Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 16 additions & 9 deletions .github/workflows/hotfix-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,26 +11,25 @@ jobs:
permissions:
contents: write
pull-requests: write
id-token: write

strategy:
matrix:
node-version: [20.x]
# See supported Node.js release schedule at https://nodejs.org/en/about/releases/

steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v6
- run: |
git config user.name ${{ github.actor }}
git config user.email ${{ github.actor }}@users.noreply.github.com

- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v3
uses: actions/setup-node@v6
with:
node-version: ${{ matrix.node-version }}
cache: 'npm'
cache-dependency-path: './common/config/rush/pnpm-lock.yaml'
package-manager-cache: false

# Install rush
- name: Install rush
run: node common/scripts/install-run-rush.js install --bypass-policy

Expand All @@ -55,10 +54,18 @@ jobs:
run: node common/scripts/install-run-rush.js build --only tag:package
- run: node common/scripts/install-run-rush.js test --only tag:package

- name: Publish to npm
env:
NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}
NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}
# Keep build/test on Node 20; npm trusted publishing requires Node >=22.14.
- name: Use Node.js 24 for publishing
uses: actions/setup-node@v6
with:
node-version: '24.x'
package-manager-cache: false

# pnpm publish delegates to the system npm CLI, which handles OIDC.
- name: Install npm with trusted publishing support
run: npm install --global npm@11.17.0

- name: Publish to npm with OIDC
run: node common/scripts/install-run-rush.js publish --publish --include-all --tag hotfix

- name: Update shrinkwrap
Expand Down
25 changes: 16 additions & 9 deletions .github/workflows/pre-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,22 +13,21 @@ jobs:

permissions:
contents: write
id-token: write

strategy:
matrix:
node-version: [20.x]
# See supported Node.js release schedule at https://nodejs.org/en/about/releases/

steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v6
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v3
uses: actions/setup-node@v6
with:
node-version: ${{ matrix.node-version }}
cache: 'npm'
cache-dependency-path: './common/config/rush/pnpm-lock.yaml'
package-manager-cache: false

# Install rush
- name: Install rush
run: node common/scripts/install-run-rush.js install --bypass-policy

Expand All @@ -52,10 +51,18 @@ jobs:
- name: Build packages
run: node common/scripts/install-run-rush.js build --only tag:package

- name: Publish to npm
env:
NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}
NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}
# Keep build/test on Node 20; npm trusted publishing requires Node >=22.14.
- name: Use Node.js 24 for publishing
uses: actions/setup-node@v6
with:
node-version: '24.x'
package-manager-cache: false

# pnpm publish delegates to the system npm CLI, which handles OIDC.
- name: Install npm with trusted publishing support
run: npm install --global npm@11.17.0

- name: Publish to npm with OIDC
run: node common/scripts/install-run-rush.js publish --publish --include-all --tag ${{ steps.semver_parser.outputs.pre_release_type }}

- name: Update shrinkwrap
Expand Down
25 changes: 16 additions & 9 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ jobs:
permissions:
contents: write
pull-requests: write
id-token: write

env:
CI: true
Expand All @@ -21,19 +22,17 @@ jobs:
# See supported Node.js release schedule at https://nodejs.org/en/about/releases/

steps:
- uses: actions/checkout@v3
- uses: actions/checkout@v6
- run: |
git config user.name ${{ github.actor }}
git config user.email ${{ github.actor }}@users.noreply.github.com

- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v3
uses: actions/setup-node@v6
with:
node-version: ${{ matrix.node-version }}
cache: 'npm'
cache-dependency-path: './common/config/rush/pnpm-lock.yaml'
package-manager-cache: false

# Install rush
- name: Install rush
run: node common/scripts/install-run-rush.js install --bypass-policy

Expand All @@ -58,10 +57,18 @@ jobs:
run: node common/scripts/install-run-rush.js build --only tag:package
- run: node common/scripts/install-run-rush.js test --only tag:package

- name: Publish to npm
env:
NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}
NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}}
# Keep build/test on Node 20; npm trusted publishing requires Node >=22.14.
- name: Use Node.js 24 for publishing
uses: actions/setup-node@v6
with:
node-version: '24.x'
package-manager-cache: false

# pnpm publish delegates to the system npm CLI, which handles OIDC.
- name: Install npm with trusted publishing support
run: npm install --global npm@11.17.0

- name: Publish to npm with OIDC
run: node common/scripts/install-run-rush.js publish --publish --include-all

- name: Update shrinkwrap
Expand Down

This file was deleted.

