mirror of
https://github.com/vercel-labs/scriptc.git
synced 2026-10-02 08:35:07 +08:00
* feat(runtime): ship precompiled macOS artifacts - Add a versioned macOS arm64 runtime pack with deterministic feature selection and artifact verification. - Link LLVM helper objects against release-built runtime and vendor inputs without compiling user-machine C. - Wire package publishing, cache validation, documentation, and full-gate coverage for the new path. * fix(runtime): harden precompiled artifact handling * fix(runtime): make precompiled artifacts reproducible * fix(runtime): reject opaque linkers from executable cache * fix(runtime): normalize precompiled archive metadata * fix(runtime): harden precompiled artifact caching * fix(runtime): close executable cache link race * fix(runtime): stage verified pack artifacts * fix(runtime): bracket helper cache inputs * fix(runtime): preserve executable link identity * fix(runtime): trace selected linker dependencies
232 lines
8.6 KiB
YAML
232 lines
8.6 KiB
YAML
name: Release
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
workflow_dispatch:
|
|
|
|
concurrency: ${{ github.workflow }}-${{ github.ref }}
|
|
|
|
jobs:
|
|
check-release:
|
|
name: Check for new version
|
|
# The private mirror carries this file too; only the public repo
|
|
# publishes (the trusted publisher is pinned to it).
|
|
if: github.repository == 'vercel-labs/scriptc'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 5
|
|
permissions:
|
|
contents: read
|
|
outputs:
|
|
should_release: ${{ steps.check.outputs.should_release }}
|
|
version: ${{ steps.check.outputs.version }}
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
registry-url: "https://registry.npmjs.org"
|
|
|
|
- name: Compare package.json version to npm
|
|
id: check
|
|
run: |
|
|
LOCAL_VERSION=$(node -p "require('./packages/cli/package.json').version")
|
|
echo "Local version: $LOCAL_VERSION"
|
|
|
|
NPM_VERSION=$(npm view scriptc version 2>/dev/null || echo "0.0.0")
|
|
echo "npm version: $NPM_VERSION"
|
|
|
|
if [ "$LOCAL_VERSION" != "$NPM_VERSION" ]; then
|
|
echo "Version changed: $NPM_VERSION -> $LOCAL_VERSION"
|
|
echo "should_release=true" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "Version unchanged on npm, skipping publish"
|
|
echo "should_release=false" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
echo "version=$LOCAL_VERSION" >> "$GITHUB_OUTPUT"
|
|
|
|
publish:
|
|
name: Publish to npm
|
|
needs: check-release
|
|
if: needs.check-release.outputs.should_release == 'true'
|
|
runs-on: macos-15
|
|
timeout-minutes: 15
|
|
environment: Release
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 11.1.3
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
registry-url: "https://registry.npmjs.org"
|
|
|
|
- name: Install pinned LLVM
|
|
run: brew install llvm@22
|
|
|
|
# Publishing uses npm trusted publishing (OIDC): the job's id-token
|
|
# permission lets npm mint short-lived credentials, so no npm token
|
|
# secret exists anywhere in this repo. All five packages —
|
|
# @scriptc/runtime, @scriptc/runtime-darwin-arm64,
|
|
# @scriptc/llvm-darwin-arm64, @scriptc/compiler, and scriptc — must each be
|
|
# configured on npmjs.com with a GitHub Actions trusted publisher
|
|
# pointing at repository vercel-labs/scriptc, workflow release.yml,
|
|
# environment Release. A package missing that configuration fails
|
|
# with an OIDC authentication error before anything uploads.
|
|
# Trusted publishing requires npm >= 11.5.1 (bundled with Node 24).
|
|
|
|
- name: Install and build
|
|
run: |
|
|
pnpm install --frozen-lockfile
|
|
pnpm --filter @scriptc/llvm-darwin-arm64 build:native
|
|
pnpm --filter @scriptc/runtime-darwin-arm64 build:native
|
|
pnpm -r build
|
|
|
|
- name: Check version sync
|
|
run: |
|
|
VERSION="${{ needs.check-release.outputs.version }}"
|
|
for pkg in packages/runtime packages/runtime-darwin-arm64 packages/llvm-darwin-arm64 packages/compiler packages/cli; do
|
|
V=$(node -p "require('./$pkg/package.json').version")
|
|
if [ "$V" != "$VERSION" ]; then
|
|
echo "Version mismatch: $pkg is $V, expected $VERSION"
|
|
echo "Run 'node scripts/sync-versions.mjs' to stamp runtime and compiler from the CLI version, then commit"
|
|
exit 1
|
|
fi
|
|
done
|
|
|
|
- name: Package and verify LLVM helper
|
|
run: |
|
|
TARBALL=$(pnpm --dir packages/llvm-darwin-arm64 pack --pack-destination "$RUNNER_TEMP" --silent)
|
|
HELPER_TARBALL="$RUNNER_TEMP/$(basename "$TARBALL")"
|
|
node scripts/verify-llvm-package.mjs "$HELPER_TARBALL"
|
|
echo "HELPER_TARBALL=$HELPER_TARBALL" >> "$GITHUB_ENV"
|
|
|
|
- name: Publish to npm
|
|
run: |
|
|
VERSION="${{ needs.check-release.outputs.version }}"
|
|
|
|
# npm accepts --provenance only from PUBLIC source repositories;
|
|
# while this repo is internal the flag is dropped, and the same
|
|
# step starts attaching provenance the moment the repo goes
|
|
# public — no workflow edit.
|
|
VISIBILITY=$(gh api "repos/${{ github.repository }}" --jq .visibility)
|
|
if [ "$VISIBILITY" = "public" ]; then
|
|
PROVENANCE="--provenance"
|
|
else
|
|
PROVENANCE=""
|
|
echo "repository visibility is '$VISIBILITY': publishing without provenance"
|
|
fi
|
|
|
|
# Dependency order, so each package's deps are resolvable the
|
|
# moment it lands. pnpm pack rewrites workspace:* to the real
|
|
# version; npm publish on the tarball handles OIDC.
|
|
# Re-runs skip anything already on the registry at this version.
|
|
publish_dir() {
|
|
dir="$1"
|
|
packed="${2:-}"
|
|
name=$(node -p "require('./$dir/package.json').name")
|
|
if npm view "$name@$VERSION" version >/dev/null 2>&1; then
|
|
echo "$name@$VERSION already published, skipping"
|
|
return 0
|
|
fi
|
|
if [ -z "$packed" ]; then
|
|
tarball=$(cd "$dir" && pnpm pack --silent | tail -1)
|
|
packed="$dir/$tarball"
|
|
fi
|
|
npm publish "$packed" $PROVENANCE --access public
|
|
}
|
|
|
|
publish_dir packages/runtime
|
|
publish_dir packages/runtime-darwin-arm64
|
|
publish_dir packages/llvm-darwin-arm64 "$HELPER_TARBALL"
|
|
publish_dir packages/compiler
|
|
publish_dir packages/cli
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
# The GitHub release is a tag, notes, and one asset: the surface
|
|
# manifest (packages/compiler/surface-manifest.json — the machine-
|
|
# readable listing of the surface the static tier compiles at this
|
|
# version, regenerated here and verified against the committed file).
|
|
# The platform helper ships through its npm package rather than as a GitHub
|
|
# release asset, so this job runs AFTER a successful npm publish and never
|
|
# gates it. The body is the CHANGELOG.md block between the
|
|
# release:start/release:end markers, which RELEASING.md keeps on the
|
|
# latest entry only.
|
|
github-release:
|
|
name: Create GitHub Release
|
|
needs: [check-release, publish]
|
|
if: needs.check-release.outputs.should_release == 'true'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
permissions:
|
|
contents: write
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Setup pnpm
|
|
uses: pnpm/action-setup@v4
|
|
with:
|
|
version: 11.1.3
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
|
|
# Regenerate the surface manifest from this tree and require it to
|
|
# match the committed file byte-for-byte — the same staleness guard
|
|
# the test suite runs — so the attached asset is provably the
|
|
# manifest of the code being released.
|
|
- name: Generate surface manifest
|
|
run: |
|
|
pnpm install --frozen-lockfile
|
|
pnpm manifest --check
|
|
|
|
- name: Extract changelog entry
|
|
run: |
|
|
VERSION="${{ needs.check-release.outputs.version }}"
|
|
awk '/<!-- release:start -->/{found=1; next} /<!-- release:end -->/{exit} found{print}' CHANGELOG.md > /tmp/release-notes.md
|
|
|
|
LINES=$(wc -l < /tmp/release-notes.md | tr -d ' ')
|
|
if [ "$LINES" -lt 2 ]; then
|
|
echo "Error: No release notes found between <!-- release:start --> and <!-- release:end --> markers in CHANGELOG.md"
|
|
exit 1
|
|
fi
|
|
echo "Extracted release notes for $VERSION ($LINES lines)"
|
|
|
|
- name: Create GitHub Release
|
|
run: |
|
|
VERSION="${{ needs.check-release.outputs.version }}"
|
|
TAG="v$VERSION"
|
|
|
|
if gh release view "$TAG" &>/dev/null; then
|
|
echo "Release $TAG already exists, skipping creation"
|
|
else
|
|
echo "Creating release $TAG..."
|
|
gh release create "$TAG" \
|
|
--target "$GITHUB_SHA" \
|
|
--title "$TAG" \
|
|
--notes-file /tmp/release-notes.md
|
|
fi
|
|
|
|
# Attach the surface manifest (idempotent: --clobber makes
|
|
# re-runs replace the asset instead of failing).
|
|
gh release upload "$TAG" packages/compiler/surface-manifest.json --clobber
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|