mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-06 21:05:21 +02:00
> Follow-up to #11006 (merged): rebased onto master and ready for review. ## Thinking Path > - Paperclip is the open source app people use to manage AI agents for work > - The release subsystem now publishes canary (every master push), nightly (scheduled, smoke-gated, added in #11006), and stable (manual) > - There is still no human-approved release-candidate lane between nightly and stable, and nothing enforces that a stable actually soaked anywhere before shipping > - Betas need a real approval gate, and stables need a soak policy that is data, not prose > - This pull request adds the beta channel: a manual promotion of a chosen nightly behind the `npm-beta` environment gate, re-smoked after publish, plus a stable preflight that enforces a 3-day beta soak with a written-justification bypass > - The benefit is a complete canary → nightly → beta → stable train where every stable shipped as a beta first, and emergencies leave a written trace ## Linked Issues or Issue Description **Subsystem affected** Release automation: `scripts/release.sh`, `scripts/release-lib.sh`, `.github/workflows/release.yml`, `.github/workflows/docker.yml`, `.github/workflows/release-smoke.yml`. **Problem or motivation** After #11006 the project has canary and nightly prerelease lanes, but no release-candidate lane. Stable promotion has no enforced soak: any ref can ship as stable directly. There is no approval boundary for a broader-audience prerelease, and no structured way to record why an emergency release skipped validation. **Proposed solution** Add a `beta` channel: a manual dispatch that promotes a chosen nightly's source commit, publishes behind the `npm-beta` GitHub environment (required reviewers are the gate), re-smokes the published beta, and tags `beta/vX`. Enforce in the stable path that the source commit shipped as a beta at least 3 days earlier (measured from the beta's npm publish time), with a `skip_soak_justification` input as the recorded emergency bypass. **Alternatives considered** Codifying the soak policy in docs only. Rejected: an unenforced policy decays; the preflight makes the policy executable while the justification input keeps the emergency path usable and auditable. ## What Changed - `scripts/release.sh` + `scripts/release-lib.sh`: `beta` channel — requires HEAD to carry a `nightly/v*` tag, publishes the package set as `YYYY.MDD.P-beta.N` under dist-tag `beta`, tags `beta/vYYYY.MDD.P-beta.N` - `.github/workflows/release.yml`: - `channel: beta` dispatch path: `select_beta` resolves the newest (or an explicit `source_version`) nightly and fails loudly on selection problems; `publish_beta` runs behind the `npm-beta` environment, pushes the tag, and dispatches `docker.yml`; `smoke_beta` re-runs the release smoke suite against the exact published beta version - stable path: new `preflight_stable` job enforces the 3-day beta soak from the beta's npm publish time; `skip_soak_justification` bypasses with the reason echoed into the job summary; dry runs report without blocking - `.github/workflows/docker.yml`: `beta/v*` tags publish `:beta` on both images, with exact version stamping - `.github/workflows/release-smoke.yml`: `beta` added to the dispatch choice list - Docs: `CHANNELS.md` beta entries; `RELEASING.md` beta lane, soak gate, and failure playbook; `RELEASE-AUTOMATION-SETUP.md` `npm-beta` environment setup, including the warning to create the environment before the first beta dispatch (GitHub auto-creates unprotected environments on first reference) - Tests: beta version-counting coverage in `scripts/release-registry-versions.test.mjs`; beta identity and nightly-tag guard coverage in `scripts/__tests__/release-dry-run-notes.test.mjs` ## Verification - `node --test` on the two touched suites: 17 pass, including the 3 new beta tests - `bash -n` on both shell scripts and YAML parse of all three workflows - After merge, in order: create the `npm-beta` environment, dispatch `channel: beta` with `dry_run: true` to preview, then a real promotion of a published nightly through the approval gate, then a stable dry-run against a young beta to see the soak gate report ## Risks - If the `npm-beta` environment does not exist when the first beta dispatch runs, GitHub creates it with no protection rules and the beta publishes without approval. Mitigated by documentation and by creating the environment before merge (operator step) - Until the first beta exists, every stable dispatch requires `skip_soak_justification`. This is deliberate — the first beta ships immediately after this merges — but it is a behavior change to the stable dispatch - The soak clock reads the beta's npm publish time from the registry; a registry outage makes the preflight fall back to requiring justification (fail-closed) ## Model Used Claude Fable 5 (`claude-fable-5`, Anthropic) in Claude Code, with extended thinking and full tool use (repository exploration, local test execution, live registry and git verification). All code, tests, and docs in this PR were model-authored under human direction. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either (a) linked existing issues with `Fixes: #` / `Closes #` / `Refs #` OR (b) described the issue in-PR following the relevant issue template - [x] I have not referenced internal/instance-local Paperclip issues or links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip` URLs) - [x] My branch name describes the change (e.g. `docs/...`, `fix/...`) and contains no internal Paperclip ticket id or instance-derived details - [x] I have run tests locally and they pass - [x] I have added or updated tests where applicable - [x] I have updated relevant documentation to reflect my changes - [x] I have considered and documented any risks above - [ ] All Paperclip CI gates are green (pending — will confirm before merge) - [ ] Greptile is 5/5 with no open P2s, recommendations, or follow-ups (pending — will confirm before merge) - [x] I will address all Greptile and reviewer comments before requesting merge
400 lines
14 KiB
Bash
Executable File
400 lines
14 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
REPO_ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
# shellcheck source=./release-lib.sh
|
|
. "$REPO_ROOT/scripts/release-lib.sh"
|
|
CLI_DIR="$REPO_ROOT/cli"
|
|
|
|
channel=""
|
|
release_date=""
|
|
dry_run=false
|
|
skip_verify=false
|
|
print_version_only=false
|
|
tag_name=""
|
|
|
|
cleanup_on_exit=false
|
|
|
|
usage() {
|
|
cat <<'EOF'
|
|
Usage:
|
|
./scripts/release.sh <canary|nightly|beta|stable> [--date YYYY-MM-DD] [--dry-run] [--skip-verify] [--print-version]
|
|
|
|
Examples:
|
|
./scripts/release.sh canary
|
|
./scripts/release.sh canary --date 2026-03-17 --dry-run
|
|
./scripts/release.sh nightly --dry-run
|
|
./scripts/release.sh beta --dry-run
|
|
./scripts/release.sh stable
|
|
./scripts/release.sh stable --date 2026-03-17 --dry-run
|
|
./scripts/release.sh stable --date 2026-03-18 --print-version
|
|
|
|
Notes:
|
|
- Stable versions use YYYY.MDD.P, where M is the UTC month, DD is the
|
|
zero-padded UTC day, and P is the same-day stable patch slot.
|
|
- Canary releases publish YYYY.MDD.P-canary.N under the npm dist-tag
|
|
"canary" and create the git tag canary/vYYYY.MDD.P-canary.N.
|
|
- Nightly releases republish a commit that already shipped a canary (HEAD
|
|
must carry a canary/v* tag) as YYYY.MDD.P-nightly.N under the npm
|
|
dist-tag "nightly", with the git tag nightly/vYYYY.MDD.P-nightly.N.
|
|
The version dates the nightly cut, not the source canary.
|
|
- Beta releases republish a commit that already shipped a nightly (HEAD
|
|
must carry a nightly/v* tag) as YYYY.MDD.P-beta.N under the npm
|
|
dist-tag "beta", with the git tag beta/vYYYY.MDD.P-beta.N.
|
|
- Stable releases publish YYYY.MDD.P under the npm dist-tag "latest" and
|
|
create the git tag vYYYY.MDD.P.
|
|
- Non-dry-run stable release notes must already exist at releases/vYYYY.MDD.P.md.
|
|
- The script rewrites versions temporarily and restores the working tree on
|
|
exit. Tags always point at the original source commit, not a generated
|
|
release commit.
|
|
EOF
|
|
}
|
|
|
|
restore_publish_artifacts() {
|
|
if [ -f "$CLI_DIR/package.dev.json" ]; then
|
|
mv "$CLI_DIR/package.dev.json" "$CLI_DIR/package.json"
|
|
fi
|
|
|
|
rm -f "$CLI_DIR/README.md"
|
|
rm -rf "$REPO_ROOT/server/ui-dist"
|
|
|
|
for pkg_dir in server packages/adapters/claude-local packages/adapters/codex-local; do
|
|
rm -rf "$REPO_ROOT/$pkg_dir/skills"
|
|
done
|
|
}
|
|
|
|
cleanup_release_state() {
|
|
restore_publish_artifacts
|
|
|
|
tracked_changes="$(git -C "$REPO_ROOT" diff --name-only; git -C "$REPO_ROOT" diff --cached --name-only)"
|
|
if [ -n "$tracked_changes" ]; then
|
|
printf '%s\n' "$tracked_changes" | sort -u | while IFS= read -r path; do
|
|
[ -z "$path" ] && continue
|
|
git -C "$REPO_ROOT" checkout -q HEAD -- "$path" || true
|
|
done
|
|
fi
|
|
|
|
untracked_changes="$(git -C "$REPO_ROOT" ls-files --others --exclude-standard)"
|
|
if [ -n "$untracked_changes" ]; then
|
|
printf '%s\n' "$untracked_changes" | while IFS= read -r path; do
|
|
[ -z "$path" ] && continue
|
|
if [ -d "$REPO_ROOT/$path" ]; then
|
|
rm -rf "$REPO_ROOT/$path"
|
|
else
|
|
rm -f "$REPO_ROOT/$path"
|
|
fi
|
|
done
|
|
fi
|
|
}
|
|
|
|
set_cleanup_trap() {
|
|
cleanup_on_exit=true
|
|
trap cleanup_release_state EXIT
|
|
}
|
|
|
|
while [ $# -gt 0 ]; do
|
|
case "$1" in
|
|
canary|nightly|beta|stable)
|
|
if [ -n "$channel" ]; then
|
|
release_fail "only one release channel may be provided."
|
|
fi
|
|
channel="$1"
|
|
;;
|
|
--date)
|
|
shift
|
|
[ $# -gt 0 ] || release_fail "--date requires YYYY-MM-DD."
|
|
release_date="$1"
|
|
;;
|
|
--dry-run) dry_run=true ;;
|
|
--skip-verify) skip_verify=true ;;
|
|
--print-version) print_version_only=true ;;
|
|
-h|--help)
|
|
usage
|
|
exit 0
|
|
;;
|
|
*)
|
|
release_fail "unexpected argument: $1"
|
|
;;
|
|
esac
|
|
shift
|
|
done
|
|
|
|
[ -n "$channel" ] || {
|
|
usage
|
|
exit 1
|
|
}
|
|
|
|
PUBLISH_REMOTE="$(resolve_release_remote)"
|
|
fetch_release_remote "$PUBLISH_REMOTE"
|
|
|
|
CURRENT_BRANCH="$(git_current_branch)"
|
|
CURRENT_SHA="$(git -C "$REPO_ROOT" rev-parse HEAD)"
|
|
LAST_STABLE_TAG="$(get_last_stable_tag)"
|
|
CURRENT_STABLE_VERSION="$(get_current_stable_version)"
|
|
RELEASE_DATE="${release_date:-$(utc_date_iso)}"
|
|
|
|
PUBLIC_PACKAGE_INFO="$(list_public_package_info)"
|
|
PUBLIC_PACKAGE_NAMES=()
|
|
while IFS= read -r package_name; do
|
|
[ -n "$package_name" ] || continue
|
|
PUBLIC_PACKAGE_NAMES+=("$package_name")
|
|
done < <(printf '%s\n' "$PUBLIC_PACKAGE_INFO" | cut -f2)
|
|
|
|
[ -n "$PUBLIC_PACKAGE_INFO" ] || release_fail "no public packages were found in the workspace."
|
|
|
|
# Pre-fetch published versions for every public package in parallel so the
|
|
# version helpers below do not each issue one serial `npm view` call per
|
|
# package (see scripts/release-registry-versions.mjs).
|
|
RELEASE_PACKAGE_VERSIONS_FILE="$(mktemp)"
|
|
export RELEASE_PACKAGE_VERSIONS_FILE
|
|
node "$REPO_ROOT/scripts/release-registry-versions.mjs" fetch "${PUBLIC_PACKAGE_NAMES[@]}" > "$RELEASE_PACKAGE_VERSIONS_FILE"
|
|
|
|
TARGET_STABLE_VERSION="$(next_stable_version "$RELEASE_DATE" "${PUBLIC_PACKAGE_NAMES[@]}")"
|
|
TARGET_PUBLISH_VERSION="$TARGET_STABLE_VERSION"
|
|
DIST_TAG="latest"
|
|
|
|
if [ "$channel" = "canary" ]; then
|
|
require_on_master_branch
|
|
TARGET_PUBLISH_VERSION="$(next_prerelease_version canary "$TARGET_STABLE_VERSION" "${PUBLIC_PACKAGE_NAMES[@]}")"
|
|
DIST_TAG="canary"
|
|
tag_name="$(prerelease_tag_name canary "$TARGET_PUBLISH_VERSION")"
|
|
elif [ "$channel" = "nightly" ]; then
|
|
# Nightly promotes an already-shipped canary commit, so it runs from a
|
|
# detached checkout of that commit rather than the master branch tip.
|
|
require_channel_tag_at_head canary
|
|
require_channel_tag_absent_at_head nightly
|
|
TARGET_PUBLISH_VERSION="$(next_prerelease_version nightly "$TARGET_STABLE_VERSION" "${PUBLIC_PACKAGE_NAMES[@]}")"
|
|
DIST_TAG="nightly"
|
|
tag_name="$(prerelease_tag_name nightly "$TARGET_PUBLISH_VERSION")"
|
|
elif [ "$channel" = "beta" ]; then
|
|
# Beta promotes an already-shipped nightly commit.
|
|
require_channel_tag_at_head nightly
|
|
require_channel_tag_absent_at_head beta
|
|
TARGET_PUBLISH_VERSION="$(next_prerelease_version beta "$TARGET_STABLE_VERSION" "${PUBLIC_PACKAGE_NAMES[@]}")"
|
|
DIST_TAG="beta"
|
|
tag_name="$(prerelease_tag_name beta "$TARGET_PUBLISH_VERSION")"
|
|
else
|
|
tag_name="$(stable_tag_name "$TARGET_STABLE_VERSION")"
|
|
fi
|
|
|
|
rm -f "$RELEASE_PACKAGE_VERSIONS_FILE"
|
|
unset RELEASE_PACKAGE_VERSIONS_FILE
|
|
|
|
if [ "$print_version_only" = true ]; then
|
|
printf '%s\n' "$TARGET_PUBLISH_VERSION"
|
|
exit 0
|
|
fi
|
|
|
|
NOTES_FILE="$(release_notes_file "$TARGET_STABLE_VERSION")"
|
|
|
|
require_clean_worktree
|
|
require_npm_publish_auth "$dry_run"
|
|
|
|
if [ "$channel" = "stable" ] && [ "$dry_run" = false ] && [ ! -f "$NOTES_FILE" ]; then
|
|
release_fail "stable release notes file is required at $NOTES_FILE before publishing stable."
|
|
fi
|
|
|
|
if [ "$channel" = "canary" ] && [ -f "$NOTES_FILE" ]; then
|
|
release_info " ✓ Stable release notes already exist at $NOTES_FILE"
|
|
fi
|
|
|
|
if git_local_tag_exists "$tag_name" || git_remote_tag_exists "$tag_name" "$PUBLISH_REMOTE"; then
|
|
release_fail "git tag $tag_name already exists locally or on $PUBLISH_REMOTE."
|
|
fi
|
|
|
|
# Fresh (non-cached) existence check, batched in parallel. Prints the
|
|
# offending package@version pairs itself before failing.
|
|
node "$REPO_ROOT/scripts/release-registry-versions.mjs" assert-absent "$TARGET_PUBLISH_VERSION" "${PUBLIC_PACKAGE_NAMES[@]}" \
|
|
|| release_fail "npm version ${TARGET_PUBLISH_VERSION} already exists for one or more packages."
|
|
|
|
release_info ""
|
|
release_info "==> Release plan"
|
|
release_info " Remote: $PUBLISH_REMOTE"
|
|
release_info " Channel: $channel"
|
|
release_info " Current branch: ${CURRENT_BRANCH:-<detached>}"
|
|
release_info " Source commit: $CURRENT_SHA"
|
|
release_info " Last stable tag: ${LAST_STABLE_TAG:-<none>}"
|
|
release_info " Current stable version: $CURRENT_STABLE_VERSION"
|
|
release_info " Release date (UTC): $RELEASE_DATE"
|
|
release_info " Target stable version: $TARGET_STABLE_VERSION"
|
|
case "$channel" in
|
|
canary) release_info " Canary version: $TARGET_PUBLISH_VERSION" ;;
|
|
nightly) release_info " Nightly version: $TARGET_PUBLISH_VERSION" ;;
|
|
beta) release_info " Beta version: $TARGET_PUBLISH_VERSION" ;;
|
|
*) release_info " Stable version: $TARGET_PUBLISH_VERSION" ;;
|
|
esac
|
|
release_info " Dist-tag: $DIST_TAG"
|
|
release_info " Git tag: $tag_name"
|
|
if [ "$channel" = "stable" ]; then
|
|
release_info " Release notes: $NOTES_FILE"
|
|
fi
|
|
|
|
set_cleanup_trap
|
|
|
|
# The release flow already prepares ui/dist before packaging. Reuse that output
|
|
# so server prepack does not rebuild the UI a second time during preview/publish.
|
|
export PAPERCLIP_RELEASE_REUSE_UI_DIST=1
|
|
|
|
if [ "$skip_verify" = false ]; then
|
|
release_info ""
|
|
release_info "==> Step 1/7: Verification gate..."
|
|
cd "$REPO_ROOT"
|
|
pnpm -r typecheck
|
|
pnpm test:run
|
|
pnpm build
|
|
else
|
|
release_info ""
|
|
release_info "==> Step 1/7: Verification gate skipped (--skip-verify)"
|
|
fi
|
|
|
|
release_info ""
|
|
release_info "==> Step 2/7: Building workspace artifacts..."
|
|
cd "$REPO_ROOT"
|
|
pnpm build
|
|
node "$REPO_ROOT/scripts/build-standalone-public-packages.mjs"
|
|
bash "$REPO_ROOT/scripts/prepare-server-ui-dist.sh"
|
|
for pkg_dir in server packages/adapters/claude-local packages/adapters/codex-local; do
|
|
rm -rf "$REPO_ROOT/$pkg_dir/skills"
|
|
cp -r "$REPO_ROOT/skills" "$REPO_ROOT/$pkg_dir/skills"
|
|
done
|
|
release_info " ✓ Workspace build complete"
|
|
|
|
release_info ""
|
|
release_info "==> Step 3/7: Rewriting workspace versions..."
|
|
set_public_package_version "$TARGET_PUBLISH_VERSION"
|
|
release_info " ✓ Versioned workspace to $TARGET_PUBLISH_VERSION"
|
|
|
|
release_info ""
|
|
release_info "==> Step 4/7: Building publishable CLI bundle..."
