Skip to content

sdk: bump to 0.1.2 and finalize npm publish pipeline - #7642

Merged
lawrencecchen merged 7 commits into
mainfrom
sdk-bump-0-1-2
Jul 8, 2026
Merged

lawrencecchen merged 7 commits into
mainfrom
sdk-bump-0-1-2

Conversation

@lawrencecchen

@lawrencecchen lawrencecchen commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Lands the state that published cmux 0.1.2 to PyPI and npm.

  • All SDK binding manifests + lockfiles bumped 0.1.0 -> 0.1.2 (0.1.2 is the smallest version free on both npm, where the CLI holds 0.1.0-0.8.3, and PyPI, where 0.1.0-0.1.1 are taken).
  • npm publish workflow fixes (all needed for the live publish to succeed): upgrade to npm >=11.5.1 for OIDC trusted-publishing auth; publish under the sdk dist-tag so npm i cmux keeps resolving the CLI (latest=0.8.3) and npm i cmux@sdk=SDK; run the publish job on a github-hosted runner (npm --provenance rejects self-hosted); add repository/homepage to package.json (provenance validation).
  • Self-hosted runner guard: documented github-hosted-required opt-out for jobs that must be github-hosted (npm provenance) and never enter the overflow rotation.

Already published live: PyPI cmux 0.1.2, npm cmux@sdk 0.1.2 (both via OIDC trusted publishing + provenance).


View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.


Note

Low Risk
Changes are limited to release versions, publish workflow, and CI guard rules—no application runtime or auth logic.

Overview
Bumps mux SDK bindings from 0.1.0 to 0.1.2 across Python (pyproject.toml), Rust (cmux-client + lockfile), and TypeScript (package.json / lockfile). Rust and TypeScript manifests also gain repository / homepage metadata for registry provenance.

The sdk-publish-npm workflow is adjusted so live publishes succeed: the publish job runs on ubuntu-latest (required for npm --provenance), installs npm ≥ 11.5.1 for OIDC trusted publishing, and publishes with --tag sdk so npm i cmux still resolves the CLI on latest while the SDK is cmux@sdk.

test_ci_self_hosted_guard.sh now allows documented github-hosted-required exceptions on runs-on lines so that publish job is not flagged. web/.gitignore adds .env*.local.

Reviewed by Cursor Bugbot for commit 79af23b. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Bumps the SDK bindings to 0.1.2 and finalizes the npm publish pipeline with provenance and OIDC trusted publishing. Adds crates.io metadata, keeps the cmux CLI on latest, and makes the SDK installable via cmux@sdk.

  • Dependencies

    • Set cmux/cmux-client version to 0.1.2 in Python, Rust, and TypeScript bindings (manifests and lockfiles).
  • Bug Fixes

    • Run the npm publish job on ubuntu-latest (GitHub‑hosted) for npm --provenance.
    • Upgrade npm to >= 11.5.1 to enable OIDC trusted publishing.
    • Publish the SDK with --tag sdk so npm i cmux keeps resolving the CLI; use npm i cmux@sdk for the SDK.
    • Add repository/homepage to the TS package.json and description/repository/homepage to the Rust crate for provenance/crates.io validation.
    • Exempt marked jobs from the self‑hosted runner guard using github-hosted-required; update the guard test accordingly.

Written for commit 79af23b. Summary will update on new commits.

Review in cubic

Summary by CodeRabbit

  • New Features
    • Improved SDK release publishing support with safer, provenance-backed publishing settings.
  • Bug Fixes
    • Corrected CI self-hosted runner guard detection for runs-on lines with inline comments and exclusions.
  • Chores
    • Bumped package version to 0.1.2 across Python, Rust, and TypeScript bindings.
    • Updated TypeScript package repository/homepage metadata.
    • Expanded the web app’s local environment file ignores.

…nd PyPI)

npm cmux 0.1.0-0.8.3 are taken by the CLI history and PyPI has 0.1.0-0.1.1,
so 0.1.2 is the smallest version publishable on every registry. Being below
npm's 0.8.3 it stays off the 'latest' tag, so 'npm i cmux' keeps installing
the CLI and nothing breaks. Unified across all bindings.
…ng auth)

Node 22 ships npm 10, which signs provenance but cannot authenticate the
publish via OIDC trusted publishing, so the PUT is unauthenticated and 404s.
npm 11.5.1+ does the OIDC token exchange for the publish.
npm refuses to implicitly move 'latest' to 0.1.2 (below the CLI's 0.8.3).
Publishing under --tag sdk keeps 'npm i cmux' resolving the CLI (latest)
while the SDK is installable via 'npm i cmux@sdk'.
npm --provenance rejects self-hosted runners (E422: only github-hosted
runners are supported when publishing with provenance). Pin only the
publish job to ubuntu-latest so the sigstore attestation verifies.
…ation)

npm --provenance requires package.json repository.url to match the source
repo (manaflow-ai/cmux) recorded in the sigstore attestation.
…uard

npm --provenance only verifies on a github-hosted runner, so the npm publish
job pins ubuntu-latest and carries a documented github-hosted-required marker.
The self-hosted runner guard now skips runs-on lines with that marker; these
publish jobs run only on dispatch and never enter the overflow rotation.
@vercel

vercel Bot commented Jul 8, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
cmux Building Building Preview, Comment Jul 8, 2026 7:25pm
cmux-staging Building Building Preview, Comment Jul 8, 2026 7:25pm

@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

This PR updates the SDK publish workflow to use a GitHub-hosted runner, upgrade npm, and publish under the sdk tag. It also bumps binding package versions, adds TypeScript package metadata, adjusts a CI guard pattern, and extends the web ignore rules.

Changes

SDK Publish Workflow and Guard

Layer / File(s) Summary
Publish workflow runner, npm upgrade, and dist-tag
.github/workflows/sdk-publish-npm.yml
The publish job switches to ubuntu-latest, installs npm@^11.5.1, and publishes with --provenance --tag sdk.
CI guard pattern update
tests/test_ci_self_hosted_guard.sh
check_no_bare_github_hosted_runners now matches runs-on: lines with trailing comments and excludes github-hosted-required entries.

Package Version Bumps and Misc Config

Layer / File(s) Summary
Version bumps and metadata across bindings
mux/bindings/python/pyproject.toml, mux/bindings/rust/Cargo.toml, mux/bindings/typescript/package.json, web/.gitignore
The Python, Rust, and TypeScript package versions move to 0.1.2; TypeScript package metadata gains repository and homepage; web/.gitignore adds /.env*.local.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

