Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .github/workflows/marketplace-sync.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,11 @@ jobs:
bun packages/cli/src/index.ts sync "${args[@]}" | tee "$RUNNER_TEMP/catalog-change-report.json"
- name: Validate catalog
run: bun run catalog validate --json
- name: Validate curated shelf resolution
# Catalog validation checks schemas and integrity. This test also
# requires each configured leading product to resolve before the
# mutable catalog-assets pointer is updated.
run: bun test packages/cli/src/config.test.ts
- name: Verify brand marks
if: inputs['bootstrap-only'] != true
run: |
Expand Down
18 changes: 8 additions & 10 deletions .github/workflows/publish-packages.yml
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
name: Publish marketplace toolkit

# Publishes the marketplace toolkit to the public npm registry as the single
# package @adea-ai/plugins on every main push that touches it (plus manual
# dispatch). Already-published versions are skipped, so the workflow is safe to
# re-run.
# package @adea-ai/plugins when main changes it. Already-published versions are
# skipped, so rerunning does not publish the same version twice.
#
# Prerequisites (one-time, dashboard):
# Set NPM_TOKEN to an automation token with publish rights on @adea-ai/*.
# One-time npm setup: configure a trusted publisher for @adea-ai/plugins with
# GitHub repository adea-ai/plugins, workflow publish-packages.yml, and npm
# publish permission. Publishing uses OIDC and needs no long-lived npm token.

on:
push:
Expand All @@ -16,8 +16,6 @@ on:
- 'schemas/**'
- 'scripts/publish-packages.mjs'
- '.github/workflows/publish-packages.yml'
workflow_dispatch:

permissions:
contents: read
id-token: write
Expand All @@ -44,16 +42,16 @@ jobs:
no-cache: true

- name: Install Node
# Writes the registry .npmrc that npm publish reads NODE_AUTH_TOKEN from.
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
registry-url: https://registry.npmjs.org

- name: Install npm with trusted publishing support
run: npm install --global npm@12.1.0

- name: Install dependencies
run: bun install --frozen-lockfile

- name: Publish changed packages
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: bun scripts/publish-packages.mjs
6 changes: 6 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -157,6 +157,12 @@ and determinism. Applying a source patch does not itself regenerate or publish
catalog data. Review the [staged migration procedure](docs/agent-plugins.md#cli-and-migration)
before switching consumers to v2 plans.

The separate `.github/workflows/publish-packages.yml` workflow publishes
`@adea-ai/plugins` when a release reaches `main`. It uses npm trusted
publishing; configure a trusted publisher for repository `adea-ai/plugins`,
workflow `publish-packages.yml`, and direct `npm publish` permission. No
long-lived npm token is used.

For first publication, `workflow_dispatch` supports `bootstrap-only`, which
validates and publishes the checked-in last-known-good catalog without live
upstream retrieval.
Expand Down
Loading
Loading