Skip to content

feat(config): add agentsync config command and [security] schema se… #114

feat(config): add agentsync config command and [security] schema se…

feat(config): add agentsync config command and [security] schema se… #114

name: release-please
on:
push:
branches:
- main
permissions:
contents: write
pull-requests: write
jobs:
release-please:
runs-on: ubuntu-latest
outputs:
release_created: ${{ steps.release.outputs.release_created }}
tag_name: ${{ steps.release.outputs.tag_name }}
steps:
- uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5
id: release
with:
token: ${{ secrets.RELEASE_TOKEN }}
config-file: release-please-config.json
manifest-file: .release-please-manifest.json
publish-package:
name: Publish npm package
needs: release-please
if: ${{ needs.release-please.outputs.release_created }}
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: "1.3.14"
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version-file: .nvmrc
- name: Cache bun dependencies
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
with:
path: ~/.bun/install/cache
key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }}
restore-keys: |
${{ runner.os }}-bun-
- name: Install dependencies
run: bun install --frozen-lockfile
- name: Upgrade npm
run: npm install --global npm@11.5.1
- name: Build package
run: bun run build:package
- name: Smoke-test package bundle
# Execute the exact bundle about to hit the npm registry. Build success
# does not prove the bundle runs: a mangled shebang, a syntax regression,
# or broken @opentui/core external resolution would publish undetected.
run: bun dist/cli.js --version
- name: Publish package
run: npm publish --provenance --access public
build-and-upload:
name: Build and upload release artifacts
needs: release-please
if: ${{ needs.release-please.outputs.release_created }}
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
target: agentsync-linux-x64
- os: ubuntu-latest
target: agentsync-linux-arm64
bun_target: bun-linux-arm64
- os: macos-latest
target: agentsync-macos-arm64
- os: macos-latest
target: agentsync-macos-x64
bun_target: bun-darwin-x64
- os: ubuntu-latest
target: agentsync-windows-x64.exe
bun_target: bun-windows-x64
runs-on: ${{ matrix.os }}
permissions:
contents: write
id-token: write
attestations: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2
with:
bun-version: "1.3.14"
# Pin Node/npm via .nvmrc so the cross-target `npm install --force
# --os --cpu` below is reproducible across runner image refreshes.
# Matches the pinning the publish-package job already uses.
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version-file: .nvmrc
- name: Cache bun dependencies
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
with:
path: ~/.bun/install/cache
key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }}
restore-keys: |
${{ runner.os }}-bun-
- name: Install dependencies
run: bun install --frozen-lockfile
# Cross-compiling embeds the target's native @opentui/core module. bun's
# --compile resolves EVERY platform branch in OpenTUI's loader, and on
# Linux that means both the glibc and musl siblings (e.g.
# @opentui/core-linux-arm64 AND -linux-arm64-musl) since OPENTUI_LIBC is
# unknown at build time. Installing one variant per target left the musl
# sibling unresolved and failed the linux-arm64 leg (#172). Mirror
# scripts/build.ts: fetch every platform's native lib so no import branch
# is missing. Pin to the hoisted core's exact version so the native libs
# match the bundled core.
- name: Install all OpenTUI native modules for cross-compile
if: matrix.bun_target
run: |
set -euo pipefail
CORE_PKG=node_modules/@opentui/core/package.json
if [ ! -f "$CORE_PKG" ]; then
echo "Expected @opentui/core hoisted at $CORE_PKG; install layout changed" >&2
exit 1
fi
VERSION=$(jq -r .version "$CORE_PKG")
echo "Installing all @opentui/core native variants @ $VERSION"
bun install --os="*" --cpu="*" "@opentui/core@${VERSION}"
- name: Build binary
run: bun build --compile ${{ matrix.bun_target && format('--target {0}', matrix.bun_target) || '' }} src/cli.ts --outfile dist/${{ matrix.target }}
- name: Smoke-test native binary
# Host-native targets only (no bun_target -> built for this runner's
# os/arch): linux-x64 on the ubuntu runner and macos-arm64 on the Apple
# Silicon runner. Executing before checksum/attest/upload stops a broken
# artifact from being signed and shipped. macOS arm64 runs here because
# `bun build --compile` ad-hoc signs its darwin output itself
# (flags=adhoc,linker-signed), which is what Apple Silicon requires to
# not SIGKILL an arm64 binary. Bun 1.3.12 shipped that signature
# truncated (oven-sh/bun#29120, fixed in 1.3.13); the pinned 1.3.14 is
# good, and executing the published binary here now fails the release
# loudly if a future Bun reintroduces that class of regression instead
# of publishing an unrunnable binary. Cross-compiled and Windows targets
# cannot run on the host and stay on the checksum + attestation checks.
if: ${{ !matrix.bun_target }}
run: ./dist/${{ matrix.target }} --version
- name: Generate SHA256 checksum
working-directory: dist
run: shasum -a 256 ${{ matrix.target }} > ${{ matrix.target }}.sha256
- name: Attest build provenance
uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4
with:
subject-path: dist/${{ matrix.target }}
- name: Upload release artifact
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }}
run: gh release upload ${{ needs.release-please.outputs.tag_name }} dist/${{ matrix.target }} dist/${{ matrix.target }}.sha256 --clobber
# No Sigstore attestation on this job: SHA256SUMS is a re-publication of
# the already-attested per-binary hashes. The trust root is the per-binary
# attestation (matrix.target). Verification chain: provenance proves binary
# → binary hash matches manifest line → safe. Attesting the manifest itself
# would add noise without raising the floor.
aggregate-checksums:
name: Aggregate SHA256SUMS manifest
needs: [release-please, build-and-upload]
if: ${{ needs.release-please.outputs.release_created }}
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Download per-binary checksums
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }}
TAG_NAME: ${{ needs.release-please.outputs.tag_name }}
run: |
mkdir -p checksums
gh release download "$TAG_NAME" \
--pattern '*.sha256' \
--dir checksums \
--repo "$GITHUB_REPOSITORY"
- name: Build aggregate SHA256SUMS
working-directory: checksums
run: cat *.sha256 | sort > SHA256SUMS
- name: Upload SHA256SUMS to release
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }}
TAG_NAME: ${{ needs.release-please.outputs.tag_name }}
run: gh release upload "$TAG_NAME" checksums/SHA256SUMS --clobber --repo "$GITHUB_REPOSITORY"