  • manaflow-ai/cmux#7583: Also changes tests/test_ci_self_hosted_guard.sh, with overlapping CI runner guard logic.
  • manaflow-ai/cmux#7601: Related changes to .github/workflows/sdk-publish-npm.yml around SDK release publishing and tagging behavior.
🚥 Pre-merge checks | ✅ 25
✅ Passed checks (25 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Cmux Swift Actor Isolation ✅ Passed The diff only changes mux/bindings/rust/Cargo.toml; no Swift files or actor-isolation-related code was introduced or worsened.
Cmux Swift Blocking Runtime ✅ Passed Diff vs origin/main changes only workflow/manifests/tests/.gitignore; no Swift sources or package manifests changed, so the Swift blocking-runtime rule doesn’t apply.
Cmux Browser Automation Off-Main ✅ Passed Diff only updates workflows/manifests/tests; no browser socket automation files or browser.* routing changes are touched, so the off-main rule isn't implicated.
Cmux Expensive Synchronous Load ✅ Passed The PR diff only changes mux/bindings/rust/Cargo.toml; no Swift code or main-actor/interactive sync-load paths were added or moved.
Cmux Cache Substitution Correctness ✅ Passed No production Swift/TS/JS source changed; the commit only updates a workflow and a shell test, so cache-substitution rules don’t apply.
Cmux No Hacky Sleeps ✅ Passed PASS: The diff only changes a Rust manifest; no TS/JS/shell/runtime code or sleep/timer logic is introduced.
Cmux Algorithmic Complexity ✅ Passed Only workflow/test scaffolding and manifests changed; the shell AWK scan is test-only and targets one fixed workflow file, which the rule allows.
Cmux Swift Concurrency ✅ Passed The Swift diff only removes Cloud VM feature guards; no DispatchQueue, Task, Combine, or completion-handler async patterns were introduced.
Cmux Swift @Concurrent ✅ Passed No Swift files or Swift concurrency changes are present in the diff, so the rule is not applicable.
Cmux Swift File And Package Boundaries ✅ Passed No Swift files changed; the PR only touches a Rust manifest, so the Swift boundary rule is not applicable.
Cmux Swiftpm Lockfiles ✅ Passed HEAD only changes mux/bindings/rust/Cargo.toml; no SwiftPM/Xcode/.gitignore/workflow/dependency-resolution files are in the diff, so the rule isn’t triggered.
Cmux Swift Logging ✅ Passed No Swift files are changed in this PR diff, so the Swift logging rule is not applicable.
Cmux User-Facing Error Privacy ✅ Passed Only Rust package metadata in Cargo.toml changed; no user-facing errors, alerts, or API/CLI messages were introduced.
Cmux Full Internationalization ✅ Passed Diff only changes workflow, manifests, a test, and .gitignore; no localized Swift/UI/web copy, string-catalog, or web/messages locale files were touched.
Cmux Swiftui State Layout ✅ Passed The diff only touches workflows/manifests; no SwiftUI source files or SwiftUI state/layout patterns are introduced.
Cmux Architecture Rethink ✅ Passed No Swift files changed in the diff, so the Swift architectural rethink rule does not apply.
Cmux Swift Auxiliary Window Close Shortcuts ✅ Passed No Swift files were changed in the PR, so the auxiliary-window close-shortcut rule is not applicable.
Cmux Source Artifacts ✅ Passed All changed paths are intentional source/config/lockfile updates; no logs, temp dirs, caches, or build artifacts were added, and required generated lockfiles are allowed.
Cmux No Test Or Debug Seam In Production Source ✅ Passed The PR diff changes no Swift production Sources/ files; it only touches manifests, workflow, tests, and support files.
Cmux No Ambient Global State ✅ Passed No Swift source files changed in the PR diff; only manifests, workflow, test, and config files were touched, so the ambient-global-state Swift rule isn't implicated.
Title check ✅ Passed The title clearly states the SDK version bump and npm publish pipeline work.
Description check ✅ Passed The description covers the version bump, publish workflow, and guard changes, but omits testing, demo, review-trigger, and checklist sections.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch sdk-bump-0-1-2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Greptile Summary

Bumps all SDK binding versions from 0.1.0 to 0.1.2 and finalizes the npm publish pipeline with OIDC trusted publishing and provenance attestation support.

  • Switches the publish job to ubuntu-latest (GitHub-hosted) since npm --provenance requires it, introduces a # github-hosted-required: comment convention to opt jobs out of the self-hosted runner guard, and updates test_ci_self_hosted_guard.sh to honor that exemption.
  • Upgrades npm to ^11.5.1 for OIDC token exchange, publishes under --tag sdk so bare npm i cmux keeps resolving the CLI at latest (0.8.3), and adds repository/homepage fields to the TypeScript and Rust manifests for provenance validation.
  • Adds .env*.local to web/.gitignore and applies a consistent version bump across Python pyproject.toml, Rust Cargo.toml/Cargo.lock, and TypeScript package.json/package-lock.json.

Confidence Score: 5/5

Safe to merge — all changes are version bumps, metadata additions, and CI pipeline fixes with no production code or Swift changes.

The diff is entirely version bumps across binding manifests and lockfiles, npm publish workflow corrections, a targeted update to the self-hosted runner guard test, and a gitignore addition. The guard exemption mechanism is logically correct: the regex now captures trailing inline comments so the opt-out token is detectable and filterable. The --tag sdk publish strategy correctly preserves the CLI on latest. No Swift, runtime, or application logic is touched.

