diff --git a/.github/workflows/hotfix-release.yml b/.github/workflows/hotfix-release.yml index 964e9ff..65cdbc3 100644 --- a/.github/workflows/hotfix-release.yml +++ b/.github/workflows/hotfix-release.yml @@ -11,6 +11,7 @@ jobs: permissions: contents: write pull-requests: write + id-token: write strategy: matrix: @@ -18,19 +19,17 @@ jobs: # See supported Node.js release schedule at https://nodejs.org/en/about/releases/ steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v6 - run: | git config user.name ${{ github.actor }} git config user.email ${{ github.actor }}@users.noreply.github.com - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v3 + uses: actions/setup-node@v6 with: node-version: ${{ matrix.node-version }} - cache: 'npm' - cache-dependency-path: './common/config/rush/pnpm-lock.yaml' + package-manager-cache: false - # Install rush - name: Install rush run: node common/scripts/install-run-rush.js install --bypass-policy @@ -55,10 +54,18 @@ jobs: run: node common/scripts/install-run-rush.js build --only tag:package - run: node common/scripts/install-run-rush.js test --only tag:package - - name: Publish to npm - env: - NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} - NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} + # Keep build/test on Node 20; npm trusted publishing requires Node >=22.14. + - name: Use Node.js 24 for publishing + uses: actions/setup-node@v6 + with: + node-version: '24.x' + package-manager-cache: false + + # pnpm publish delegates to the system npm CLI, which handles OIDC. + - name: Install npm with trusted publishing support + run: npm install --global npm@11.17.0 + + - name: Publish to npm with OIDC run: node common/scripts/install-run-rush.js publish --publish --include-all --tag hotfix - name: Update shrinkwrap diff --git a/.github/workflows/pre-release.yml b/.github/workflows/pre-release.yml index 39d6f6a..86d8ae3 100644 --- a/.github/workflows/pre-release.yml +++ b/.github/workflows/pre-release.yml @@ -13,6 +13,7 @@ jobs: permissions: contents: write + id-token: write strategy: matrix: @@ -20,15 +21,13 @@ jobs: # See supported Node.js release schedule at https://nodejs.org/en/about/releases/ steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v6 - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v3 + uses: actions/setup-node@v6 with: node-version: ${{ matrix.node-version }} - cache: 'npm' - cache-dependency-path: './common/config/rush/pnpm-lock.yaml' + package-manager-cache: false - # Install rush - name: Install rush run: node common/scripts/install-run-rush.js install --bypass-policy @@ -52,10 +51,18 @@ jobs: - name: Build packages run: node common/scripts/install-run-rush.js build --only tag:package - - name: Publish to npm - env: - NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} - NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} + # Keep build/test on Node 20; npm trusted publishing requires Node >=22.14. + - name: Use Node.js 24 for publishing + uses: actions/setup-node@v6 + with: + node-version: '24.x' + package-manager-cache: false + + # pnpm publish delegates to the system npm CLI, which handles OIDC. + - name: Install npm with trusted publishing support + run: npm install --global npm@11.17.0 + + - name: Publish to npm with OIDC run: node common/scripts/install-run-rush.js publish --publish --include-all --tag ${{ steps.semver_parser.outputs.pre_release_type }} - name: Update shrinkwrap diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 913ff4f..15769bf 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -11,6 +11,7 @@ jobs: permissions: contents: write pull-requests: write + id-token: write env: CI: true @@ -21,19 +22,17 @@ jobs: # See supported Node.js release schedule at https://nodejs.org/en/about/releases/ steps: - - uses: actions/checkout@v3 + - uses: actions/checkout@v6 - run: | git config user.name ${{ github.actor }} git config user.email ${{ github.actor }}@users.noreply.github.com - name: Use Node.js ${{ matrix.node-version }} - uses: actions/setup-node@v3 + uses: actions/setup-node@v6 with: node-version: ${{ matrix.node-version }} - cache: 'npm' - cache-dependency-path: './common/config/rush/pnpm-lock.yaml' + package-manager-cache: false - # Install rush - name: Install rush run: node common/scripts/install-run-rush.js install --bypass-policy @@ -58,10 +57,18 @@ jobs: run: node common/scripts/install-run-rush.js build --only tag:package - run: node common/scripts/install-run-rush.js test --only tag:package - - name: Publish to npm - env: - NODE_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} - NPM_AUTH_TOKEN: ${{secrets.NPM_TOKEN}} + # Keep build/test on Node 20; npm trusted publishing requires Node >=22.14. + - name: Use Node.js 24 for publishing + uses: actions/setup-node@v6 + with: + node-version: '24.x' + package-manager-cache: false + + # pnpm publish delegates to the system npm CLI, which handles OIDC. + - name: Install npm with trusted publishing support + run: npm install --global npm@11.17.0 + + - name: Publish to npm with OIDC run: node common/scripts/install-run-rush.js publish --publish --include-all - name: Update shrinkwrap diff --git a/common/changes/@visactor/vlayouts/feat-sankey-nodeHeight-callback_2025-07-07-07-16.json b/common/changes/@visactor/vlayouts/feat-sankey-nodeHeight-callback_2025-07-07-07-16.json deleted file mode 100644 index 4753d35..0000000 --- a/common/changes/@visactor/vlayouts/feat-sankey-nodeHeight-callback_2025-07-07-07-16.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "changes": [ - { - "packageName": "@visactor/vlayouts", - "comment": " feat: add columns information in sankey nodeHeight callback", - "type": "none" - } - ], - "packageName": "@visactor/vlayouts" -} \ No newline at end of file diff --git a/common/config/rush/.npmrc-publish b/common/config/rush/.npmrc-publish index a3607cd..3da8b65 100644 --- a/common/config/rush/.npmrc-publish +++ b/common/config/rush/.npmrc-publish @@ -17,5 +17,7 @@ # environment variable, which can be referenced from .npmrc using ${} expansion. For example: # # +registry=https://registry.npmjs.org/ +# GitHub Actions uses OIDC. Rush omits the optional local token below when unset. //registry.npmjs.org/:_authToken=${NPM_AUTH_TOKEN} # diff --git a/common/config/rush/pnpm-lock.yaml b/common/config/rush/pnpm-lock.yaml index 99feaa8..85c8f89 100644 --- a/common/config/rush/pnpm-lock.yaml +++ b/common/config/rush/pnpm-lock.yaml @@ -22,7 +22,7 @@ importers: specifier: ^6.5.0 version: 6.5.0 '@visactor/vutils': - specifier: workspace:1.0.23 + specifier: workspace:1.0.24 version: link:../vutils d3-dsv: specifier: ^2.0.0 @@ -140,10 +140,10 @@ importers: specifier: ^6.5.0 version: 6.5.0 '@visactor/vscale': - specifier: workspace:1.0.23 + specifier: workspace:1.0.24 version: link:../vscale '@visactor/vutils': - specifier: workspace:1.0.23 + specifier: workspace:1.0.24 version: link:../vutils eventemitter3: specifier: ^4.0.7 @@ -201,7 +201,7 @@ importers: ../../packages/vscale: dependencies: '@visactor/vutils': - specifier: workspace:1.0.23 + specifier: workspace:1.0.24 version: link:../vutils devDependencies: '@internal/bundler': diff --git a/common/config/rush/version-policies.json b/common/config/rush/version-policies.json index b100f79..ce47e2c 100644 --- a/common/config/rush/version-policies.json +++ b/common/config/rush/version-policies.json @@ -1 +1 @@ -[{"definitionName":"lockStepVersion","policyName":"vutilMain","version":"1.0.23","nextBump":"patch"}] +[{"definitionName":"lockStepVersion","policyName":"vutilMain","version":"1.0.24","nextBump":"patch"}] diff --git a/docs/superpowers/plans/2026-09-18-npm-trusted-publishing.md b/docs/superpowers/plans/2026-09-18-npm-trusted-publishing.md new file mode 100644 index 0000000..3d61197 --- /dev/null +++ b/docs/superpowers/plans/2026-09-18-npm-trusted-publishing.md @@ -0,0 +1,49 @@ +# npm Trusted Publishing Implementation Plan + +> Execute inline in the current task. The user has approved the migration; preserve the existing release behavior. + +**Goal:** Publish VUtil packages from GitHub Actions using OIDC instead of `NPM_TOKEN`. + +**Architecture:** Keep Rush and pnpm publishing. Provide a compatible system npm CLI and OIDC permissions, then register each existing release workflow in each npm package's trusted publishers. + +**Tech Stack:** GitHub Actions, Node 20 for build/test and Node 24 for publishing, npm 11.17.0, Rush 5.164.0, pnpm 10.7.0. + +## Global Constraints + +- All three release workflows must preserve their branch triggers, versioning, distribution tags, and post-publish steps. +- Use `VisActor/VUtil` with matching case in repository metadata and npm settings. +- Only a real GitHub-hosted release can validate OIDC authentication end to end. + +## Task 1: Update release configuration + +**Files:** `.github/workflows/release.yml`, `.github/workflows/pre-release.yml`, `.github/workflows/hotfix-release.yml`, `common/config/rush/.npmrc-publish`, and the four `packages/*/package.json` files. + +- [x] Keep the build/test Node matrix at `20.x`; use `actions/checkout@v6` and `actions/setup-node@v6`, with a separate Node 24 setup immediately before publishing. +- [x] Disable setup-node package manager caching for release jobs and install `npm@11.17.0` explicitly. +- [x] Add `id-token: write` alongside existing job permissions and remove the publish step's `NODE_AUTH_TOKEN` / `NPM_AUTH_TOKEN` environment block. +- [x] Add `repository.type = git`, `repository.url = git+https://github.com/VisActor/VUtil.git`, and each package's `repository.directory`. +- [x] Set the publish registry explicitly and document the optional local token reference. + +## Task 2: Validate the existing publication path + +- [x] Run `git diff --check` and an Actions workflow validator. +- [x] Run `node common/scripts/install-run-rush.js install --bypass-policy` with Node 20. +- [x] Run `node common/scripts/install-run-rush.js build --only tag:package` and `CI=true node common/scripts/install-run-rush.js test --only tag:package`. +- [x] Use pnpm 10.7.0 with `publish --dry-run --no-git-checks` for each public package; verify packed manifests contain canonical repository metadata and no `workspace:` dependency specifications. + +## Task 3: Configure npm and report rollout status + +- [x] After the user signs in, inspect existing trusted publishers for each of the four packages. +- [x] Add any missing GitHub Actions publishers for `VisActor/VUtil`: `release.yml`, `pre-release.yml`, and `hotfix-release.yml`, with no environment and direct publishing allowed. +- [x] Verify saved npm settings and document any required user authentication step. +- [x] Report local validation and the remaining release action accurately; do not claim a successful OIDC publish before a real Actions run succeeds. + +## Validation results and current state + +- Actionlint 1.7.12 and `git diff --check` pass. +- Node 20.20.2 install/build/test pass: 92 suites and 737 tests pass; 1 suite and 6 tests remain skipped by the existing configuration. +- Node 24.19.0 / npm 11.17.0 / pnpm 10.7.0 dry-runs pass for all four packages. Packed repository metadata, resolved workspace dependencies, and cjs/es/dist outputs were checked. Dry-runs use temporary unpacked copies bumped to 1.0.24, as the working tree's 1.0.23 versions already exist on npm. Logs and tarballs: `/tmp/vutil-oidc-packages-y0ay5lak`. +- npm confirms all four packages (`vdataset`, `vutils`, `vscale`, and `vlayouts`) trust all three workflows in `VisActor/VUtil`, with direct publish allowed (12/12 connections saved and verified). +- The final `vlayouts` hotfix connection was saved in Google Chrome after the user completed 2FA there; the in-app browser could not accept the user's verification input. +- Local validation did not publish any packages. A real GitHub Actions run must confirm OIDC authentication end to end. +- Roll out these changes by committing and pushing to `release/1.0.24`. The original failed run used `3998da1b11b59738cd55766b093a96389077b3db`; rerunning it would retain its original workflow. diff --git a/docs/superpowers/specs/2026-09-18-npm-trusted-publishing-design.md b/docs/superpowers/specs/2026-09-18-npm-trusted-publishing-design.md new file mode 100644 index 0000000..d3bb6d9 --- /dev/null +++ b/docs/superpowers/specs/2026-09-18-npm-trusted-publishing-design.md @@ -0,0 +1,23 @@ +# npm trusted publishing + +## Goal + +Restore automated releases without an expiring npm token. The user approved migrating the GitHub workflows and npm package settings to trusted publishing. + +## Approach + +Keep Rush 5.164.0 and pnpm 10.7.0. The pinned pnpm implementation packs workspace dependencies and invokes the system npm CLI, inheriting the GitHub OIDC environment. Keep build and test on Node 20, then switch all three workflows to Node 24 and npm 11.17.0 immediately before publishing, grant `id-token: write`, and stop passing `NPM_TOKEN` to publishing. Preserve the existing release commands and distribution tags. + +The existing vscale Wilkinson tiny-number test fails under Node 24 but passes under Node 20. Restricting the runtime upgrade to publishing avoids coupling this authentication migration to numerical behavior changes. + +Replacing Rush with a custom publisher would duplicate its version checks, workspace packing, and partial-release recovery. Rotating a granular token would restore publishing temporarily but retain the expiry problem. Neither is needed for this migration. + +Add the canonical `git+https://github.com/VisActor/VUtil.git` repository URL and package directory to each public package. These metadata let npm validate the repository when generating provenance. Keep `.npmrc-publish` pointed at the public npm registry; its optional token reference remains available for local workflows and is omitted by Rush when unset in CI. + +## npm configuration + +For each of `@visactor/vdataset`, `@visactor/vlayouts`, `@visactor/vscale`, and `@visactor/vutils`, add GitHub Actions trusted publishers for `VisActor/VUtil` with workflow filenames `release.yml`, `pre-release.yml`, and `hotfix-release.yml`. Leave the environment name unset because these jobs do not declare an environment. Allow direct `npm publish`, matching the existing release process. Do not change unrelated package permissions or revoke credentials during setup. + +## Validation and rollout + +Validate workflow syntax, build and test the four packages with Node 20, and dry-run packing/publishing with the pinned pnpm and npm versions. Check packed repository metadata and resolved workspace dependency versions. These checks cannot prove OIDC exchange locally; that requires a real GitHub Actions release