
GHA->>GHA: "npm install -g npm@^11.5.1"
GHA->>GHA: "npm ci && npm run build"
GHA->>NPM: npm publish --provenance --tag sdk
NPM-->>GHA: "cmux@sdk=0.1.2 published (OIDC token exchange)"
Note over NPM: latest=0.8.3 (CLI) unchanged, sdk=0.1.2 (SDK) new
Dev->>PyPI: (separate) trusted publish
PyPI-->>Dev: cmux 0.1.2 published
Reviews (2): Last reviewed commit: "crates: add description/repository/homep..." | Re-trigger Greptile |
| # authenticate the publish via OIDC trusted publishing (the PUT is | ||
| # unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token | ||
| # exchange for the publish itself. | ||
| run: npm install -g npm@^11.5.1 |
There was a problem hiding this comment.
The
^11.5.1 caret range lets npm resolve any 11.x release at run time, so a future 11.x regression could silently change publish behavior. For a publish pipeline where determinism matters, pinning an exact version is safer.
| run: npm install -g npm@^11.5.1 | |
| run: npm install -g npm@11.5.1 |
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.github/workflows/sdk-publish-npm.yml:
- Around line 151-157: The npm upgrade step in the publish workflow is too
loosely versioned, which can make provenance/OIDC behavior non-reproducible.
Update the install command in the “Upgrade npm for OIDC trusted publishing” step
to pin npm to the exact 11.5.1 release instead of using the caret range, keeping
the publish job stable while preserving the existing Node 22.14.0 setup.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro
Run ID: a78ab81c-79d5-496a-a414-6b91c6c985b3
⛔ Files ignored due to path filters (2)
mux/Cargo.lockis excluded by!**/*.lockmux/bindings/typescript/package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (6)
.github/workflows/sdk-publish-npm.ymlmux/bindings/python/pyproject.tomlmux/bindings/rust/Cargo.tomlmux/bindings/typescript/package.jsontests/test_ci_self_hosted_guard.shweb/.gitignore
| - name: Upgrade npm for OIDC trusted publishing | ||
| # Node 22 bundles npm 10, which signs provenance but cannot | ||
| # authenticate the publish via OIDC trusted publishing (the PUT is | ||
| # unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token | ||
| # exchange for the publish itself. | ||
| run: npm install -g npm@^11.5.1 | ||
|
|
There was a problem hiding this comment.
📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value
Consider pinning npm to an exact version.
npm@^11.5.1 allows any 11.x release to be installed at publish time, so a future npm minor/patch could silently alter provenance/OIDC behavior on a provenance-critical publish. Pinning exactly (npm@11.5.1) keeps this job reproducible. This also addresses the zizmor adhoc-packages warning at Line 156. node-version: "22.14.0" already satisfies npm 11's >=22.9.0 requirement, so no Node change is needed.
♻️ Proposed pin
- run: npm install -g npm@^11.5.1
+ run: npm install -g npm@11.5.1📝 Committable suggestion
‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.
| - name: Upgrade npm for OIDC trusted publishing | |
| # Node 22 bundles npm 10, which signs provenance but cannot | |
| # authenticate the publish via OIDC trusted publishing (the PUT is | |
| # unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token | |
| # exchange for the publish itself. | |
| run: npm install -g npm@^11.5.1 | |
| - name: Upgrade npm for OIDC trusted publishing | |
| # Node 22 bundles npm 10, which signs provenance but cannot | |
| # authenticate the publish via OIDC trusted publishing (the PUT is | |
| # unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token | |
| # exchange for the publish itself. | |
| run: npm install -g npm@11.5.1 |
🧰 Tools
🪛 zizmor (1.26.1)
[warning] 156-156: ad-hoc installation of packages (adhoc-packages): installs a package outside of a lockfile
(adhoc-packages)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/sdk-publish-npm.yml around lines 151 - 157, The npm
upgrade step in the publish workflow is too loosely versioned, which can make
provenance/OIDC behavior non-reproducible. Update the install command in the
“Upgrade npm for OIDC trusted publishing” step to pin npm to the exact 11.5.1
release instead of using the caret range, keeping the publish job stable while
preserving the existing Node 22.14.0 setup.
Source: Linters/SAST tools
… publish requires description)
Lands the state that published cmux 0.1.2 to PyPI and npm.
sdkdist-tag sonpm i cmuxkeeps resolving the CLI (latest=0.8.3) andnpm i cmux@sdk=SDK; run the publish job on a github-hosted runner (npm --provenance rejects self-hosted); addrepository/homepageto package.json (provenance validation).github-hosted-requiredopt-out for jobs that must be github-hosted (npm provenance) and never enter the overflow rotation.Already published live: PyPI cmux 0.1.2, npm cmux@sdk 0.1.2 (both via OIDC trusted publishing + provenance).
Need help on this PR? Tag
/codesmithwith what you need. Autofix is disabled.Note
Low Risk
Changes are limited to release versions, publish workflow, and CI guard rules—no application runtime or auth logic.
Overview
Bumps mux SDK bindings from
0.1.0to0.1.2across Python (pyproject.toml), Rust (cmux-client+ lockfile), and TypeScript (package.json/ lockfile). Rust and TypeScript manifests also gainrepository/homepagemetadata for registry provenance.The
sdk-publish-npmworkflow is adjusted so live publishes succeed: the publish job runs onubuntu-latest(required fornpm --provenance), installs npm ≥ 11.5.1 for OIDC trusted publishing, and publishes with--tag sdksonpm i cmuxstill resolves the CLI onlatestwhile the SDK iscmux@sdk.test_ci_self_hosted_guard.shnow allows documentedgithub-hosted-requiredexceptions onruns-onlines so that publish job is not flagged.web/.gitignoreadds.env*.local.Reviewed by Cursor Bugbot for commit 79af23b. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Bumps the SDK bindings to 0.1.2 and finalizes the
npmpublish pipeline with provenance and OIDC trusted publishing. Adds crates.io metadata, keeps thecmuxCLI onlatest, and makes the SDK installable viacmux@sdk.Dependencies
cmux/cmux-clientversion to 0.1.2 in Python, Rust, and TypeScript bindings (manifests and lockfiles).Bug Fixes
npmpublish job onubuntu-latest(GitHub‑hosted) fornpm --provenance.npmto >= 11.5.1 to enable OIDC trusted publishing.--tag sdksonpm i cmuxkeeps resolving the CLI; usenpm i cmux@sdkfor the SDK.repository/homepageto the TSpackage.jsonanddescription/repository/homepageto the Rust crate for provenance/crates.io validation.github-hosted-required; update the guard test accordingly.Written for commit 79af23b. Summary will update on new commits.
Summary by CodeRabbit
runs-onlines with inline comments and exclusions.