Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 6 additions & 40 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,8 @@ jobs:
publish-stable:
if: inputs.mode == 'stable' && inputs.package != 'bailian-kb-dsh'
name: publish stable (${{ inputs.package }}) to npm + binary + tag
runs-on: ubuntu-latest
# Apple's codesign handles Bun's cross-compiled Intel Mach-O; rcodesign 0.29.0 panics here.
runs-on: macos-15-intel
environment: production # Required Reviewers gate
permissions:
contents: write # push tag + create GitHub Release with binary assets
Expand All @@ -52,28 +53,10 @@ jobs:
set -euo pipefail
GITLEAKS_VERSION=8.21.2
curl -sSfL \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_darwin_x64.tar.gz" \
| sudo tar -xz -C /usr/local/bin gitleaks
gitleaks version

- name: Ensure zip and tar (per-platform binary archives)
run: sudo apt-get update && sudo apt-get install -y zip

# bun build --compile leaves an invalid darwin linker signature. rcodesign
# re-signs those Mach-O files on the Linux runner (binary-codesign.mjs).
- name: Install rcodesign (ad-hoc sign darwin binaries)
run: |
set -euo pipefail
RCODESIGN_VERSION=0.29.0
asset="apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl.tar.gz"
curl -fsSL -o "/tmp/${asset}" \
"https://github.com/indygreg/apple-platform-rs/releases/download/apple-codesign/${RCODESIGN_VERSION}/${asset}"
tar -xzf "/tmp/${asset}" -C /tmp
sudo install -m 755 \
"/tmp/apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl/rcodesign" \
/usr/local/bin/rcodesign
rcodesign --version

- run: pnpm install --frozen-lockfile

# Binary compile uses `bun build --compile` CLI (not Bun.build API).
Expand Down Expand Up @@ -101,7 +84,8 @@ jobs:
publish-channel:
if: inputs.mode == 'channel' && inputs.package != 'bailian-kb-dsh'
name: publish channel (${{ inputs.package }}) to npm + binary
runs-on: ubuntu-latest
# Keep binary publishing on Apple codesign; Linux rcodesign 0.29.0 panics on Intel Mach-O.
runs-on: macos-15-intel
permissions:
contents: write # create prerelease GitHub Release with binary assets
id-token: write # OIDC for npm Trusted Publishing + provenance
Expand All @@ -127,28 +111,10 @@ jobs:
set -euo pipefail
GITLEAKS_VERSION=8.21.2
curl -sSfL \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_darwin_x64.tar.gz" \
| sudo tar -xz -C /usr/local/bin gitleaks
gitleaks version

- name: Ensure zip and tar (per-platform binary archives)
run: sudo apt-get update && sudo apt-get install -y zip

# bun build --compile leaves an invalid darwin linker signature. rcodesign
# re-signs those Mach-O files on the Linux runner (binary-codesign.mjs).
- name: Install rcodesign (ad-hoc sign darwin binaries)
run: |
set -euo pipefail
RCODESIGN_VERSION=0.29.0
asset="apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl.tar.gz"
curl -fsSL -o "/tmp/${asset}" \
"https://github.com/indygreg/apple-platform-rs/releases/download/apple-codesign/${RCODESIGN_VERSION}/${asset}"
tar -xzf "/tmp/${asset}" -C /tmp
sudo install -m 755 \
"/tmp/apple-codesign-${RCODESIGN_VERSION}-x86_64-unknown-linux-musl/rcodesign" \
/usr/local/bin/rcodesign
rcodesign --version

- run: pnpm install --frozen-lockfile

# Binary compile uses `bun build --compile` CLI (not Bun.build API).
Expand Down
3 changes: 2 additions & 1 deletion docs/agents/publish.md
Original file line number Diff line number Diff line change
Expand Up @@ -115,7 +115,7 @@ node tools/release/publish-channel.mjs --channel test --knowledge --dry-run
- **GitHub Release**:`contents: write` + `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}`(stable / channel 均需)
- **Node 版本**:24(npm 11.5+ 才支持 OIDC token 交换)
- **Bun**:`oven-sh/setup-bun`,版本钉死在 workflow 中
- **darwin 签名**:编完后 `binary-codesign.mjs` 对 darwin Mach-O 做 ad-hoc 重签,并按 Apple 的方式重算每一页 SHA-256(末页不补零)。对不上就中止发布。macOS runner 额外跑 `codesign --verify --strict`。Linux runner 用 `rcodesign 0.29.0 sign`;不要用 `rcodesign verify`(会拒绝 Apple 已通过的 ad-hoc 签名)。漏签时 Apple Silicon 会在启动时 SIGKILL
- **darwin 签名**:编完后 `binary-codesign.mjs` 对 darwin Mach-O 做 ad-hoc 重签,并按 Apple 的方式重算每一页 SHA-256(末页不补零)。对不上就中止发布。含二进制的 stable / channel job 使用 `macos-15-intel` 和 Apple `codesign`;`rcodesign 0.29.0` 在 Linux 上签 Bun 的 darwin-x64 二进制会 panic。漏签时 Apple Silicon 会在启动时 SIGKILL
- **Actions 版本**:checkout/setup-node/pnpm-action 均为 v6(Node 24 兼容)
- **npm 配置**:当前 release tooling 发布的包(`bailian-cli-core` / `bailian-cli-runtime` / `bailian-cli-commands` / `bailian-cli` / `knowledge-studio-cli`)的 Trusted Publisher 指向 `modelstudioai/cli` 的 `publish.yml`;新增发布包时同步 npm Trusted Publisher

Expand Down Expand Up @@ -162,6 +162,7 @@ node tools/release/publish-channel.mjs --channel test --knowledge --dry-run
| CI 用 Node 22(npm 10)跑 publish | npm 10 不支持 OIDC token 交换,publish 报 404 |
| stable 发布前没有升级版本号 | 所选发布集合的版本已全部存在于 npm,CI 明确报错并要求先升级版本号 |
| channel job 缺少 `contents: write` | `gh release create` 失败 |
| 在 Linux runner 上用 `rcodesign 0.29.0` 签 Bun 的 darwin-x64 二进制 | `rcodesign` 因签名范围越界 panic;二进制发布在生成 Release / npm 前中止 |
| darwin 二进制编完后没有 ad-hoc 重签 | Apple Silicon / macOS 27 对失效的 linker 签名直接 SIGKILL(`Killed: 9`) |
| npm 先于二进制 / OSS 成功 | latest 已发出,CDN 上没有对应 zip/tar.gz;OSS 网络失败时无法回滚 npm |
| stable 未先推 tag 就建 Release | `--verify-tag` 失败 |
Loading