No files require special attention.

Important Files Changed

Filename Overview
.github/workflows/sdk-publish-npm.yml Publish job pinned to ubuntu-latest for provenance; npm upgraded to >=11.5.1 for OIDC; --tag sdk added to keep CLI on latest; guard opt-out comment convention documented.
tests/test_ci_self_hosted_guard.sh Guard regex extended to capture inline-comment suffixes; pipeline excludes lines tagged github-hosted-required, cleanly handling the new npm publish exemption.
mux/bindings/typescript/package.json Version bumped to 0.1.2; repository and homepage fields added for npm provenance validation.
mux/bindings/rust/Cargo.toml Version bumped to 0.1.2; description, repository, and homepage metadata added.
mux/bindings/python/pyproject.toml Version bumped from 0.1.0 to 0.1.2; no other changes.
mux/bindings/typescript/package-lock.json Lockfile updated to match package.json version bump to 0.1.2.
mux/Cargo.lock cmux-client version updated to 0.1.2 to match Cargo.toml bump.
web/.gitignore Adds .env*.local glob to prevent local Next.js environment files from entering source control.

Sequence Diagram

%%{init: {'theme': 'neutral'}}%%
sequenceDiagram
    participant Dev as Developer
    participant GHA as GitHub Actions
    participant NPM as npm Registry (OIDC)
    participant PyPI as PyPI (OIDC)

    Dev->>GHA: "workflow_dispatch (confirm_npm_cmux=true)"
    GHA->>GHA: version job — validate all bindings at 0.1.2
    GHA->>GHA: bindings-e2e-typescript (self-hosted runner)
    GHA->>GHA: publish job (ubuntu-latest / github-hosted-required)
    GHA->>GHA: "npm install -g npm@^11.5.1"
    GHA->>GHA: "npm ci && npm run build"
    GHA->>NPM: npm publish --provenance --tag sdk
    NPM-->>GHA: "cmux@sdk=0.1.2 published (OIDC token exchange)"
    Note over NPM: latest=0.8.3 (CLI) unchanged, sdk=0.1.2 (SDK) new
    Dev->>PyPI: (separate) trusted publish
    PyPI-->>Dev: cmux 0.1.2 published
Loading
%%{init: {'theme': 'base', 'themeVariables': {"darkMode": true, "background": "#0d1117", "primaryColor": "#21262d", "primaryTextColor": "#e6edf3", "primaryBorderColor": "#8b949e", "lineColor": "#8b949e", "textColor": "#e6edf3", "edgeLabelBackground": "#161b22", "actorBkg": "#21262d", "actorBorder": "#8b949e", "actorTextColor": "#e6edf3", "actorLineColor": "#8b949e", "signalColor": "#8b949e", "signalTextColor": "#e6edf3", "noteBkgColor": "#373320", "noteBorderColor": "#d4a72c", "noteTextColor": "#f0e6c0", "labelBoxBkgColor": "#21262d", "labelBoxBorderColor": "#8b949e", "labelTextColor": "#e6edf3", "loopTextColor": "#e6edf3", "activationBkgColor": "#30363d", "activationBorderColor": "#8b949e"}}}%%
sequenceDiagram
    participant Dev as Developer
    participant GHA as GitHub Actions
    participant NPM as npm Registry (OIDC)
    participant PyPI as PyPI (OIDC)

    Dev->>GHA: "workflow_dispatch (confirm_npm_cmux=true)"
    GHA->>GHA: version job — validate all bindings at 0.1.2
    GHA->>GHA: bindings-e2e-typescript (self-hosted runner)
    GHA->>GHA: publish job (ubuntu-latest / github-hosted-required)
    GHA->>GHA: "npm install -g npm@^11.5.1"
    GHA->>GHA: "npm ci && npm run build"
    GHA->>NPM: npm publish --provenance --tag sdk
    NPM-->>GHA: "cmux@sdk=0.1.2 published (OIDC token exchange)"
    Note over NPM: latest=0.8.3 (CLI) unchanged, sdk=0.1.2 (SDK) new
    Dev->>PyPI: (separate) trusted publish
    PyPI-->>Dev: cmux 0.1.2 published
Loading

