Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions docs/release-readiness.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ The release workflow uses npm trusted publishing (GitHub Actions OIDC) and requi

The release dry-run workflow exercises the same npm preparation and artifact handoff on relevant pull requests: it packs once and runs `npm publish <tarball> --dry-run --access public`. `npm run release:workflow-check` guards both workflows against omitting or downgrading the pinned trusted-publishing npm version, repacking, or failing to reuse the artifact.

The CLI reads its version from `package.json`; there is no second version literal to update. After `npm version patch --no-git-tag-version`, `npm run release:check` verifies that the built CLI and the installed packed artifact both report the packed manifest version.

## Notes

- Keep README examples aligned with the fixture-backed smoke command.
Expand Down
4 changes: 3 additions & 1 deletion src/cli.ts
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
#!/usr/bin/env node
import { promises as fs } from "node:fs";
import { createRequire } from "node:module";
import path from "node:path";
import { Command } from "commander";
import { scanProject } from "./core/audit.js";
Expand All @@ -8,11 +9,12 @@ import { renderReport, type OutputFormat } from "./render/index.js";
import type { RiskLevel } from "./types.js";

const program = new Command();
const { version } = createRequire(import.meta.url)("../package.json") as { version: string };

program
.name("scriptaudit")
.description("Audit local scripts and command docs without executing them.")
.version("0.1.0");
.version(version);

program
.command("scan")
Expand Down
45 changes: 45 additions & 0 deletions tests/version.test.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
import assert from "node:assert/strict";
import { spawnSync } from "node:child_process";
import { cpSync, mkdtempSync, readFileSync, writeFileSync } from "node:fs";
import os from "node:os";
import path from "node:path";
import test from "node:test";
import { fileURLToPath } from "node:url";

const repo = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "..");

test("built CLI reads its version from the package manifest", () => {
const fixture = mkdtempSync(path.join(os.tmpdir(), "scriptaudit-version-"));
cpSync(path.join(repo, "dist"), path.join(fixture, "dist"), { recursive: true });
cpSync(path.join(repo, "node_modules"), path.join(fixture, "node_modules"), { recursive: true });
writeFileSync(path.join(fixture, "package.json"), JSON.stringify({ type: "module", version: "9.8.7" }));

const result = spawnSync(process.execPath, [path.join(fixture, "dist", "cli.js"), "--version"], {
encoding: "utf8"
});

assert.equal(result.status, 0, result.stderr);
assert.equal(result.stdout, "9.8.7\n");
});

test("packed and installed CLI version matches the packed manifest", () => {
const fixture = mkdtempSync(path.join(os.tmpdir(), "scriptaudit-package-version-"));
const packed = spawnSync("npm", ["pack", "--json", "--pack-destination", fixture], {
cwd: repo,
encoding: "utf8"
});
assert.equal(packed.status, 0, packed.stderr);
const tarball = path.join(fixture, JSON.parse(packed.stdout)[0].filename);

const installed = spawnSync("npm", ["install", "--ignore-scripts", "--no-audit", "--no-fund", tarball], {
cwd: fixture,
encoding: "utf8"
});
assert.equal(installed.status, 0, installed.stderr);

const manifest = JSON.parse(readFileSync(path.join(fixture, "node_modules", "scriptaudit", "package.json"), "utf8"));
const cli = path.join(fixture, "node_modules", "scriptaudit", "dist", "cli.js");
const version = spawnSync(process.execPath, [cli, "--version"], { encoding: "utf8" });
assert.equal(version.status, 0, version.stderr);
assert.equal(version.stdout.trim(), manifest.version);
});