2 changes: 2 additions & 0 deletions common/config/rush/.npmrc-publish
Original file line number Diff line number Diff line change
Expand Up @@ -17,5 +17,7 @@
# environment variable, which can be referenced from .npmrc using ${} expansion. For example:
#
#
registry=https://registry.npmjs.org/
# GitHub Actions uses OIDC. Rush omits the optional local token below when unset.
//registry.npmjs.org/:_authToken=${NPM_AUTH_TOKEN}
#
8 changes: 4 additions & 4 deletions common/config/rush/pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion common/config/rush/version-policies.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
[{"definitionName":"lockStepVersion","policyName":"vutilMain","version":"1.0.23","nextBump":"patch"}]
[{"definitionName":"lockStepVersion","policyName":"vutilMain","version":"1.0.24","nextBump":"patch"}]
49 changes: 49 additions & 0 deletions docs/superpowers/plans/2026-09-18-npm-trusted-publishing.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,49 @@
# npm Trusted Publishing Implementation Plan

> Execute inline in the current task. The user has approved the migration; preserve the existing release behavior.

**Goal:** Publish VUtil packages from GitHub Actions using OIDC instead of `NPM_TOKEN`.

**Architecture:** Keep Rush and pnpm publishing. Provide a compatible system npm CLI and OIDC permissions, then register each existing release workflow in each npm package's trusted publishers.

**Tech Stack:** GitHub Actions, Node 20 for build/test and Node 24 for publishing, npm 11.17.0, Rush 5.164.0, pnpm 10.7.0.

## Global Constraints

- All three release workflows must preserve their branch triggers, versioning, distribution tags, and post-publish steps.
- Use `VisActor/VUtil` with matching case in repository metadata and npm settings.
- Only a real GitHub-hosted release can validate OIDC authentication end to end.

## Task 1: Update release configuration

**Files:** `.github/workflows/release.yml`, `.github/workflows/pre-release.yml`, `.github/workflows/hotfix-release.yml`, `common/config/rush/.npmrc-publish`, and the four `packages/*/package.json` files.

- [x] Keep the build/test Node matrix at `20.x`; use `actions/checkout@v6` and `actions/setup-node@v6`, with a separate Node 24 setup immediately before publishing.
- [x] Disable setup-node package manager caching for release jobs and install `npm@11.17.0` explicitly.
- [x] Add `id-token: write` alongside existing job permissions and remove the publish step's `NODE_AUTH_TOKEN` / `NPM_AUTH_TOKEN` environment block.
- [x] Add `repository.type = git`, `repository.url = git+https://github.com/VisActor/VUtil.git`, and each package's `repository.directory`.
- [x] Set the publish registry explicitly and document the optional local token reference.

## Task 2: Validate the existing publication path

- [x] Run `git diff --check` and an Actions workflow validator.
- [x] Run `node common/scripts/install-run-rush.js install --bypass-policy` with Node 20.
- [x] Run `node common/scripts/install-run-rush.js build --only tag:package` and `CI=true node common/scripts/install-run-rush.js test --only tag:package`.
- [x] Use pnpm 10.7.0 with `publish --dry-run --no-git-checks` for each public package; verify packed manifests contain canonical repository metadata and no `workspace:` dependency specifications.

## Task 3: Configure npm and report rollout status

- [x] After the user signs in, inspect existing trusted publishers for each of the four packages.
- [x] Add any missing GitHub Actions publishers for `VisActor/VUtil`: `release.yml`, `pre-release.yml`, and `hotfix-release.yml`, with no environment and direct publishing allowed.
- [x] Verify saved npm settings and document any required user authentication step.
- [x] Report local validation and the remaining release action accurately; do not claim a successful OIDC publish before a real Actions run succeeds.

## Validation results and current state

- Actionlint 1.7.12 and `git diff --check` pass.
- Node 20.20.2 install/build/test pass: 92 suites and 737 tests pass; 1 suite and 6 tests remain skipped by the existing configuration.
- Node 24.19.0 / npm 11.17.0 / pnpm 10.7.0 dry-runs pass for all four packages. Packed repository metadata, resolved workspace dependencies, and cjs/es/dist outputs were checked. Dry-runs use temporary unpacked copies bumped to 1.0.24, as the working tree's 1.0.23 versions already exist on npm. Logs and tarballs: `/tmp/vutil-oidc-packages-y0ay5lak`.
- npm confirms all four packages (`vdataset`, `vutils`, `vscale`, and `vlayouts`) trust all three workflows in `VisActor/VUtil`, with direct publish allowed (12/12 connections saved and verified).
- The final `vlayouts` hotfix connection was saved in Google Chrome after the user completed 2FA there; the in-app browser could not accept the user's verification input.
- Local validation did not publish any packages. A real GitHub Actions run must confirm OIDC authentication end to end.
- Roll out these changes by committing and pushing to `release/1.0.24`. The original failed run used `3998da1b11b59738cd55766b093a96389077b3db`; rerunning it would retain its original workflow.
23 changes: 23 additions & 0 deletions docs/superpowers/specs/2026-09-18-npm-trusted-publishing-design.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# npm trusted publishing

## Goal

Restore automated releases without an expiring npm token. The user approved migrating the GitHub workflows and npm package settings to trusted publishing.

