Release 1.0.37 — CI/publish simplification, package.json normalization, dependency bumps
This release prepares and publishes version 1.0.37 and consolidates several maintenance tasks focused on package metadata, developer tooling, and CI/publishing behavior. The primary themes are: standardizing package.json formatting and version handling, updating lint/build-related devDependencies to pickup small fixes, and simplifying the GitHub Actions workflow used for npm publishing so the publish job runs without a separate build job. The changes are intentionally conservative and target deterministic installs, cleaner repo metadata, and a smaller, simpler publish pipeline.
Summary of what's included
- Finalize release metadata: package.json version set to 1.0.37 and related EOF/format normalizations.
- Dependency updates: bump @fjell/eslint-config across patch releases and pin esbuild to a specific patch version.
- Lockfile sync: package-lock.json updated to match bumped devDependencies so installs remain deterministic.
- CI/workflow changes: removed standalone build job from .github/workflows/npm-publish.yml and simplified the publish job to run without depending on a separate build job.
- Other housekeeping: multiple commits that remove or reintroduce the version field during development iterations; consistent end-of-file newline normalization across edits.
New Features
- None. This release contains infrastructure, dependency, and metadata updates only.
Improvements
-
package.json normalization and version handling
- Set package.json "version" to "1.0.37" for this release (prepare release commit). This replaces the development pre-release value used during development iterations.
- Several commits added or removed an in-file version field during development. The intent recorded in commit messages is to avoid conflicting in-file versioning when CI/release pipelines can manage version injection. For this release the file contains the released version.
- Normalized end-of-file formatting in package.json across multiple commits (ensure single trailing newline, consistent EOF behavior).
- Reordered and normalized package.json metadata ordering/format in the prepare release commit while preserving description/type/main fields.
-
DevDependency updates and pinning
- Bumped @fjell/eslint-config devDependency from earlier ranges up to ^1.1.24 to pick up lint-rule fixes and small patches. Commits show progressive bumps: ^1.1 -> ^1.1.19 -> ^1.1.20 -> ^1.1.21 -> ^1.1.23 -> ^1.1.24 as the chain of updates.
- Impact: updated ESLint rules/fixes apply to local linting and CI lint steps (when run). Consumers and contributors will receive the updated lint rules on fresh installs that honor the lockfile.
- Pinned esbuild to exact 0.25.9 in package.json (removed caret) to ensure deterministic installs and to apply a specific patch-level fix.
- Impact: builds that use esbuild will now use the pinned 0.25.9 version unless the lockfile or overrides change it.
- Bumped @fjell/eslint-config devDependency from earlier ranges up to ^1.1.24 to pick up lint-rule fixes and small patches. Commits show progressive bumps: ^1.1 -> ^1.1.19 -> ^1.1.20 -> ^1.1.21 -> ^1.1.23 -> ^1.1.24 as the chain of updates.
-
package-lock.json synchronization
- package-lock.json regenerated/updated to reflect the bumped @fjell/eslint-config versions and changes to devDependencies. The lockfile updates include adjusted resolved tarball URLs and integrity hashes so npm installs remain deterministic and produce reproducible node_modules.
CI / Release pipeline changes
-
GitHub Actions: simplify npm-publish workflow
- Removed the separate
buildjob from .github/workflows/npm-publish.yml. The deleted steps included checkout, setup-node, npm ci, lint, build, test, and a codecov upload. - Simplified the
publish-npmjob by removingneeds: builddependency so the publish job can run independently. - The publish job still performs checkout using actions/checkout@v4. The workflow now expects publishing to run without a dedicated build job.
- Rationale (from commit message): reduce workflow complexity for publishing; publishing is decoupled from running a project-specific build/test pipeline in this workflow. If full build/test verification is required before publish, that should be run elsewhere or reintroduced as part of a release pipeline.
- Impact: publishes triggered via this workflow will no longer automatically run the removed build/test/lint steps. Users and maintainers should be aware that the workflow no longer enforces those checks before publish; ensure CI or release automation runs the required checks prior to invoking the publish workflow.
- Removed the separate
-
Test workflow tuning
- One commit restricts the project's CI test workflow to run only on main and feature branches by removing 'release/**' and 'working' from on.push.branches in .github/workflows/test.yml and tidies some YAML formatting.
- Impact: reduces CI runs on release/working branches to limit unnecessary jobs. Reintroduce branches to the trigger list if those branches should run tests.
Bug Fixes and housekeeping
-
Deterministic installs and lockfile fixes
- The package-lock.json changes align the lockfile with the bumped devDependency versions and with the pinned esbuild version. That prevents inconsistent installs that could result from mismatched package.json and lockfile entries.
-
Formatting and EOF normalizations
- Multiple commits normalize trailing newlines and EOF formatting for package.json. This is low-risk housekeeping but helps avoid noisy diffs and tooling inconsistencies across editors/OSes.
Refactoring / structural changes
- Version field handling (notes and context)
- Several commits removed the version field from package.json during development iterations to avoid in-file versioning (intended to have release pipeline manage versions). Later commits reintroduced and finalized the version for the release. The repository now contains a committed release version (1.0.37) for this published release; future changes may again rely on external version injection depending on release process.
- Impact: Consumers should not need to change anything; however automated tooling that previously relied on a stable in-file version may need to account for pipeline-driven versioning if that approach is re-adopted.
Documentation updates
- No direct user-facing documentation or README changes were made in these commits. The changes are primarily in package metadata, lockfile, and workflow files.
Breaking changes
- None that alter runtime behavior or public APIs in code shipped to consumers. The changes are operational and developer-facing (build, lint, CI, packaging). However, note:
- The npm publish workflow no longer runs the removed build/test/lint steps; publishing may proceed without those checks unless they are enforced elsewhere.
- If consumers or CI rely on the presence/absence of the version field in package.json for automation, verify whether the release process will continue to commit versions into package.json or will manage versions externally.
Developer experience
- What maintainers should know
- Local linting rules may be updated when devDependencies are reinstalled due to the @fjell/eslint-config bump. Reinstall devDependencies (npm ci) to sync to the lockfile state.
- The pinned esbuild version reduces variability during local and CI builds; expect exact version 0.25.9 unless the lockfile or package.json is changed.
- Publishing via the GitHub Actions npm-publish workflow is now simpler; if build/test gating is required prior to publish, ensure those checks run in the desired pipeline step.
Files changed (high level)
-
package.json
- Version set to 1.0.37, devDependency bumps for @fjell/eslint-config, esbuild pinned to 0.25.9, EOF/formatting normalization and metadata ordering normalization.
-
package-lock.json
- Updated to reflect bumped devDependencies (updated resolved URLs and integrity hashes) for deterministic installs.
-
.github/workflows/npm-publish.yml
- Removed a standalone build job and simplified the publish job so it no longer needs the build job.
-
.github/workflows/test.yml
- Adjusted push branch triggers to restrict CI runs to main and feature branches and tidied YAML formatting.
How to adapt / next steps
- If you maintain local or CI scripts that expect the publish workflow to run build/test steps, update those scripts or introduce a separate workflow that performs verification before triggering the publish workflow.
- Run npm ci locally (or in CI) to pick up the updated package-lock.json and to ensure node_modules match the lockfile.
- Check linting locally after updating devDependencies to ensure the new @fjell/eslint-config rules do not surface unexpected issues.
If further changes are planned
- Consider documenting how versioning should be handled going forward (in-file vs. external pipeline) so automated tooling remains stable.
- If pre-publish verification is required, reintroduce build/test/lint steps into the publish workflow or add a dedicated verification workflow that gates publishing.
Changelog references (by commit messages)
- Bump package version to 1.0.37 (prepare release)
- Update package-lock.json to reflect @fjell/eslint-config v1.1.24
- Bump @fjell/eslint-config devDependency to ^1.1.24 and normalize package.json EOF
- Remove standalone build job from npm-publish workflow and simplify publish step
- Bump esbuild to 0.25.9 and pin version in package.json
- Multiple housekeeping commits adjusting package.json version fields and EOF normalization
This release focuses on predictable installs, updated lint/build tooling, and a smaller publish workflow rather than feature changes. Review CI and release automation expectations if your processes depended on the removed build job or on in-file versioning.