Skip to content

chore: publish through CI with provenance, bump dependencies - #546

Open
arzafran wants to merge 9 commits into
mainfrom
chore/maintenance-rollup
Open

arzafran wants to merge 9 commits into
mainfrom
chore/maintenance-rollup

Conversation

@arzafran

@arzafran arzafran commented Oct 1, 2026

Copy link
Copy Markdown
Member

What this does

Releases now publish to npm only from GitHub Actions, with provenance and no stored npm token. Dev dependencies are on current minor versions, and the playground runs on astro 7.

This replaces #516, #532 and #540, which are closed in favor of this PR.

Review order

  1. .github/workflows/release.yml: the publish workflow from chore(security): harden npm publish pipeline against supply-chain attacks #516, with two changes. Prerelease tags such as v1.3.27-dev.0 now publish under the dev dist-tag, so they never become latest. npm is pinned to 11.21.0 instead of npm@latest.
  2. SECURITY.md, .npmrc, .github/CODEOWNERS, .github/dependabot.yml, package.json: the rest of chore(security): harden npm publish pipeline against supply-chain attacks #516. The publish:dev and publish:main scripts are gone.
  3. playground/package.json: astro 7.3 from Bump astro from 5.18.2 to 7.3.2 in /playground in the npm_and_yarn group across 1 directory #540. @astrojs/react and @astrojs/vue are also bumped to 7, because astro 7 requires them.
  4. bun.lock plus the other manifests: the bumps from chore: weekly maintenance — dep bumps #532 (Biome 2.5.5, tsdown 0.21.10, TypeScript 5.9.3, React 19.2, Vue 3.5.40, Nuxt 3.21). All are dev dependencies, so the peer ranges consumers see don't change.
  5. playground/www/layouts/Layout.astro: one blank line for the Biome 2.5 import rule. The file also switches from CRLF to LF line endings, because Biome 2.5 formats Astro frontmatter as LF.

Before the first release

Someone with npm admin rights has to set up Trusted Publishing for lenis, following SECURITY.md. Until that's done, the workflow can't publish.

Test plan

  • bun run build passes
  • astro build in playground builds all 10 pages on astro 7.3.5
  • npm pack --dry-run contains only dist/, README.md, LICENSE and package.json
  • The dist-tag routing sends v1.3.27 to latest and v1.3.27-dev.0 to dev
  • tsc --noEmit reports the same 18 errors as main, and astro check reports the same 5. Both were already failing and this PR doesn't fix them
  • Biome reports the same 4 errors as main (all already there)
  • Trusted Publisher configured on npmjs.com
  • The first tag push publishes with a provenance badge on npm

arzafran and others added 7 commits August 11, 2026 09:22
- Tag-triggered release workflow with build provenance
- GitHub Actions pinned by commit SHA, hardened runner
- Tag-version match guard before publish
- Removes manual publish scripts
- Adds SECURITY.md, npm Dependabot tracking, CODEOWNERS for release paths
Bumps the npm_and_yarn group with 1 update in the /playground directory: [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro).


Updates `astro` from 5.18.2 to 7.3.2
- [Release notes](https://github.com/withastro/astro/releases)
- [Changelog](https://github.com/withastro/astro/blob/main/packages/astro/CHANGELOG.md)
- [Commits](https://github.com/withastro/astro/commits/astro@7.3.2/packages/astro)

---
updated-dependencies:
- dependency-name: astro
  dependency-version: 7.3.2
  dependency-type: direct:production
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <support@github.com>
…nd/npm_and_yarn-a0fd20a96d' into chore/maintenance-rollup

# Conflicts:
#	playground/package.json
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
lenis-playground Ready Ready Preview Oct 1, 2026 1:55pm UTC

This branch was successfully deployed

1 active deployment
Preview — 2cf3a671 Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants