Skip to content

ci(release): publish @eqrm/ct-cli to GitHub Packages — no-PAT cross-repo consumption (#24) - #83

Merged
2000game merged 1 commit into
mainfrom
feat/publish-github-packages-24
Jul 10, 2026
Merged

2000game merged 1 commit into
mainfrom
feat/publish-github-packages-24

Conversation

@2000game

Copy link
Copy Markdown
Member

Publishes ct-cli to GitHub Packages so eqrm/ct-structure (and any org repo) can consume it in CI with the built-in GITHUB_TOKEN — no personal PAT. Directly unblocks the CI half of #24 / #23.

Why

ct-structure's plan/apply workflows fail at npm ci:

npm error command git ... ls-remote ssh://git@github.com/eqrm/ct-cli.git
npm error git@github.com: Permission denied (publickey).

The git dependency needs a credential the workflow's GITHUB_TOKEN can't provide — it still can't read another private repo's source in the same org. The recent GitHub improvement (pull private deps in CI with GITHUB_TOKEN, no PAT) applies to package registries (*.pkg.github.com), not raw git deps. So we publish ct-cli as a package.

Changes

  • package.json — scope the name to @eqrm/ct-cli (GitHub Packages requires the owner scope); drop private: true (it hard-blocks npm publish); pin publishConfig.registry to npm.pkg.github.com so a stray npm publish can never hit public npm; add the repository field GitHub Packages links by.
  • .releaserc.json — add @semantic-release/npm before the github plugin. It bumps the in-workspace version and publishes, but only when commit-analyzer finds a releasable feat/fix (no accidental republish; never public npm).
  • release.yml — add packages: write; run npm ci + npm run build in the release job (the package publishes from this working tree; the release-assets artifact carries only the binaries, not dist/); pass NPM_TOKEN=GITHUB_TOKEN.

Consumer side (in eqrm/ct-structure — separate PR there)

// package.json
"dependencies": { "@eqrm/ct-cli": "^1.0.0" }
# workflow
permissions: { packages: read, contents: read }
- uses: actions/setup-node@v4
  with: { node-version: 22, registry-url: https://npm.pkg.github.com, scope: '@eqrm' }
- run: npm ci
  env: { NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} }

One-time: in this repo's package settings, grant eqrm/ct-structure Actions access to the published package.

Verification

  • npm pack → @eqrm/ct-cli with dist/ built via the prepare script (4 files).
  • npm run lint && npm run typecheck && npm test && npm run build — all green (535 tests). Only in-repo reference to the string "ct-cli" is an unrelated keychain-service constant; nothing imports the package by name.
  • Can't dry-run the release pipeline without a merge-to-main (it publishes for real). This ci: commit is itself non-releasing, so the package first publishes on the next releasable feat/fix. If the release ever fails on npm auth, revert this PR — the binary/GitHub-Release path is unchanged otherwise.

…d no PAT (#24)

ct-structure's CI can't 'npm install' ct-cli today: the git dependency
ssh://git@github.com/eqrm/ct-cli.git needs a credential GITHUB_TOKEN can't
provide across private repos in the same org (Permission denied (publickey)).
The recent GitHub improvement — pulling private deps in CI with the built-in
GITHUB_TOKEN, no PAT — applies to package REGISTRIES, not raw git deps. So
publish ct-cli to GitHub Packages and let consumers depend on the package.

- package.json: scope the name to @eqrm/ct-cli (GitHub Packages requires the
  owner scope); drop 'private: true' (it blocks 'npm publish'); pin
  publishConfig.registry to npm.pkg.github.com so a stray publish can never hit
  public npm; add the 'repository' field GitHub Packages links the package by.
- .releaserc.json: add @semantic-release/npm before the github plugin — it
  bumps the in-workspace version and publishes, but ONLY when commit-analyzer
  finds a releasable feat/fix (no accidental republish).
- release.yml: add 'packages: write'; run 'npm ci' + build in the release job
  (the package is published from this working tree, and the release-assets
  artifact carries only the binaries, not dist/); pass NPM_TOKEN=GITHUB_TOKEN
  to authenticate against GitHub Packages.

Consumers (eqrm/ct-structure) then depend on @eqrm/ct-cli and install it in CI
with just secrets.GITHUB_TOKEN + 'permissions: packages: read', after granting
the consumer repo Actions access to the package — no personal PAT. Verified
locally: 'npm pack' produces @eqrm/ct-cli with dist/ built via the prepare
script; lint/typecheck/test/build all green.

Note: this ci: commit is itself non-releasing, so the package first publishes
on the next releasable feat/fix merged to main.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant