Skip to content

chore: bump ai sdk family to ai 7.0.124 (#273) #234

chore: bump ai sdk family to ai 7.0.124 (#273)

chore: bump ai sdk family to ai 7.0.124 (#273) #234

name: release-please
on:
push:
branches: [main]
# Recovery lever for a release that was tagged on GitHub but never reached
# npm (e.g. the release run died between tagging and emitting its outputs).
# Trusted publishing authorizes it because it runs from this same workflow file.
workflow_dispatch:
inputs:
release_tag:
description: "Existing release tag to publish to npm (e.g. sandbox-v0.4.0)"
required: true
type: string
# Only one release run at a time; never cancel an in-progress publish.
concurrency:
group: release-please-${{ github.ref }}
cancel-in-progress: false
permissions: {}
jobs:
release-please:
if: ${{ github.event_name == 'push' }}
runs-on: ubuntu-latest
permissions:
actions: write # restart checks after GITHUB_TOKEN updates release PR branches
contents: write # create release tags, GitHub releases, and the release PR
pull-requests: write # open/update the release PR
outputs:
# Per-package outputs. The path contains a '/', so it MUST be read with
# JS-style bracket+quote indexing, not dot access.
sandbox_released: ${{ steps.release.outputs['packages/sandbox--release_created'] }}
agent_released: ${{ steps.release.outputs['packages/agent--release_created'] }}
provider_released: ${{ steps.release.outputs['packages/provider--release_created'] }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
env:
# The action exports this token only after cached-binary self-update.
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
# Avoid release-in-progress 404s; mirrors pnpm's minimumReleaseAge posture.
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
# Runs release-please as a library with our AI changelog-notes hook
# registered (changelog-type: "ai" in the config). release-please itself
# writes the CHANGELOG, the release PR, and the GitHub Release — nothing
# downstream overwrites its output. The harness emits the same per-path
# outputs the stock action did, so the publish jobs below are unchanged.
- name: Run release-please (AI changelog notes)
id: release
run: pnpm --filter @coder/release-please-ai exec tsx src/cli.ts
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
# Publish jobs authenticate to npm via OIDC trusted publishing (no NPM_TOKEN).
# Requires a trusted publisher configured per package on npmjs.com pointing at
# this repo + workflow file. Provenance is attested via the OIDC id-token.
# The publish conditions use !cancelled() so an emitted release still publishes
# even if the release-please job later failed on housekeeping: its outputs are
# written the moment releases are tagged, and a tagged release only publishes
# from this run (re-runs see it as already tagged and skip it).
publish-sandbox:
needs: release-please
if: ${{ !cancelled() && needs.release-please.outputs.sandbox_released == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
- run: pnpm --filter @coder/ai-sdk-sandbox build
- name: Publish @coder/ai-sdk-sandbox
run: pnpm --filter @coder/ai-sdk-sandbox publish --provenance --access public --no-git-checks
publish-agent:
needs: release-please
if: ${{ !cancelled() && needs.release-please.outputs.agent_released == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
- run: pnpm --filter @coder/ai-sdk-agent build
- name: Publish @coder/ai-sdk-agent
run: pnpm --filter @coder/ai-sdk-agent publish --provenance --access public --no-git-checks
publish-provider:
needs: release-please
if: ${{ !cancelled() && needs.release-please.outputs.provider_released == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
- run: pnpm --filter @coder/ai-sdk-provider build
- name: Publish @coder/ai-sdk-provider
run: pnpm --filter @coder/ai-sdk-provider publish --provenance --access public --no-git-checks
# Manual recovery (workflow_dispatch): publish an already-tagged release whose
# npm publish never ran. Builds the tag's checkout and refuses to run if the
# tag doesn't match the package.json version or the version is already on npm.
publish-recovery:
if: ${{ github.event_name == 'workflow_dispatch' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.release_tag }}
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@9149ea85001c7435d5a66bb127d6a1b6227cb0a5 # v5.0.0
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- name: Resolve package from tag
id: pkg
env:
RELEASE_TAG: ${{ inputs.release_tag }}
run: |
case "$RELEASE_TAG" in
sandbox-v*) name="@coder/ai-sdk-sandbox" path="packages/sandbox" ;;
agent-v*) name="@coder/ai-sdk-agent" path="packages/agent" ;;
provider-v*) name="@coder/ai-sdk-provider" path="packages/provider" ;;
*) echo "unrecognized release tag: $RELEASE_TAG" >&2; exit 1 ;;
esac
version="${RELEASE_TAG#*-v}"
manifest_version="$(jq -r .version "$path/package.json")"
if [ "$manifest_version" != "$version" ]; then
echo "tag version $version does not match $path/package.json version $manifest_version" >&2
exit 1
fi
if npm view "$name@$version" version >/dev/null 2>&1; then
echo "$name@$version is already published" >&2
exit 1
fi
echo "name=$name" >> "$GITHUB_OUTPUT"
- run: pnpm install --frozen-lockfile
- run: pnpm --filter "$PACKAGE_NAME" build
env:
PACKAGE_NAME: ${{ steps.pkg.outputs.name }}
- name: Publish ${{ inputs.release_tag }}
run: pnpm --filter "$PACKAGE_NAME" publish --provenance --access public --no-git-checks
env:
PACKAGE_NAME: ${{ steps.pkg.outputs.name }}