Skip to content

0.0.4 — Standardized CI workflows and improved npm publish automation

Latest

Choose a tag to compare

@tobrien tobrien released this 01 Feb 02:28
· 1 commit to working since this release
6fbc0e2

Overview

0.0.4 focuses on release/CI hygiene: more consistent GitHub Actions behavior, faster/safer npm publishing, and clearer separation between production releases and development publishes.

Changes

npm publishing workflow: safer production releases, better dev publishes

Updates to .github/workflows/npm-publish.yml change how and when packages are published:

  • Production publishes only happen on GitHub Release creation

    • If package.json contains a production version (no -... prerelease suffix), the workflow publishes only when triggered by a release: created event.
    • Pushes to the working branch will not publish production versions, preventing accidental “latest” publishes.
  • Pre-release publishing supports uniquely-versioned dev builds

    • If package.json contains a prerelease version (contains -), the workflow publishes under the dev npm dist-tag.
    • The version is rewritten at publish-time to include a timestamp and short SHA:
      • Example: 0.0.4-dev.0 → 0.0.4-dev.<timestamp>.<sha>
    • This makes dev publishes traceable and avoids version collisions.
  • Publishing setup streamlined

    • Node is set to Node 24 in the workflow.
    • Publish steps run only when the workflow determines should_publish=true.

Test workflow: more consistent installs and less wasted CI time

Updates to .github/workflows/test.yml:

  • Expanded branch coverage for CI

    • Tests now run on pushes to: main, working, release/**, feature/**, dependabot/** (and PRs targeting main).
  • Concurrency control

    • Adds workflow concurrency with cancellation of in-progress runs for the same branch/ref, reducing redundant CI runs.
  • Clean install approach (package-lock is ignored)

    • The workflow explicitly removes node_modules and package-lock.json and runs npm install --force.
    • The intent is to avoid CI flakiness around optional/platform-specific dependencies (notably Rollup native bindings) given that package-lock.json is gitignored.

Version bump

  • package.json version is now 0.0.4.

Impact

For users

  • No runtime/library feature changes in this release; it primarily affects how builds/tests/releases are produced and published.

For maintainers / contributors

  • Expect different publishing behavior:

    • “latest” is only published from GitHub Releases, not from branch pushes.
    • Dev builds (prerelease versions) can still be published from working, and will be uniquely versioned.
  • CI runs may behave differently due to:

    • New branch triggers
    • Concurrency cancellation
    • Forced clean installs in the test workflow

Breaking changes

  • No API-breaking changes detected in this release range.
  • Operational note: the npm publish workflow behavior is materially different (production publishes gated on GitHub Release creation). If you relied on production publishes from branch pushes, adjust your release process accordingly.