Files
PaperClipAI/scripts/release-lib.test.mjs
T
DottaandPaperclip 47c38777d8 fix(release): use trusted publishing npm for bundled packages (#10030)
## Thinking Path

> - Paperclip is the open source app people use to manage AI agents for
work
> - Paperclip publishes canary and stable packages through a shared
release script
> - GitHub Actions authenticates those publishes through npm trusted
publishing and an OIDC identity token
> - Bundled-dependency packages recently moved from pnpm publish to a
pinned npm CLI to preserve their bundled files
> - That pin selected npm 10, which cannot use trusted publishing, so
the first bundled package failed with `ENEEDAUTH`
> - This pull request keeps bundled-package packing on npm 10 while
routing actual publishing through the trusted-publishing-capable npm 11
version
> - The benefit is bundled packages keep their required npm packaging
behavior while canary and stable releases authenticate successfully

## Linked Issues or Issue Description

**What happened**

The canary release job failed while publishing
`@paperclipai/adapter-utils` with `ENEEDAUTH`. The package has bundled
dependencies, so the release helper selected pinned `npm@10.9.7`; the
workflow provides OIDC trusted publishing rather than an npm token, and
npm 10 cannot use that authentication path. Because this is the first
package attempted, the release exited before trying the remaining
packages.

**Expected behavior**

Bundled-dependency packages should publish with an npm CLI that both
preserves bundled dependencies and supports GitHub Actions trusted
publishing.

**Steps to reproduce**

Run the canary release workflow from master after PR #9980. The
`publish_canary` job reaches `@paperclipai/adapter-utils`, invokes `npx
npm@10.9.7 publish`, and fails with `ENEEDAUTH`.

**Deployment mode**

GitHub Actions canary and stable npm release workflows.

Refs #9980.

## What Changed

- Kept bundled-package dry-run packing on npm `10.9.7`, which
successfully produces the staged tarball.
- Routed bundled-package publishing through npm `11.16.0`, which
supports GitHub Actions trusted publishing.
- Split the pack and publish helpers so future npm changes cannot
silently couple the two compatibility requirements.
- Updated focused release and ACPX packaging tests to enforce both
versions and call paths.

## Verification

- `pnpm test:release-registry` — 67 passed locally.
- Initial all-npm-11 PR head: Canary Dry Run reproduced an npm-internal
crash during bundled `pack`.
- Current head `5b3961ed13dd26ed2d6b1096ea23fd91b32e4353`: Canary Dry
Run passed with split npm pack/publish helpers.
- All PR checks passed, including build, typecheck + release registry,
server/workspace suites, both e2e shards, security gates, and Greptile.
- Greptile reviewed the current head at 5/5 confidence with no blocking
issues.

## Risks

- Low risk: the change only separates the npm CLI used for
bundled-package packing from the CLI used for publishing.
- The versions remain explicitly pinned because npm 11.16.0 currently
crashes on the bundled pack payload, while npm 10.9.7 cannot perform
trusted publishing.
- Focused tests assert both pins and both helper call paths, and the
full Canary Dry Run passes on the current head.

> For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and
discuss it in `#dev` before opening the PR. Feature PRs that overlap
with planned core work may need to be redirected — check the roadmap
first. See `CONTRIBUTING.md`.

## Model Used

- OpenAI Codex, exact model ID `gpt-5.6-sol`, high reasoning mode, with
repository, shell, GitHub CLI, and code-execution tools.

## Checklist

- [x] I have included a thinking path that traces from project context
to this change
- [x] I have specified the model used (with version and capability
details)
- [x] I have checked ROADMAP.md and confirmed this PR does not duplicate
planned core work
- [x] I have searched GitHub for duplicate or related PRs and linked
them above
- [x] I have either (a) linked existing issues with `Fixes: #` / `Closes
#` / `Refs #` OR (b) described the issue in-PR following the relevant
issue template
- [x] I have not referenced internal/instance-local Paperclip issues or
links (only public GitHub `#NNN` / `github.com/paperclipai/paperclip`
URLs)
- [x] My branch name describes the change (e.g. `docs/...`, `fix/...`)
and contains no internal Paperclip ticket id or instance-derived details
- [x] I have run tests locally and they pass
- [x] I have added or updated tests where applicable
- [x] I have updated relevant documentation to reflect my changes
- [x] I have considered and documented any risks above
- [x] All Paperclip CI gates are green
- [x] Greptile is 5/5 with no open P2s, recommendations, or follow-ups
- [x] I will address all Greptile and reviewer comments before
requesting merge

---------

Co-authored-by: Paperclip <noreply@paperclip.ing>
2026-07-22 13:19:15 -05:00

195 lines
5.8 KiB
JavaScript

import assert from "node:assert/strict";
import { execFileSync } from "node:child_process";
import { mkdirSync, mkdtempSync, readFileSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import test from "node:test";
const repoRoot = new URL("..", import.meta.url).pathname.replace(/\/$/, "");
function writeExecutable(path, body) {
writeFileSync(path, body, { mode: 0o755 });
}
function runPublishHelper({
pnpmMode,
npmVersionExists = false,
distTag = "canary",
callerPipefail = true,
publishTool = "pnpm",
}) {
const fixtureDir = mkdtempSync(join(tmpdir(), "paperclip-release-lib-"));
const binDir = join(fixtureDir, "bin");
const stateDir = join(fixtureDir, "state");
const callLog = join(fixtureDir, "calls.log");
mkdirSync(binDir);
mkdirSync(stateDir);
writeFileSync(callLog, "");
writeExecutable(
join(binDir, "pnpm"),
`#!/usr/bin/env bash
set -euo pipefail
printf 'pnpm %s\\n' "$*" >> "$FAKE_CALL_LOG"
case "$PNPM_MODE" in
success)
echo "published"
exit 0
;;
tlog-then-success)
if [ ! -f "$FAKE_STATE_DIR/pnpm-called" ]; then
touch "$FAKE_STATE_DIR/pnpm-called"
echo "npm error code TLOG_CREATE_ENTRY_ERROR"
echo "npm error error creating tlog entry - (409) an equivalent entry already exists in the transparency log with UUID abc"
exit 1
fi
case " $* " in
*" --provenance=false "*)
echo "published without provenance"
exit 0
;;
*)
echo "retry did not disable provenance"
exit 1
;;
esac
;;
tlog-always-fails)
echo "npm error code TLOG_CREATE_ENTRY_ERROR"
echo "npm error error creating tlog entry - (409) an equivalent entry already exists in the transparency log with UUID abc"
exit 1
;;
non-tlog-failure)
echo "npm error code E500"
exit 1
;;
esac
exit 1
`,
);
writeExecutable(
join(binDir, "npm"),
`#!/usr/bin/env bash
set -euo pipefail
printf 'npm %s\\n' "$*" >> "$FAKE_CALL_LOG"
if [ "$1" = "view" ] && [ "$NPM_VERSION_EXISTS" = "true" ]; then
echo "1.2.3"
exit 0
fi
if [ "$1" = "publish" ]; then
echo "published"
exit 0
fi
exit 1
`,
);
writeExecutable(
join(binDir, "npx"),
`#!/usr/bin/env bash
set -euo pipefail
printf 'npx %s\n' "$*" >> "$FAKE_CALL_LOG"
[ "$1" = "--yes" ] && shift
[ "$1" = "npm@11.16.0" ] && shift
exec npm "$@"
`,
);
const shellOptions = callerPipefail ? "set -euo pipefail" : "set -eu";
const script = `
${shellOptions}
source "${repoRoot}/scripts/release-lib.sh"
publish_package_to_npm ${distTag} @paperclipai/example 1.2.3 ${publishTool}
`;
let status = 0;
let output = "";
try {
output = execFileSync("bash", ["-c", script], {
cwd: fixtureDir,
encoding: "utf8",
env: {
...process.env,
PATH: `${binDir}:${process.env.PATH}`,
FAKE_CALL_LOG: callLog,
FAKE_STATE_DIR: stateDir,
NPM_VERSION_EXISTS: npmVersionExists ? "true" : "false",
PNPM_MODE: pnpmMode,
REPO_ROOT: fixtureDir,
},
stdio: ["ignore", "pipe", "pipe"],
});
} catch (error) {
status = error.status ?? 1;
output = `${error.stdout ?? ""}${error.stderr ?? ""}`;
}
return {
calls: readFileSync(callLog, "utf8"),
output,
status,
};
}
test("publish_package_to_npm returns after a successful pnpm publish", () => {
const result = runPublishHelper({ pnpmMode: "success" });
assert.equal(result.status, 0);
assert.match(result.calls, /^pnpm publish --no-git-checks --tag canary --access public$/m);
assert.doesNotMatch(result.calls, /npm view/);
assert.doesNotMatch(result.calls, /--provenance=false/);
});
test("publish_package_to_npm uses trusted-publishing-capable npm for bundled dependencies", () => {
const result = runPublishHelper({ pnpmMode: "success", publishTool: "npm" });
assert.equal(result.status, 0);
assert.match(result.calls, /^npx --yes npm@11\.16\.0 publish --tag canary --access public$/m);
assert.match(result.calls, /^npm publish --tag canary --access public$/m);
assert.doesNotMatch(result.calls, /^pnpm publish/m);
});
test("publish_package_to_npm retries duplicate tlog failures without provenance", () => {
const result = runPublishHelper({ pnpmMode: "tlog-then-success" });
assert.equal(result.status, 0);
assert.match(result.calls, /^npm view @paperclipai\/example@1\.2\.3 version$/m);
assert.match(
result.calls,
/^pnpm publish --no-git-checks --tag canary --access public --provenance=false$/m,
);
});
test("publish_package_to_npm treats a duplicate tlog failure as complete when npm exposes the version", () => {
const result = runPublishHelper({ pnpmMode: "tlog-always-fails", npmVersionExists: true });
assert.equal(result.status, 0);
assert.match(result.calls, /^npm view @paperclipai\/example@1\.2\.3 version$/m);
assert.doesNotMatch(result.calls, /--provenance=false/);
});
test("publish_package_to_npm does not retry unrelated publish failures", () => {
const result = runPublishHelper({ pnpmMode: "non-tlog-failure" });
assert.notEqual(result.status, 0);
assert.doesNotMatch(result.calls, /npm view/);
assert.doesNotMatch(result.calls, /--provenance=false/);
});
test("publish_package_to_npm does not mask failures when caller has no pipefail", () => {
const result = runPublishHelper({ pnpmMode: "non-tlog-failure", callerPipefail: false });
assert.notEqual(result.status, 0);
assert.doesNotMatch(result.calls, /npm view/);
assert.doesNotMatch(result.calls, /--provenance=false/);
});
test("publish_package_to_npm does not retry stable publishes without provenance", () => {
const result = runPublishHelper({ pnpmMode: "tlog-then-success", distTag: "latest" });
assert.notEqual(result.status, 0);
assert.match(result.calls, /^npm view @paperclipai\/example@1\.2\.3 version$/m);
assert.doesNotMatch(result.calls, /--provenance=false/);
});