feat(config): add agentsync config command and [security] schema se…
#114
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release-please | |
| on: | |
| push: | |
| branches: | |
| - main | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| jobs: | |
| release-please: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| release_created: ${{ steps.release.outputs.release_created }} | |
| tag_name: ${{ steps.release.outputs.tag_name }} | |
| steps: | |
| - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5 | |
| id: release | |
| with: | |
| token: ${{ secrets.RELEASE_TOKEN }} | |
| config-file: release-please-config.json | |
| manifest-file: .release-please-manifest.json | |
| publish-package: | |
| name: Publish npm package | |
| needs: release-please | |
| if: ${{ needs.release-please.outputs.release_created }} | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 | |
| with: | |
| bun-version: "1.3.14" | |
| - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 | |
| with: | |
| node-version-file: .nvmrc | |
| - name: Cache bun dependencies | |
| uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 | |
| with: | |
| path: ~/.bun/install/cache | |
| key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }} | |
| restore-keys: | | |
| ${{ runner.os }}-bun- | |
| - name: Install dependencies | |
| run: bun install --frozen-lockfile | |
| - name: Upgrade npm | |
| run: npm install --global npm@11.5.1 | |
| - name: Build package | |
| run: bun run build:package | |
| - name: Smoke-test package bundle | |
| # Execute the exact bundle about to hit the npm registry. Build success | |
| # does not prove the bundle runs: a mangled shebang, a syntax regression, | |
| # or broken @opentui/core external resolution would publish undetected. | |
| run: bun dist/cli.js --version | |
| - name: Publish package | |
| run: npm publish --provenance --access public | |
| build-and-upload: | |
| name: Build and upload release artifacts | |
| needs: release-please | |
| if: ${{ needs.release-please.outputs.release_created }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - os: ubuntu-latest | |
| target: agentsync-linux-x64 | |
| - os: ubuntu-latest | |
| target: agentsync-linux-arm64 | |
| bun_target: bun-linux-arm64 | |
| - os: macos-latest | |
| target: agentsync-macos-arm64 | |
| - os: macos-latest | |
| target: agentsync-macos-x64 | |
| bun_target: bun-darwin-x64 | |
| - os: ubuntu-latest | |
| target: agentsync-windows-x64.exe | |
| bun_target: bun-windows-x64 | |
| runs-on: ${{ matrix.os }} | |
| permissions: | |
| contents: write | |
| id-token: write | |
| attestations: write | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 | |
| with: | |
| bun-version: "1.3.14" | |
| # Pin Node/npm via .nvmrc so the cross-target `npm install --force | |
| # --os --cpu` below is reproducible across runner image refreshes. | |
| # Matches the pinning the publish-package job already uses. | |
| - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6 | |
| with: | |
| node-version-file: .nvmrc | |
| - name: Cache bun dependencies | |
| uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5 | |
| with: | |
| path: ~/.bun/install/cache | |
| key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }} | |
| restore-keys: | | |
| ${{ runner.os }}-bun- | |
| - name: Install dependencies | |
| run: bun install --frozen-lockfile | |
| # Cross-compiling embeds the target's native @opentui/core module. bun's | |
| # --compile resolves EVERY platform branch in OpenTUI's loader, and on | |
| # Linux that means both the glibc and musl siblings (e.g. | |
| # @opentui/core-linux-arm64 AND -linux-arm64-musl) since OPENTUI_LIBC is | |
| # unknown at build time. Installing one variant per target left the musl | |
| # sibling unresolved and failed the linux-arm64 leg (#172). Mirror | |
| # scripts/build.ts: fetch every platform's native lib so no import branch | |
| # is missing. Pin to the hoisted core's exact version so the native libs | |
| # match the bundled core. | |
| - name: Install all OpenTUI native modules for cross-compile | |
| if: matrix.bun_target | |
| run: | | |
| set -euo pipefail | |
| CORE_PKG=node_modules/@opentui/core/package.json | |
| if [ ! -f "$CORE_PKG" ]; then | |
| echo "Expected @opentui/core hoisted at $CORE_PKG; install layout changed" >&2 | |
| exit 1 | |
| fi | |
| VERSION=$(jq -r .version "$CORE_PKG") | |
| echo "Installing all @opentui/core native variants @ $VERSION" | |
| bun install --os="*" --cpu="*" "@opentui/core@${VERSION}" | |
| - name: Build binary | |
| run: bun build --compile ${{ matrix.bun_target && format('--target {0}', matrix.bun_target) || '' }} src/cli.ts --outfile dist/${{ matrix.target }} | |
| - name: Smoke-test native binary | |
| # Host-native targets only (no bun_target -> built for this runner's | |
| # os/arch): linux-x64 on the ubuntu runner and macos-arm64 on the Apple | |
| # Silicon runner. Executing before checksum/attest/upload stops a broken | |
| # artifact from being signed and shipped. macOS arm64 runs here because | |
| # `bun build --compile` ad-hoc signs its darwin output itself | |
| # (flags=adhoc,linker-signed), which is what Apple Silicon requires to | |
| # not SIGKILL an arm64 binary. Bun 1.3.12 shipped that signature | |
| # truncated (oven-sh/bun#29120, fixed in 1.3.13); the pinned 1.3.14 is | |
| # good, and executing the published binary here now fails the release | |
| # loudly if a future Bun reintroduces that class of regression instead | |
| # of publishing an unrunnable binary. Cross-compiled and Windows targets | |
| # cannot run on the host and stay on the checksum + attestation checks. | |
| if: ${{ !matrix.bun_target }} | |
| run: ./dist/${{ matrix.target }} --version | |
| - name: Generate SHA256 checksum | |
| working-directory: dist | |
| run: shasum -a 256 ${{ matrix.target }} > ${{ matrix.target }}.sha256 | |
| - name: Attest build provenance | |
| uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4 | |
| with: | |
| subject-path: dist/${{ matrix.target }} | |
| - name: Upload release artifact | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }} | |
| run: gh release upload ${{ needs.release-please.outputs.tag_name }} dist/${{ matrix.target }} dist/${{ matrix.target }}.sha256 --clobber | |
| # No Sigstore attestation on this job: SHA256SUMS is a re-publication of | |
| # the already-attested per-binary hashes. The trust root is the per-binary | |
| # attestation (matrix.target). Verification chain: provenance proves binary | |
| # → binary hash matches manifest line → safe. Attesting the manifest itself | |
| # would add noise without raising the floor. | |
| aggregate-checksums: | |
| name: Aggregate SHA256SUMS manifest | |
| needs: [release-please, build-and-upload] | |
| if: ${{ needs.release-please.outputs.release_created }} | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - name: Download per-binary checksums | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }} | |
| TAG_NAME: ${{ needs.release-please.outputs.tag_name }} | |
| run: | | |
| mkdir -p checksums | |
| gh release download "$TAG_NAME" \ | |
| --pattern '*.sha256' \ | |
| --dir checksums \ | |
| --repo "$GITHUB_REPOSITORY" | |
| - name: Build aggregate SHA256SUMS | |
| working-directory: checksums | |
| run: cat *.sha256 | sort > SHA256SUMS | |
| - name: Upload SHA256SUMS to release | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }} | |
| TAG_NAME: ${{ needs.release-please.outputs.tag_name }} | |
| run: gh release upload "$TAG_NAME" checksums/SHA256SUMS --clobber --repo "$GITHUB_REPOSITORY" |