Reviews (2): Last reviewed commit: "crates: add description/repository/homep..." | Re-trigger Greptile

# authenticate the publish via OIDC trusted publishing (the PUT is
# unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token
# exchange for the publish itself.
run: npm install -g npm@^11.5.1

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 The ^11.5.1 caret range lets npm resolve any 11.x release at run time, so a future 11.x regression could silently change publish behavior. For a publish pipeline where determinism matters, pinning an exact version is safer.

Suggested change
run: npm install -g npm@^11.5.1
run: npm install -g npm@11.5.1

Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/sdk-publish-npm.yml:
- Around line 151-157: The npm upgrade step in the publish workflow is too
loosely versioned, which can make provenance/OIDC behavior non-reproducible.
Update the install command in the “Upgrade npm for OIDC trusted publishing” step
to pin npm to the exact 11.5.1 release instead of using the caret range, keeping
the publish job stable while preserving the existing Node 22.14.0 setup.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: a78ab81c-79d5-496a-a414-6b91c6c985b3

📥 Commits

Reviewing files that changed from the base of the PR and between a9d8a08 and e1c5708.

⛔ Files ignored due to path filters (2)
  • mux/Cargo.lock is excluded by !**/*.lock
  • mux/bindings/typescript/package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (6)
  • .github/workflows/sdk-publish-npm.yml
  • mux/bindings/python/pyproject.toml
  • mux/bindings/rust/Cargo.toml
  • mux/bindings/typescript/package.json
  • tests/test_ci_self_hosted_guard.sh
  • web/.gitignore

Comment on lines +151 to +157
- name: Upgrade npm for OIDC trusted publishing
# Node 22 bundles npm 10, which signs provenance but cannot
# authenticate the publish via OIDC trusted publishing (the PUT is
# unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token
# exchange for the publish itself.
run: npm install -g npm@^11.5.1

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Consider pinning npm to an exact version.

npm@^11.5.1 allows any 11.x release to be installed at publish time, so a future npm minor/patch could silently alter provenance/OIDC behavior on a provenance-critical publish. Pinning exactly (npm@11.5.1) keeps this job reproducible. This also addresses the zizmor adhoc-packages warning at Line 156. node-version: "22.14.0" already satisfies npm 11's >=22.9.0 requirement, so no Node change is needed.

♻️ Proposed pin
-        run: npm install -g npm@^11.5.1
+        run: npm install -g npm@11.5.1
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- name: Upgrade npm for OIDC trusted publishing
# Node 22 bundles npm 10, which signs provenance but cannot
# authenticate the publish via OIDC trusted publishing (the PUT is
# unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token
# exchange for the publish itself.
run: npm install -g npm@^11.5.1
- name: Upgrade npm for OIDC trusted publishing
# Node 22 bundles npm 10, which signs provenance but cannot
# authenticate the publish via OIDC trusted publishing (the PUT is
# unauthenticated and 404s). npm >= 11.5.1 performs the OIDC token
# exchange for the publish itself.
run: npm install -g npm@11.5.1
🧰 Tools
🪛 zizmor (1.26.1)

[warning] 156-156: ad-hoc installation of packages (adhoc-packages): installs a package outside of a lockfile

(adhoc-packages)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/sdk-publish-npm.yml around lines 151 - 157, The npm
upgrade step in the publish workflow is too loosely versioned, which can make
provenance/OIDC behavior non-reproducible. Update the install command in the
“Upgrade npm for OIDC trusted publishing” step to pin npm to the exact 11.5.1
release instead of using the caret range, keeping the publish job stable while
preserving the existing Node 22.14.0 setup.

Source: Linters/SAST tools

@lawrencecchen
lawrencecchen merged commit 0302b40 into main Jul 8, 2026
45 of 49 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant