mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 16:11:46 +02:00
Bumps [paperclipai/paperclip/.github/workflows/pr-trusted.yml](https://github.com/paperclipai/paperclip) from39b8ee2960tof038633bf5. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/paperclipai/paperclip/blob/master/doc/RELEASE-AUTOMATION-SETUP.md">paperclipai/paperclip/.github/workflows/pr-trusted.yml's changelog</a>.</em></p> <blockquote> <h1>Release Automation Setup</h1> <p>This document covers the GitHub and npm setup required for the current Paperclip release model:</p> <ul> <li>automatic canaries from <code>master</code></li> <li>manual stable promotion from a chosen source ref</li> <li>npm trusted publishing via GitHub OIDC</li> <li>protected release infrastructure in a public repository</li> </ul> <p>Repo-side files that depend on this setup:</p> <ul> <li><code>.github/workflows/release.yml</code></li> <li><code>.github/CODEOWNERS</code></li> </ul> <p>Note:</p> <ul> <li>the release workflows intentionally use <code>pnpm install --no-frozen-lockfile</code></li> <li>this matches the repo's current policy where <code>pnpm-lock.yaml</code> is refreshed by GitHub automation after manifest changes land on <code>master</code></li> <li>the publish jobs then restore <code>pnpm-lock.yaml</code> before running <code>scripts/release.sh</code>, so the release script still sees a clean worktree</li> </ul> <h2>1. Merge the Repo Changes First</h2> <p>Before touching GitHub or npm settings, merge the release automation code so the referenced workflow filenames already exist on the default branch.</p> <p>Required files:</p> <ul> <li><code>.github/workflows/release.yml</code></li> <li><code>.github/CODEOWNERS</code></li> </ul> <h2>2. Configure npm Trusted Publishing</h2> <p>Do this for every public package that Paperclip publishes.</p> <p>At minimum that includes:</p> <ul> <li><code>paperclipai</code></li> <li><code>@paperclipai/server</code></li> <li><code>@paperclipai/ui</code></li> <li>public packages under <code>packages/</code></li> </ul> <h3>2.1. In npm, open each package settings page</h3> <p>For each package:</p> <ol> <li>open npm as an owner of the package</li> <li>go to the package settings / publishing access area</li> <li>add a trusted publisher for the GitHub repository <code>paperclipai/paperclip</code></li> </ol> <h3>2.2. Add one trusted publisher entry per package</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/paperclipai/paperclip/commit/f038633bf5b04163ff985ef0542876bd9f455379"><code>f038633</code></a> feat(runner): reduce ACPX provider state (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12417">#12417</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/7bb6cebeae727a16c205bb80b5c2b9e92ea6b5fa"><code>7bb6ceb</code></a> feat(runner): normalize ACPX provider events (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12416">#12416</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/fe2ddfad2b5cb604b3244492257db0e6aec11d47"><code>fe2ddfa</code></a> feat(runner): validate ACPX event payloads (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12415">#12415</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/3db24d9366831559b1219782475e760ec041b639"><code>3db24d9</code></a> feat(runner): bind ACPX event scope (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12414">#12414</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/75708fec6d421a247ba2fc832997de24ed10a085"><code>75708fe</code></a> feat(runner): add ACPX sidecar transport (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12412">#12412</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/9ad8dbffa0a4759dcda2769042d6e8f02adcdf8d"><code>9ad8dbf</code></a> feat(runner): add Codex ACPX sidecar (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12410">#12410</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/b93ad538b63c81a1e3d24bbb54c02f8effdea787"><code>b93ad53</code></a> test(runner): add question adapter conformance (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12409">#12409</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/4fe3189f0256873a359d2d53c209076919fd1c3b"><code>4fe3189</code></a> feat(runner): bridge Codex ACPX questions (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12408">#12408</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/96421b0663d8b740ac5d5d53359aef65c5a158ca"><code>96421b0</code></a> feat(runner): recover settled Codex ACPX sessions (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12407">#12407</a>)</li> <li><a href="https://github.com/paperclipai/paperclip/commit/30ef14edd4e7290d9eac43ca7b7835611933cc74"><code>30ef14e</code></a> feat(runner): wire the Codex ACPX backend (<a href="https://redirect.github.com/paperclipai/paperclip/issues/12406">#12406</a>)</li> <li>Additional commits viewable in <a href="https://github.com/paperclipai/paperclip/compare/39b8ee2960541d14b380f95365deecba6723d9bd...f038633bf5b04163ff985ef0542876bd9f455379">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
14 lines
218 B
YAML
14 lines
218 B
YAML
name: PR
|
|
|
|
on:
|
|
pull_request:
|
|
|
|
permissions:
|
|
actions: read
|
|
contents: read
|
|
pull-requests: read
|
|
|
|
jobs:
|
|
ci:
|
|
uses: paperclipai/paperclip/.github/workflows/pr-trusted.yml@f038633bf5b04163ff985ef0542876bd9f455379
|