after npm settings are saved and the workflow changes reach the release branch. Re-running the original failed run alone will reuse its old workflow. diff --git a/packages/vdataset/CHANGELOG.json b/packages/vdataset/CHANGELOG.json index 772946c..cc1fadb 100644 --- a/packages/vdataset/CHANGELOG.json +++ b/packages/vdataset/CHANGELOG.json @@ -1,6 +1,12 @@ { "name": "@visactor/vdataset", "entries": [ + { + "version": "1.0.24", + "tag": "@visactor/vdataset_v1.0.24", + "date": "Fri, 18 Sep 2026 08:59:37 GMT", + "comments": {} + }, { "version": "1.0.23", "tag": "@visactor/vdataset_v1.0.23", diff --git a/packages/vdataset/CHANGELOG.md b/packages/vdataset/CHANGELOG.md index 9e42461..46f86bd 100644 --- a/packages/vdataset/CHANGELOG.md +++ b/packages/vdataset/CHANGELOG.md @@ -1,6 +1,11 @@ # Change Log - @visactor/vdataset -This log was last generated on Wed, 11 Mar 2026 06:07:08 GMT and should not be manually modified. +This log was last generated on Fri, 18 Sep 2026 08:59:37 GMT and should not be manually modified. + +## 1.0.24 +Fri, 18 Sep 2026 08:59:37 GMT + +_Version update only_ ## 1.0.23 Wed, 11 Mar 2026 06:07:08 GMT diff --git a/packages/vdataset/package.json b/packages/vdataset/package.json index 97ebbc2..d7dad6e 100644 --- a/packages/vdataset/package.json +++ b/packages/vdataset/package.json @@ -1,6 +1,6 @@ { "name": "@visactor/vdataset", - "version": "1.0.23", + "version": "1.0.24", "main": "cjs/index.js", "module": "es/index.js", "types": "es/index.d.ts", @@ -21,6 +21,11 @@ "name": "VisActor", "url": "https://VisActor.io/" }, + "repository": { + "type": "git", + "url": "git+https://github.com/VisActor/VUtil.git", + "directory": "packages/vdataset" + }, "license": "MIT", "keywords": [ "visual", @@ -38,7 +43,7 @@ "test-cov": "jest -w 16 --coverage" }, "dependencies": { - "@visactor/vutils": "workspace:1.0.23", + "@visactor/vutils": "workspace:1.0.24", "@turf/flatten": "^6.5.0", "@turf/helpers": "^6.5.0", "@turf/rewind": "^6.5.0", diff --git a/packages/vlayouts/CHANGELOG.json b/packages/vlayouts/CHANGELOG.json index 789eec5..f25d060 100644 --- a/packages/vlayouts/CHANGELOG.json +++ b/packages/vlayouts/CHANGELOG.json @@ -1,6 +1,18 @@ { "name": "@visactor/vlayouts", "entries": [ + { + "version": "1.0.24", + "tag": "@visactor/vlayouts_v1.0.24", + "date": "Fri, 18 Sep 2026 08:59:37 GMT", + "comments": { + "none": [ + { + "comment": " feat: add columns information in sankey nodeHeight callback" + } + ] + } + }, { "version": "1.0.23", "tag": "@visactor/vlayouts_v1.0.23", diff --git a/packages/vlayouts/CHANGELOG.md b/packages/vlayouts/CHANGELOG.md index 9d423e6..7b88eea 100644 --- a/packages/vlayouts/CHANGELOG.md +++ b/packages/vlayouts/CHANGELOG.md @@ -1,6 +1,13 @@ # Change Log - @visactor/vlayouts -This log was last generated on Wed, 11 Mar 2026 06:07:08 GMT and should not be manually modified. +This log was last generated on Fri, 18 Sep 2026 08:59:37 GMT and should not be manually modified. + +## 1.0.24 +Fri, 18 Sep 2026 08:59:37 GMT + +### Updates + +- feat: add columns information in sankey nodeHeight callback ## 1.0.23 Wed, 11 Mar 2026 06:07:08 GMT diff --git a/packages/vlayouts/package.json b/packages/vlayouts/package.json index 600da97..3cdd882 100644 --- a/packages/vlayouts/package.json +++ b/packages/vlayouts/package.json @@ -1,6 +1,6 @@ { "name": "@visactor/vlayouts", - "version": "1.0.23", + "version": "1.0.24", "main": "cjs/index.js", "module": "es/index.js", "types": "es/index.d.ts", @@ -14,6 +14,11 @@ "name": "VisActor", "url": "https://VisActor.io/" }, + "repository": { + "type": "git", + "url": "git+https://github.com/VisActor/VUtil.git", + "directory": "packages/vlayouts" + }, "license": "MIT", "keywords": [ "visual", @@ -49,8 +54,8 @@ "canvas": "~3.1.0" }, "dependencies": { - "@visactor/vscale": "workspace:1.0.23", - "@visactor/vutils": "workspace:1.0.23", + "@visactor/vscale": "workspace:1.0.24", + "@visactor/vutils": "workspace:1.0.24", "eventemitter3": "^4.0.7", "@turf/invariant": "^6.5.0", "@turf/helpers": "^6.5.0" diff --git a/packages/vscale/CHANGELOG.json b/packages/vscale/CHANGELOG.json index 0e4db6b..8cc01f0 100644 --- a/packages/vscale/CHANGELOG.json +++ b/packages/vscale/CHANGELOG.json @@ -1,6 +1,12 @@ { "name": "@visactor/vscale", "entries": [ + { + "version": "1.0.24", + "tag": "@visactor/vscale_v1.0.24", + "date": "Fri, 18 Sep 2026 08:59:37 GMT", + "comments": {} + }, { "version": "1.0.23", "tag": "@visactor/vscale_v1.0.23", diff --git a/packages/vscale/CHANGELOG.md b/packages/vscale/CHANGELOG.md index d7223fa..d14190a 100644 --- a/packages/vscale/CHANGELOG.md +++ b/packages/vscale/CHANGELOG.md @@ -1,6 +1,11 @@ # Change Log - @visactor/vscale -This log was last generated on Wed, 11 Mar 2026 06:07:08 GMT and should not be manually modified. +This log was last generated on Fri, 18 Sep 2026 08:59:37 GMT and should not be manually modified. + +## 1.0.24 +Fri, 18 Sep 2026 08:59:37 GMT + +_Version update only_ ## 1.0.23 Wed, 11 Mar 2026 06:07:08 GMT diff --git a/packages/vscale/package.json b/packages/vscale/package.json index d585898..751a7cb 100644 --- a/packages/vscale/package.json +++ b/packages/vscale/package.json @@ -1,6 +1,6 @@ { "name": "@visactor/vscale", - "version": "1.0.23", + "version": "1.0.24", "description": "Scales for visual encoding, used in VGrammar, VTable", "keywords": [ "scale", @@ -13,6 +13,11 @@ "name": "VisActor", "url": "https://VisActor.io/" }, + "repository": { + "type": "git", + "url": "git+https://github.com/VisActor/VUtil.git", + "directory": "packages/vscale" + }, "license": "MIT", "sideEffects": false, "main": "cjs/index.js", @@ -34,7 +39,7 @@ "test-cov": "jest -w 16 --coverage" }, "dependencies": { - "@visactor/vutils": "workspace:1.0.23" + "@visactor/vutils": "workspace:1.0.24" }, "devDependencies": { "@internal/bundler": "workspace:*", diff --git a/packages/vutils/CHANGELOG.json b/packages/vutils/CHANGELOG.json index ce83b6c..1d4b205 100644 --- a/packages/vutils/CHANGELOG.json +++ b/packages/vutils/CHANGELOG.json @@ -1,6 +1,12 @@ { "name": "@visactor/vutils", "entries": [ + { + "version": "1.0.24", + "tag": "@visactor/vutils_v1.0.24", + "date": "Fri, 18 Sep 2026 08:59:37 GMT", + "comments": {} + }, { "version": "1.0.23", "tag": "@visactor/vutils_v1.0.23", diff --git a/packages/vutils/CHANGELOG.md b/packages/vutils/CHANGELOG.md index 12cf882..7b7c350 100644 --- a/packages/vutils/CHANGELOG.md +++ b/packages/vutils/CHANGELOG.md @@ -1,6 +1,11 @@ # Change Log - @visactor/vutils -This log was last generated on Wed, 11 Mar 2026 06:07:08 GMT and should not be manually modified. +This log was last generated on Fri, 18 Sep 2026 08:59:37 GMT and should not be manually modified. + +## 1.0.24 +Fri, 18 Sep 2026 08:59:37 GMT + +_Version update only_ ## 1.0.23 Wed, 11 Mar 2026 06:07:08 GMT diff --git a/packages/vutils/package.json b/packages/vutils/package.json index 9edf7c7..a67e0c8 100644 --- a/packages/vutils/package.json +++ b/packages/vutils/package.json @@ -1,6 +1,6 @@ { "name": "@visactor/vutils", - "version": "1.0.23", + "version": "1.0.24", "main": "cjs/index.js", "module": "es/index.js", "types": "es/index.d.ts", @@ -14,6 +14,11 @@ "name": "VisActor", "url": "https://VisActor.io/" }, + "repository": { + "type": "git", + "url": "git+https://github.com/VisActor/VUtil.git", + "directory": "packages/vutils" + }, "license": "MIT", "keywords": [ "visual",