## Approach

Keep Rush 5.164.0 and pnpm 10.7.0. The pinned pnpm implementation packs workspace dependencies and invokes the system npm CLI, inheriting the GitHub OIDC environment. Keep build and test on Node 20, then switch all three workflows to Node 24 and npm 11.17.0 immediately before publishing, grant `id-token: write`, and stop passing `NPM_TOKEN` to publishing. Preserve the existing release commands and distribution tags.

The existing vscale Wilkinson tiny-number test fails under Node 24 but passes under Node 20. Restricting the runtime upgrade to publishing avoids coupling this authentication migration to numerical behavior changes.

Replacing Rush with a custom publisher would duplicate its version checks, workspace packing, and partial-release recovery. Rotating a granular token would restore publishing temporarily but retain the expiry problem. Neither is needed for this migration.

Add the canonical `git+https://github.com/VisActor/VUtil.git` repository URL and package directory to each public package. These metadata let npm validate the repository when generating provenance. Keep `.npmrc-publish` pointed at the public npm registry; its optional token reference remains available for local workflows and is omitted by Rush when unset in CI.

## npm configuration

For each of `@visactor/vdataset`, `@visactor/vlayouts`, `@visactor/vscale`, and `@visactor/vutils`, add GitHub Actions trusted publishers for `VisActor/VUtil` with workflow filenames `release.yml`, `pre-release.yml`, and `hotfix-release.yml`. Leave the environment name unset because these jobs do not declare an environment. Allow direct `npm publish`, matching the existing release process. Do not change unrelated package permissions or revoke credentials during setup.

## Validation and rollout

Validate workflow syntax, build and test the four packages with Node 20, and dry-run packing/publishing with the pinned pnpm and npm versions. Check packed repository metadata and resolved workspace dependency versions. These checks cannot prove OIDC exchange locally; that requires a real GitHub Actions release after npm settings are saved and the workflow changes reach the release branch. Re-running the original failed run alone will reuse its old workflow.
6 changes: 6 additions & 0 deletions packages/vdataset/CHANGELOG.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,12 @@
{
"name": "@visactor/vdataset",
"entries": [
{
"version": "1.0.24",
"tag": "@visactor/vdataset_v1.0.24",
"date": "Fri, 18 Sep 2026 08:59:37 GMT",
"comments": {}
},
{
"version": "1.0.23",
"tag": "@visactor/vdataset_v1.0.23",
Expand Down
7 changes: 6 additions & 1 deletion packages/vdataset/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,11 @@
# Change Log - @visactor/vdataset

This log was last generated on Wed, 11 Mar 2026 06:07:08 GMT and should not be manually modified.
This log was last generated on Fri, 18 Sep 2026 08:59:37 GMT and should not be manually modified.

## 1.0.24
Fri, 18 Sep 2026 08:59:37 GMT

_Version update only_

## 1.0.23
Wed, 11 Mar 2026 06:07:08 GMT
Expand Down
9 changes: 7 additions & 2 deletions packages/vdataset/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@visactor/vdataset",
"version": "1.0.23",
"version": "1.0.24",
"main": "cjs/index.js",
"module": "es/index.js",
"types": "es/index.d.ts",
Expand All @@ -21,6 +21,11 @@
"name": "VisActor",
"url": "https://VisActor.io/"
},
"repository": {
"type": "git",
"url": "git+https://github.com/VisActor/VUtil.git",
"directory": "packages/vdataset"
},
"license": "MIT",
"keywords": [
"visual",
Expand All @@ -38,7 +43,7 @@
"test-cov": "jest -w 16 --coverage"
},
"dependencies": {
"@visactor/vutils": "workspace:1.0.23",
"@visactor/vutils": "workspace:1.0.24",
"@turf/flatten": "^6.5.0",
"@turf/helpers": "^6.5.0",
"@turf/rewind": "^6.5.0",
Expand Down
12 changes: 12 additions & 0 deletions packages/vlayouts/CHANGELOG.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,18 @@
{
"name": "@visactor/vlayouts",
"entries": [
{
"version": "1.0.24",
"tag": "@visactor/vlayouts_v1.0.24",
"date": "Fri, 18 Sep 2026 08:59:37 GMT",
"comments": {
"none": [
{
"comment": " feat: add columns information in sankey nodeHeight callback"
}
]
}
},
{
"version": "1.0.23",
"tag": "@visactor/vlayouts_v1.0.23",
Expand Down
9 changes: 8 additions & 1 deletion packages/vlayouts/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,13 @@
# Change Log - @visactor/vlayouts

This log was last generated on Wed, 11 Mar 2026 06:07:08 GMT and should not be manually modified.
This log was last generated on Fri, 18 Sep 2026 08:59:37 GMT and should not be manually modified.

## 1.0.24
Fri, 18 Sep 2026 08:59:37 GMT

### Updates

- feat: add columns information in sankey nodeHeight callback

## 1.0.23
Wed, 11 Mar 2026 06:07:08 GMT
Expand Down
Loading
Loading