ci: auto-publish to npm + MCP Registry on version tags - #3
Conversation
Triggers on git tag v* (e.g. v1.1.4). Pipeline: 1. Checkout + npm ci 2. Validate tag == package.json.version == server.json.version == server.json.packages[0].version, and package.json.mcpName == server.json.name. Fails fast if any of these drift. 3. typecheck + test + build 4. npm publish --access public (uses NPM_TOKEN secret) 5. mcp-publisher login github-oidc (no secret needed, uses GitHub OIDC) 6. mcp-publisher publish Removes the manual publish dance (brew install + login + publish) from future releases. After this lands, releasing becomes: bump versions in PR → merge → git tag v1.1.4 && git push --tags
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 39461ae6c4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Addresses Codex review P1 on PR #3: if any step after npm publish fails (transient network issue during mcp-publisher download/login/publish), "Re-run failed jobs" would crash at npm publish with "version already exists" — leaving the release stuck in a manual-recovery state. Both publish steps now check whether the exact version is already published first: - npm: use `npm view @orcarouter/mcp@<version>` to probe; skip on hit - MCP Registry: query /v0/servers?search=<name> and filter for matching (name, version); skip on hit This makes the job safe to rerun any number of times. A partial failure between the two publish steps can now recover with a single click.
|
@codex review Addressed the P1 finding from your previous review (rerun-safety for
Pushed as |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8d775e427f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if npm view "@orcarouter/mcp@${VERSION}" version >/dev/null 2>&1; then | ||
| echo "@orcarouter/mcp@${VERSION} already on npm — skipping publish" |
There was a problem hiding this comment.
Define release version before idempotency checks
Both idempotency guards use ${VERSION}, but this workflow never sets VERSION (the earlier TAG_VERSION is local to a different run step), so these checks do not test the tagged release version. In reruns, that means the npm/registry probes can miss the already-published tag and still execute publish, recreating the original "version already exists" failure mode the change is meant to prevent. Set VERSION at job/workflow scope (or export via $GITHUB_ENV) and use that in both checks.
Useful? React with 👍 / 👎.
Codex P1 on PR #3 follow-up: the npm and MCP Registry idempotency checks reference ${VERSION}, but the validation step only set a local bash TAG_VERSION inside its own run block. Across GitHub Actions steps the variable was undefined, so the probes were running with an empty version string — meaning the "already published?" check never matched and the publish ran every time, defeating the rerun-safety fix in 8d775e4. Fix: write TAG_VERSION to $GITHUB_ENV after validation passes, so later steps see VERSION as a real env var.
|
@codex review Good catch — Fixed in 954579d: write Please take another look. |
|
Codex Review: Didn't find any major issues. Keep it up! ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
`npm ci` requires a package-lock.json. This repo uses bun as its
primary package manager and only commits bun.lock, so the v1.1.4 tag
push triggered a CI failure at the Install dependencies step:
npm error The `npm ci` command can only install with an existing
package-lock.json or npm-shrinkwrap.json
PR #3 originally chose `npm ci` from the official MCP Registry docs
example — that example assumes an npm-managed project. Our Dockerfile
(merged in #5) already uses `npm install --no-audit --no-fund` against
the same package.json with no issues; this commit aligns the publish
workflow with that pattern.
We accept the trade-off of non-pinned transitive deps in CI: deps are
pinned to caret ranges in package.json that have been stable across
releases, the build is bundled by tsup so transitive shape doesn't
leak into the published artifact, and tag-gated runs are infrequent
enough that drift detection is moot.
After this merges, the existing v1.1.4 tag needs to be re-pointed at
the new commit (delete + recreate) to retrigger publish — there is no
v1.1.4 on npm or MCP Registry yet, since the failed run aborted before
either publish step.
Co-authored-by: fengyat <fengya.tian@continuum01.ai>
Summary
Adds
.github/workflows/publish-mcp.ymlthat fully automates releases. After this lands, the publish dance we did manually for v1.1.3 collapses into agit tag && git push.How releases work after this
Pipeline (in order)
actions/checkout@v5+actions/setup-node@v5npm civ1.1.4)package.jsonversionserver.jsonversionserver.jsonpackages[0].versionpackage.json.mcpName == server.json.namenpm run typechecknpm testnpm run buildnpm publish --access public(usesNPM_TOKENsecret)mcp-publisherCLI from latest releasemcp-publisher login github-oidc(uses GitHub OIDC, no secret)mcp-publisher publishAuthentication
NODE_AUTH_TOKENfromNPM_TOKENsecretid-token: writepermission)Continuum-AI-Corporg to the matchingio.github.Continuum-AI-Corp/...namespaceRequired setup before this can run
Add an
NPM_TOKENsecret to the repo:NPM_TOKENathttps://github.com/Continuum-AI-Corp/orcarouter-mcp-server/settings/secrets/actionsThe OIDC side needs no setup — it works out of the box because:
mcpNameisio.github.Continuum-AI-Corp/orcarouter-mcpContinuum-AI-Corporgrepository_ownerOIDC claim matches the namespaceWhy the drift check matters
It catches the most common release-PR mistake: bumping
package.jsonbut forgetting to bumpserver.json(or vice versa). The MCP Registry would reject a mismatched publish anyway, but failing in CI beforenpm publishruns prevents shipping an orphaned npm version.Out of scope
Test plan
python3 -c 'import yaml; yaml.safe_load(...)')NPM_TOKENsecret will be added before mergingv1.1.3-test(or whatever) on a feature branch and inspecting CI output — actually, sincenpm publishwould 409 on the existing v1.1.3, the safer way to dry-run is to wait for the real next release (v1.1.4) and watch closely