Skip to content

ci: npm trusted publishing (like bambu-printer-mcp); local code-review gate - #26

Merged
DMontgomery40 merged 3 commits into
mainfrom
ci/trusted-publishing
Sep 29, 2026
Merged

DMontgomery40 merged 3 commits into
mainfrom
ci/trusted-publishing

Conversation

@DMontgomery40

@DMontgomery40 DMontgomery40 commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Adds .github/workflows/publish.yml: on every merge to main (and on manual dispatch) it runs npm ci, npm test, and npm run test:package, then npm publish through GitHub Actions trusted publishing (OIDC, provenance). No npm token or 2FA code is involved, and versions already on npm are skipped. This matches bambu-printer-mcp's release path.

One-time setup on npmjs.com for mcp-3d-printer-server: Settings → Trusted publishing → GitHub Actions → owner DMontgomery40, repository mcp-3D-printer-server, workflow publish.yml.

AGENTS.md changes:

  • Releases go through this workflow.
  • The pre-PR gate is Matt Pocock's code-review skill run locally against the main merge base before GitHub CI.
  • Codex review is not part of the process.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T08:02:11.810484Z 68f1e4b New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@DMontgomery40 DMontgomery40 changed the title ci: npm trusted publishing (like bambu-printer-mcp); Codex review optional ci: npm trusted publishing (like bambu-printer-mcp); local code-review gate Sep 29, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b4a426d14

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +40 to +44
if npm view "$name@$version" version >/dev/null 2>&1; then
echo "$name@$version is already published; nothing to do."
echo "publish=false" >> "$GITHUB_OUTPUT"
else
echo "publish=true" >> "$GITHUB_OUTPUT"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bump the npm version for this update

This commit changes configuration but leaves both package manifests at the already released 1.2.10, so when this exact commit reaches main, the version check succeeds and every install, test, and publish step is skipped. Increment package.json and package-lock.json so this update receives the required release rather than silently doing nothing.

AGENTS.md reference: AGENTS.md:L7-L7

Useful? React with 👍 / 👎.

Comment on lines +19 to +21
concurrency:
group: publish-${{ github.ref }}
cancel-in-progress: false

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Give each release a unique concurrency group

If three pushes reach main while the first workflow is still running, all runs use the same concurrency group; GitHub retains only one pending run and replaces that pending run when the third arrives, even with cancel-in-progress: false. The middle commit's unique patch version is therefore never tested or published, violating the requirement that every main update be released; key the group by commit SHA or remove workflow-level concurrency.

AGENTS.md reference: AGENTS.md:L7-L7

Useful? React with 👍 / 👎.

Add the Publish Package workflow bambu-printer-mcp uses (GitHub Actions
OIDC trusted publishing with provenance, Node 24), skipping versions that
are already on npm. AGENTS.md now points releases at it and makes Codex
review optional to save credits, with a local independent review otherwise.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 68f1e4b56e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

push:
branches:
- main
workflow_dispatch:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Restrict manual publishing to main

When a maintainer dispatches this workflow with a non-main ref, actions/checkout checks out the selected branch and the unconditional final step publishes its package version, allowing unmerged code to reach npm without passing the required PR-to-main path. Remove workflow_dispatch or guard the publish job so it can run only for refs/heads/main.

AGENTS.md reference: AGENTS.md:L10-L10

Useful? React with 👍 / 👎.

Comment thread AGENTS.md
- Publish from a clean build of the merged main commit, then create a `v<version>` tag and GitHub release with the accumulated changelog notes. Verify npm, the tag, the release, and a fresh `npx -y mcp-3d-printer-server` startup before declaring the release complete. Never move a published tag.
- The main-branch Publish Package workflow (`.github/workflows/publish.yml`) runs the checks and `npm publish` with trusted publishing; do not publish from a local checkout. Verify that workflow and the exact npm version before claiming publication. Then create a `v<version>` tag and GitHub release with the accumulated changelog notes. Verify npm, the tag, the release, and a fresh `npx -y mcp-3d-printer-server` startup before declaring the release complete. Never move a published tag.
- Changes to src/, scripts/, or printer behavior need a present-tense CHANGELOG.md entry under `## Unreleased`, including evidence limits (mocked transports versus real hardware).
- Never add AI or agent attribution anywhere in Git or GitHub: no `Co-Authored-By` trailers for Claude, Codex, or other assistants, no "Generated with" footers, and no agent session links in commits, PR titles or bodies, review replies, issue comments, or release notes.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Remove AI attribution from the commit metadata

The commit being reviewed ends with a “Generated with Claude Code” footer and an agent session URL, directly violating the newly added prohibition on AI attribution in Git. Remove both pieces of attribution from the commit message before integrating it.

AGENTS.md reference: AGENTS.md:L12-L12

Useful? React with 👍 / 👎.

@DMontgomery40
DMontgomery40 merged commit 1eed93c into main Sep 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant