This document explains how @icodenet/eval-dashboards is published to npm.
Primary release path uses the trusted-publishing workflow:
- Trigger
.github/workflows/publish.ymlmanually with the version inpackage.json - Publishes to npm using GitHub Actions OIDC trusted publishing
- Creates GitHub release + tag (
vX.Y.Z) - Does not require an
NPM_TOKENsecret
Legacy Semantic Release config remains available in .github/workflows/release.yml for manual experiments only. It is not run on every main push because @semantic-release/npm requires NPM_TOKEN, while this package is configured for trusted publishing.
Configure the package on npm for trusted publishing from this GitHub repository and the Publish to npm workflow. No npm automation token is required for the primary path.
Only needed if running .github/workflows/release.yml manually:
- Login to npm as the
@icodenetowner - Go to https://www.npmjs.com/settings/tokens
- Create an Automation token
- Add it to GitHub repo secrets as
NPM_TOKEN
Semantic Release depends on conventional commits:
feat:-> minor bumpfix:-> patch bumpperf:-> patch bumpfeat!:orBREAKING CHANGE:-> major bumpdocs:/chore:by default do not publish a new release unless configured
This repository also accepts ticket/initial prefixes before the type, for example:
[AB#272021] [BT] feat: add grouped report index[AB#272021] [BT] fix: handle missing suite manifest
- Update
package.jsonandCHANGELOG.mdfor the intended version. - Merge or push the release commit to
main. - Run
.github/workflows/publish.ymlmanually with the version input. - The workflow runs
pnpm release:preparebefore publish, which enforces:- project checks (
pnpm check) - deterministic regeneration of release dashboards/screenshots (
pnpm assets:regenerate) - no drift in tracked release assets (
git diff --exit-code -- eval-report eval-report-dark docs/images)
- project checks (
- Publish proceeds only when all checks pass, then creates the npm package and GitHub release.
Use dry run to preview next release without publishing:
pnpm install
pnpm release:prepare
pnpm release:dryRun .github/workflows/publish.yml manually from Actions:
- Provide
versioninput (must matchpackage.json) - Workflow validates, runs checks, publishes to npm, creates release
The install step in this workflow supports both cases:
- lockfile present ->
pnpm install --frozen-lockfile - lockfile absent in ref -> fallback
pnpm install --no-frozen-lockfile
| Issue | Solution |
|---|---|
| Push to main does not publish | Run .github/workflows/publish.yml with the version from package.json |
| PR title lint fails | Rename PR title to conventional format |
| npm publish fails with trusted publishing | Verify the npm package trusted publisher points at this repository and workflow |
Legacy semantic-release fails with ENONPMTOKEN |
Either use publish.yml, or add an NPM_TOKEN before running release.yml manually |
| Manual publish version mismatch | Ensure package.json version matches manual version input |
After a successful release:
npm view @icodenet/eval-dashboards
npm view @icodenet/eval-dashboards version