Repository navigation
ci: npm trusted publishing (like bambu-printer-mcp); local code-review gate - #26
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8b4a426d14
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if npm view "$name@$version" version >/dev/null 2>&1; then | ||
| echo "$name@$version is already published; nothing to do." | ||
| echo "publish=false" >> "$GITHUB_OUTPUT" | ||
| else | ||
| echo "publish=true" >> "$GITHUB_OUTPUT" |
There was a problem hiding this comment.
Bump the npm version for this update
This commit changes configuration but leaves both package manifests at the already released 1.2.10, so when this exact commit reaches main, the version check succeeds and every install, test, and publish step is skipped. Increment package.json and package-lock.json so this update receives the required release rather than silently doing nothing.
AGENTS.md reference: AGENTS.md:L7-L7
Useful? React with 👍 / 👎.
| concurrency: | ||
| group: publish-${{ github.ref }} | ||
| cancel-in-progress: false |
There was a problem hiding this comment.
Give each release a unique concurrency group
If three pushes reach main while the first workflow is still running, all runs use the same concurrency group; GitHub retains only one pending run and replaces that pending run when the third arrives, even with cancel-in-progress: false. The middle commit's unique patch version is therefore never tested or published, violating the requirement that every main update be released; key the group by commit SHA or remove workflow-level concurrency.
AGENTS.md reference: AGENTS.md:L7-L7
Useful? React with 👍 / 👎.
Add the Publish Package workflow bambu-printer-mcp uses (GitHub Actions OIDC trusted publishing with provenance, Node 24), skipping versions that are already on npm. AGENTS.md now points releases at it and makes Codex review optional to save credits, with a local independent review otherwise.
3d77cf4 to
68f1e4b
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 68f1e4b56e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| push: | ||
| branches: | ||
| - main | ||
| workflow_dispatch: |
There was a problem hiding this comment.
Restrict manual publishing to main
When a maintainer dispatches this workflow with a non-main ref, actions/checkout checks out the selected branch and the unconditional final step publishes its package version, allowing unmerged code to reach npm without passing the required PR-to-main path. Remove workflow_dispatch or guard the publish job so it can run only for refs/heads/main.
AGENTS.md reference: AGENTS.md:L10-L10
Useful? React with 👍 / 👎.
| - Publish from a clean build of the merged main commit, then create a `v<version>` tag and GitHub release with the accumulated changelog notes. Verify npm, the tag, the release, and a fresh `npx -y mcp-3d-printer-server` startup before declaring the release complete. Never move a published tag. | ||
| - The main-branch Publish Package workflow (`.github/workflows/publish.yml`) runs the checks and `npm publish` with trusted publishing; do not publish from a local checkout. Verify that workflow and the exact npm version before claiming publication. Then create a `v<version>` tag and GitHub release with the accumulated changelog notes. Verify npm, the tag, the release, and a fresh `npx -y mcp-3d-printer-server` startup before declaring the release complete. Never move a published tag. | ||
| - Changes to src/, scripts/, or printer behavior need a present-tense CHANGELOG.md entry under `## Unreleased`, including evidence limits (mocked transports versus real hardware). | ||
| - Never add AI or agent attribution anywhere in Git or GitHub: no `Co-Authored-By` trailers for Claude, Codex, or other assistants, no "Generated with" footers, and no agent session links in commits, PR titles or bodies, review replies, issue comments, or release notes. |
There was a problem hiding this comment.
Remove AI attribution from the commit metadata
The commit being reviewed ends with a “Generated with Claude Code” footer and an agent session URL, directly violating the newly added prohibition on AI attribution in Git. Remove both pieces of attribution from the commit message before integrating it.
AGENTS.md reference: AGENTS.md:L12-L12
Useful? React with 👍 / 👎.
Adds
.github/workflows/publish.yml: on every merge to main (and on manual dispatch) it runsnpm ci,npm test, andnpm run test:package, thennpm publishthrough GitHub Actions trusted publishing (OIDC, provenance). No npm token or 2FA code is involved, and versions already on npm are skipped. This matches bambu-printer-mcp's release path.One-time setup on npmjs.com for
mcp-3d-printer-server: Settings → Trusted publishing → GitHub Actions → ownerDMontgomery40, repositorymcp-3D-printer-server, workflowpublish.yml.AGENTS.md changes:
code-reviewskill run locally against the main merge base before GitHub CI.