|
|
"$REPO_ROOT/scripts/build-npm.sh" --skip-checks --skip-typecheck
|
|
release_info " ✓ CLI bundle ready"
|
|
|
|
VERSIONED_PACKAGE_INFO="$(list_public_package_info)"
|
|
VERSION_IN_CLI_PACKAGE="$(node -e "console.log(require('$CLI_DIR/package.json').version)")"
|
|
if [ "$VERSION_IN_CLI_PACKAGE" != "$TARGET_PUBLISH_VERSION" ]; then
|
|
release_fail "versioning drift detected. Expected $TARGET_PUBLISH_VERSION but found $VERSION_IN_CLI_PACKAGE."
|
|
fi
|
|
|
|
VERIFY_ATTEMPTS="${NPM_PUBLISH_VERIFY_ATTEMPTS:-12}"
|
|
VERIFY_DELAY_SECONDS="${NPM_PUBLISH_VERIFY_DELAY_SECONDS:-5}"
|
|
|
|
release_info ""
|
|
if [ "$dry_run" = true ]; then
|
|
release_info "==> Step 5/7: Previewing publish payloads (--dry-run)..."
|
|
while IFS=$'\t' read -r pkg_dir _pkg_name _pkg_version; do
|
|
[ -z "$pkg_dir" ] && continue
|
|
release_info " --- $pkg_dir ---"
|
|
cd "$REPO_ROOT/$pkg_dir"
|
|
publish_tool="$(package_publish_tool)"
|
|
if [ "$publish_tool" = "npm" ]; then
|
|
publish_dir="$(mktemp -d "${TMPDIR:-/tmp}/paperclip-release-package.XXXXXX")"
|
|
node "$REPO_ROOT/scripts/prepare-bundled-package.mjs" "$REPO_ROOT/$pkg_dir" "$publish_dir"
|
|
cd "$publish_dir"
|
|
run_bundled_npm_pack pack --pack-destination "$publish_dir" 2>&1 | tail -3
|
|
rm -rf "$publish_dir"
|
|
else
|
|
pnpm publish --dry-run --no-git-checks --tag "$DIST_TAG" 2>&1 | tail -3
|
|
fi
|
|
done <<< "$VERSIONED_PACKAGE_INFO"
|
|
release_info " [dry-run] Would create git tag $tag_name on $CURRENT_SHA"
|
|
else
|
|
release_info "==> Step 5/7: Publishing packages to npm..."
|
|
while IFS=$'\t' read -r pkg_dir pkg_name pkg_version; do
|
|
[ -z "$pkg_dir" ] && continue
|
|
release_info " Publishing $pkg_name@$pkg_version"
|
|
cd "$REPO_ROOT/$pkg_dir"
|
|
publish_tool="$(package_publish_tool)"
|
|
if [ "$publish_tool" = "npm" ]; then
|
|
publish_dir="$(mktemp -d "${TMPDIR:-/tmp}/paperclip-release-package.XXXXXX")"
|
|
node "$REPO_ROOT/scripts/prepare-bundled-package.mjs" "$REPO_ROOT/$pkg_dir" "$publish_dir"
|
|
cd "$publish_dir"
|
|
fi
|
|
if ! publish_package_to_npm_and_wait \
|
|
"$DIST_TAG" \
|
|
"$pkg_name" \
|
|
"$pkg_version" \
|
|
"$publish_tool" \
|
|
"$VERIFY_ATTEMPTS" \
|
|
"$VERIFY_DELAY_SECONDS"; then
|
|
if [ "$publish_tool" = "npm" ]; then
|
|
rm -rf "$publish_dir"
|
|
fi
|
|
release_fail "stopping release: npm did not publish and expose ${pkg_name}@${pkg_version}"
|
|
fi
|
|
if [ "$publish_tool" = "npm" ]; then
|
|
rm -rf "$publish_dir"
|
|
fi
|
|
release_info " ✓ Published version is registry-visible"
|
|
done <<< "$VERSIONED_PACKAGE_INFO"
|
|
release_info " ✓ Published the full package set under dist-tag $DIST_TAG"
|
|
fi
|
|
|
|
release_info ""
|
|
if [ "$dry_run" = true ]; then
|
|
release_info "==> Step 6/7: Skipping npm verification in dry-run mode..."
|
|
else
|
|
release_info "==> Step 6/7: Confirming npm package availability and dist-tag integrity..."
|
|
REGISTRY_STATE_VERIFY_ATTEMPTS="${NPM_REGISTRY_STATE_VERIFY_ATTEMPTS:-12}"
|
|
REGISTRY_STATE_VERIFY_DELAY_SECONDS="${NPM_REGISTRY_STATE_VERIFY_DELAY_SECONDS:-5}"
|
|
release_info " ✓ Every version was registry-visible before the next package publish"
|
|
|
|
verify_args=(
|
|
--channel "$channel"
|
|
--dist-tag "$DIST_TAG"
|
|
--target-version "$TARGET_PUBLISH_VERSION"
|
|
)
|
|
while IFS=$'\t' read -r _pkg_dir pkg_name _pkg_version; do
|
|
[ -z "$pkg_name" ] && continue
|
|
verify_args+=(--package "$pkg_name")
|
|
done <<< "$VERSIONED_PACKAGE_INFO"
|
|
|
|
release_info " Waiting for npm dist-tags and package metadata to converge..."
|
|
if wait_for_release_registry_state \
|
|
"$REGISTRY_STATE_VERIFY_ATTEMPTS" \
|
|
"$REGISTRY_STATE_VERIFY_DELAY_SECONDS" \
|
|
"${verify_args[@]}"; then
|
|
:
|
|
else
|
|
verify_status=$?
|
|
if [ "$verify_status" -eq 2 ]; then
|
|
release_fail "publish completed, but registry verification failed immediately for ${TARGET_PUBLISH_VERSION}; dist-tag state is wrong or requires operator intervention"
|
|
fi
|
|
|
|
release_fail "publish completed, but npm dist-tags or registry metadata never converged for ${TARGET_PUBLISH_VERSION}"
|
|
fi
|
|
|
|
release_info " Installing paperclipai@$DIST_TAG into a clean prefix..."
|
|
if ! verify_npm_installable "paperclipai@$DIST_TAG" "$TARGET_PUBLISH_VERSION"; then
|
|
release_fail "paperclipai@$DIST_TAG did not install cleanly at expected version ${TARGET_PUBLISH_VERSION}"
|
|
fi
|
|
release_info " ✓ Clean-prefix install resolved ${TARGET_PUBLISH_VERSION}"
|
|
fi
|
|
|
|
release_info ""
|
|
if [ "$dry_run" = true ]; then
|
|
release_info "==> Step 7/7: Dry run complete..."
|
|
else
|
|
release_info "==> Step 7/7: Creating git tag..."
|
|
git -C "$REPO_ROOT" tag "$tag_name" "$CURRENT_SHA"
|
|
release_info " ✓ Created tag $tag_name on $CURRENT_SHA"
|
|
fi
|
|
|
|
release_info ""
|
|
if [ "$dry_run" = true ]; then
|
|
release_info "Dry run complete for $channel ${TARGET_PUBLISH_VERSION}."
|
|
else
|
|
case "$channel" in
|
|
canary|nightly|beta)
|
|
release_info "Published $channel ${TARGET_PUBLISH_VERSION}."
|
|
release_info "Install with: npx paperclipai@$channel onboard"
|
|
release_info "Next step: git push ${PUBLISH_REMOTE} refs/tags/${tag_name}"
|
|
;;
|
|
*)
|
|
release_info "Published stable ${TARGET_PUBLISH_VERSION}."
|
|
release_info "Next steps:"
|
|
release_info " git push ${PUBLISH_REMOTE} refs/tags/${tag_name}"
|
|
release_info " ./scripts/create-github-release.sh $TARGET_STABLE_VERSION"
|
|
;;
|
|
esac
|
|
fi
|