From 6da62960c11a16212cae04dc1e05672d492b8d1b Mon Sep 17 00:00:00 2001 From: ProgramComputer <22284856+ProgramComputer@users.noreply.github.com> Date: Tue, 29 Sep 2026 14:45:56 -0500 Subject: [PATCH] Create the registry download folder in the package gate and run release verification with the harness from main --- .github/workflows/verify-release.yml | 5 +++-- scripts/package-smoke.mjs | 3 ++- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/.github/workflows/verify-release.yml b/.github/workflows/verify-release.yml index 1df271b..47288d5 100644 --- a/.github/workflows/verify-release.yml +++ b/.github/workflows/verify-release.yml @@ -50,9 +50,11 @@ jobs: [[ "$TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]] || { echo "::error::tag must look like v1.2.3"; exit 1; } [[ "$INTEGRITY" =~ ^sha512-[A-Za-z0-9+/]{86}==$ ]] || { echo "::error::integrity must be a sha512-... value"; exit 1; } + # The verification harness (scripts and tests) comes from the branch this + # workflow runs on, so harness fixes apply to already-tagged releases. The + # package under test comes from the registry, pinned by the tested integrity. - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - ref: refs/tags/${{ inputs.tag }} persist-credentials: false - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 @@ -71,7 +73,6 @@ jobs: run: | set -euo pipefail VERSION="${TAG#v}" - [[ "$(node -p "require('./package.json').version")" == "$VERSION" ]] || { echo "::error::tag and package.json disagree"; exit 1; } published="" for i in $(seq 1 30); do published=$(npm view "$PACKAGE@$VERSION" dist.integrity --prefer-online 2>/dev/null || true) diff --git a/scripts/package-smoke.mjs b/scripts/package-smoke.mjs index ed24504..688c9b5 100644 --- a/scripts/package-smoke.mjs +++ b/scripts/package-smoke.mjs @@ -9,7 +9,7 @@ import { spawnSync } from 'node:child_process'; import { createHash } from 'node:crypto'; import { gunzipSync } from 'node:zlib'; -import { mkdtempSync, readFileSync, readdirSync, realpathSync, rmSync, writeFileSync, existsSync } from 'node:fs'; +import { existsSync, mkdirSync, mkdtempSync, readFileSync, readdirSync, realpathSync, rmSync, writeFileSync } from 'node:fs'; import { tmpdir } from 'node:os'; import { join, resolve, sep } from 'node:path'; import { fileURLToPath } from 'node:url'; @@ -102,6 +102,7 @@ try { if (registrySpec) { const downloads = join(work, 'download'); + mkdirSync(downloads, { recursive: true }); // npm pack --pack-destination does not create it run(npmCmd, ['pack', registrySpec, '--json', '--pack-destination', downloads, '--cache', cache, '--prefer-online'], { cwd: work, env: { ...process.env, npm_config_cache: cache } }); const found = existsSync(downloads) ? readdirSync(downloads).filter((f) => f.endsWith('.tgz')) : []; if (found.length !== 1) throw new Error(`expected one downloaded tarball, found ${found.length}`);