From f759001ee2449f9ce52e2a7d41deb9944ed7b8cf Mon Sep 17 00:00:00 2001 From: Martijn Wagena Date: Thu, 27 Aug 2026 22:37:27 +0200 Subject: [PATCH 1/3] Prepare package for public distribution Publishing moves to the public npm registry, so the GitLab registry setup that consumers previously needed disappears and the version in package.json is realigned with the release tags it drifted away from. --- .github/workflows/publish.yml | 36 +++++++++++++++++ .github/workflows/tests.yml | 30 ++++++++++++++ .gitlab-ci.yml | 76 ----------------------------------- .npmrc | 1 - README.md | 26 +----------- package.json | 23 ++++++++--- 6 files changed, 85 insertions(+), 107 deletions(-) create mode 100644 .github/workflows/publish.yml create mode 100644 .github/workflows/tests.yml delete mode 100644 .gitlab-ci.yml delete mode 100644 .npmrc diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..5b0ba2d --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,36 @@ +name: publish + +on: + push: + tags: ['v*'] + +jobs: + publish: + runs-on: ubuntu-latest + name: Publish to npm + + steps: + - uses: actions/checkout@v5 + + - name: Setup Node + uses: actions/setup-node@v5 + with: + node-version-file: .nvmrc + cache: npm + registry-url: https://registry.npmjs.org + + - name: Install dependencies + run: npm ci --ignore-scripts + + - name: Set version from tag + env: + TAG_NAME: ${{ github.ref_name }} + run: npm version "${TAG_NAME#v}" --no-git-tag-version --allow-same-version + + - name: Build + run: npm run build + + - name: Publish + run: npm publish --access public + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml new file mode 100644 index 0000000..5d2a8fa --- /dev/null +++ b/.github/workflows/tests.yml @@ -0,0 +1,30 @@ +name: tests + +on: + push: + branches: [1.x, develop] + tags: ['v*'] + pull_request: + +jobs: + build: + runs-on: ubuntu-latest + name: Build and format check + + steps: + - uses: actions/checkout@v5 + + - name: Setup Node + uses: actions/setup-node@v5 + with: + node-version-file: .nvmrc + cache: npm + + - name: Install dependencies + run: npm ci --ignore-scripts + + - name: Check formatting + run: npm run prettier:check + + - name: Build + run: npm run build diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml deleted file mode 100644 index 19f27e1..0000000 --- a/.gitlab-ci.yml +++ /dev/null @@ -1,76 +0,0 @@ -stages: - - versions - - install - - build - - deploy - -versions: - image: alpine:latest - stage: versions - script: - - | - if [[ -s .nvmrc ]]; then - RAW_NODE_VERSION=$(cat .nvmrc) - NODE_VERSION=$(echo "$RAW_NODE_VERSION" | sed -E 's/^v?([^\/]+).*/\1/') - echo "NODE_VERSION=$NODE_VERSION" >> build.env - echo "✅ Found Node version: $NODE_VERSION" - fi - artifacts: - reports: - dotenv: build.env - -node: - stage: install - image: ${CI_DEPENDENCY_PROXY_GROUP_IMAGE_PREFIX}/node:${NODE_VERSION} - script: - - export GITHUB_PACKAGE_REGISTRY_TOKEN=$GITHUB_PACKAGE_REGISTRY_TOKEN - - npm ci - artifacts: - paths: - - node_modules - expire_in: 1 days - when: always - tags: - - javascript - needs: - - job: versions - -build-package: - stage: build - image: ${CI_DEPENDENCY_PROXY_GROUP_IMAGE_PREFIX}/node:${NODE_VERSION} - script: - - | - if [ -n "$CI_COMMIT_TAG" ]; then - VERSION="${CI_COMMIT_TAG#v}" - echo "Tag detected → setting version to $VERSION" - npm version "$VERSION" --no-git-tag-version - else - echo "No tag → skipping version bump" - fi - - npm run build - - artifacts: - paths: - - dist/* - - package.json - expire_in: 1 days - when: always - needs: - - job: versions - - job: node - tags: - - javascript - -publish-package: - stage: deploy - image: ${CI_DEPENDENCY_PROXY_GROUP_IMAGE_PREFIX}/node:${NODE_VERSION} - rules: - - if: $CI_COMMIT_TAG - script: - - echo "@concept7:registry=https://${CI_SERVER_HOST}/api/v4/projects/${CI_PROJECT_ID}/packages/npm/" > .npmrc - - echo "//${CI_SERVER_HOST}/api/v4/projects/${CI_PROJECT_ID}/packages/npm/:_authToken=${CI_JOB_TOKEN}" >> .npmrc - - npm publish --registry https://${CI_SERVER_HOST}/api/v4/projects/${CI_PROJECT_ID}/packages/npm/ - needs: - - job: versions - - job: node - - job: build-package diff --git a/.npmrc b/.npmrc deleted file mode 100644 index cdc57a0..0000000 --- a/.npmrc +++ /dev/null @@ -1 +0,0 @@ -//gitlab.concept7.nl/api/v4/projects/284/packages/npm/:_authToken=${GITLAB_TOKEN} \ No newline at end of file diff --git a/README.md b/README.md index a8447c6..372fa32 100644 --- a/README.md +++ b/README.md @@ -1,30 +1,6 @@ # JavaScript Kite -JavaScript/TypeScript CLI tool that reports project metadata to the [Kite](https://gitlab.concept7.nl/workflow/kite-backend) monitoring API. - -## Prerequisites - -### npmrc file - -A `.npmrc` file with the following content must exist in the root of the project: - -``` -@concept7:registry=https://gitlab.concept7.nl/api/v4/projects/284/packages/npm/ -//gitlab.concept7.nl/api/v4/projects/284/packages/npm/:_authToken=${CI_JOB_TOKEN} -``` - -### GitLab Personal Access Token - -1. Go to [GitLab](https://gitlab.concept7.nl/-/user_settings/personal_access_tokens) and create a new personal access token (scope: `api`, max expiry: 1 year) -2. Add to your `.zshrc`: - -```bash -export CI_JOB_TOKEN=your-personal-accesstoken -``` - -### Project access - -Add the consuming project to the [Job token permissions](https://gitlab.concept7.nl/workflow/javascript-kite/-/settings/ci_cd#js-token-access) section with `Default permissions`. +JavaScript/TypeScript CLI tool that reports project metadata to the [Kite](https://kite-monitor.com) monitoring API. ## Installation diff --git a/package.json b/package.json index 93f9c8e..8c84bbe 100644 --- a/package.json +++ b/package.json @@ -1,15 +1,28 @@ { "name": "@concept7/kite", - "version": "0.0.2", + "version": "1.1.2", "description": "Kite Project version monitoring tool", "author": "Concept7", "license": "MIT", "type": "module", "main": "dist/index.js", "types": "dist/index.d.ts", + "homepage": "https://github.com/concept7/javascript-kite", "repository": { "type": "git", - "url": "git@gitlab.concept7.nl:workflow/javascript-kite.git" + "url": "git+https://github.com/concept7/javascript-kite.git" + }, + "bugs": { + "url": "https://github.com/concept7/javascript-kite/issues" + }, + "keywords": [ + "kite", + "monitoring", + "dependencies", + "cli" + ], + "publishConfig": { + "access": "public" }, "files": [ "dist" @@ -21,8 +34,8 @@ "rebuild": "npm run clean && npm run build", "grant:permission": "chmod +x dist/index.js", "prettier": "prettier . --write", - "prepare": "npm run build", - "publish-package": "npm publish --registry https://gitlab.concept7.nl/api/v4/projects/284/packages/npm/" + "prettier:check": "prettier . --check", + "prepare": "npm run build" }, "bin": { "kite": "dist/index.js" @@ -35,4 +48,4 @@ "dependencies": { "dotenv": "^16.0.0" } -} \ No newline at end of file +} From 466a08944078249cfb5398b848d294223c095ec1 Mon Sep 17 00:00:00 2001 From: Martijn Wagena Date: Thu, 27 Aug 2026 22:38:06 +0200 Subject: [PATCH 2/3] Format sources with Prettier The format check now runs on every push, so the existing deviation in utils.ts would fail the first public build. --- .github/workflows/publish.yml | 62 +++++++++++++++++------------------ .github/workflows/tests.yml | 40 +++++++++++----------- src/utils.ts | 5 +-- 3 files changed, 52 insertions(+), 55 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 5b0ba2d..0dd2908 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,36 +1,36 @@ name: publish on: - push: - tags: ['v*'] + push: + tags: ["v*"] jobs: - publish: - runs-on: ubuntu-latest - name: Publish to npm - - steps: - - uses: actions/checkout@v5 - - - name: Setup Node - uses: actions/setup-node@v5 - with: - node-version-file: .nvmrc - cache: npm - registry-url: https://registry.npmjs.org - - - name: Install dependencies - run: npm ci --ignore-scripts - - - name: Set version from tag - env: - TAG_NAME: ${{ github.ref_name }} - run: npm version "${TAG_NAME#v}" --no-git-tag-version --allow-same-version - - - name: Build - run: npm run build - - - name: Publish - run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + publish: + runs-on: ubuntu-latest + name: Publish to npm + + steps: + - uses: actions/checkout@v5 + + - name: Setup Node + uses: actions/setup-node@v5 + with: + node-version-file: .nvmrc + cache: npm + registry-url: https://registry.npmjs.org + + - name: Install dependencies + run: npm ci --ignore-scripts + + - name: Set version from tag + env: + TAG_NAME: ${{ github.ref_name }} + run: npm version "${TAG_NAME#v}" --no-git-tag-version --allow-same-version + + - name: Build + run: npm run build + + - name: Publish + run: npm publish --access public + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 5d2a8fa..f76138e 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -1,30 +1,30 @@ name: tests on: - push: - branches: [1.x, develop] - tags: ['v*'] - pull_request: + push: + branches: [1.x, develop] + tags: ["v*"] + pull_request: jobs: - build: - runs-on: ubuntu-latest - name: Build and format check + build: + runs-on: ubuntu-latest + name: Build and format check - steps: - - uses: actions/checkout@v5 + steps: + - uses: actions/checkout@v5 - - name: Setup Node - uses: actions/setup-node@v5 - with: - node-version-file: .nvmrc - cache: npm + - name: Setup Node + uses: actions/setup-node@v5 + with: + node-version-file: .nvmrc + cache: npm - - name: Install dependencies - run: npm ci --ignore-scripts + - name: Install dependencies + run: npm ci --ignore-scripts - - name: Check formatting - run: npm run prettier:check + - name: Check formatting + run: npm run prettier:check - - name: Build - run: npm run build + - name: Build + run: npm run build diff --git a/src/utils.ts b/src/utils.ts index 615800b..1d64603 100644 --- a/src/utils.ts +++ b/src/utils.ts @@ -62,10 +62,7 @@ export const getPackages = (): Array => { return []; } - const directNames = new Set([ - ...Object.keys(packageJson?.dependencies ?? {}), - ...Object.keys(packageJson?.devDependencies ?? {}), - ]); + const directNames = new Set([...Object.keys(packageJson?.dependencies ?? {}), ...Object.keys(packageJson?.devDependencies ?? {})]); const requiredByMap = buildRequiredByMap(lockfile.packages); const packages: Record = {}; From e4db7067f44e6600bf9c021b6636efd668c95cd0 Mon Sep 17 00:00:00 2001 From: Martijn Wagena Date: Wed, 9 Sep 2026 15:44:59 +0200 Subject: [PATCH 3/3] Publish to npm without a stored token The repository has no NPM_TOKEN secret, so the publish job could only ever fail with ENEEDAUTH. npm's trusted publisher for this package authenticates the workflow over OIDC instead, which removes the long-lived credential and adds a provenance attestation to every release. The npm upgrade is required because OIDC support landed in npm 11.5.1. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/publish.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 0dd2908..095f8be 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -9,6 +9,10 @@ jobs: runs-on: ubuntu-latest name: Publish to npm + permissions: + contents: read + id-token: write + steps: - uses: actions/checkout@v5 @@ -19,6 +23,9 @@ jobs: cache: npm registry-url: https://registry.npmjs.org + - name: Update npm + run: npm install -g npm@latest + - name: Install dependencies run: npm ci --ignore-scripts @@ -32,5 +39,3 @@ jobs: - name: Publish run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}