Skip to content

[verification only] ci: GitHub Actions workflows - #1

Closed
edusperoni wants to merge 3 commits into
masterfrom
ci/github-actions-provenance
Closed

edusperoni wants to merge 3 commits into
masterfrom
ci/github-actions-provenance

Conversation

@edusperoni

Copy link
Copy Markdown
Owner

Fork-internal PR to exercise the tests workflow (JS suite + native macOS/Windows builds) before the upstream PR merges. Not for merging here.

…ions

Releases were assembled by hand: build with Xcode, build twice with Visual
Studio, copy the results together, npm pack, npm publish. The last release
shipped an arm64-only macOS binary and no Windows binaries as a result.

This adds the same release pipeline the NativeScript CLI uses:

- build-native.yml (reusable) compiles the universal macOS binary on a macOS
  runner and the x64/ia32 Windows binaries on a Windows runner, verifying
  each and uploading them as artifacts.
- tests.yml runs the mocha suite on Node 20/22/24 and the native builds on
  every pull request and push to master.
- npm_release.yml publishes a rolling "next" prerelease on every push to
  master, a stable release on a v* tag, and supports a manual dispatch that
  bumps, tags and releases. Publishing uses npm trusted publishing (OIDC)
  from the npm-publish environment with --provenance, with a granular-token
  fallback behind the USE_NPM_TOKEN repository variable. Tag pushes and
  dispatched releases also create a GitHub release with the tarball and an
  in-toto statement attached.

package.json's repository URL is updated to the NativeScript org: npm refuses
to publish with provenance when it does not match the repository the workflow
runs in. semver and conventional-changelog-cli are added as devDependencies
for the version scripts and the release notes.
The Windows sources have not compiled since the iOS 17 changes in NativeScript#81:
IOSDeviceLib.cpp includes <dlfcn.h> unconditionally and resolves SSL_free
through dlsym, SocketHelper.cpp calls AMDServiceConnectionSend which
Declarations.h only declares for macOS, GDBHelper.cpp passes a HANDLE to
closesocket, and a translation unit pulls winsock.h in ahead of winsock2.h.
That is also why 0.9.5 shipped without bin/win32. The release pipeline
covers what the package can ship today; a windows-latest job belongs in
build-native.yml once the sources build again.
@edusperoni

Copy link
Copy Markdown
Owner Author

Verification complete: JS tests (Node 20/22/24) and the macOS universal build pass on c203999. Upstream PR is NativeScript#87.

@edusperoni edusperoni closed this Sep 3, 2026
Mirrors the NativeScript core repo's preview-release workflow. Every push to
master and every pull request publishes the packed package, including the
freshly built macOS binary, so a fix can be tried from a PR with
npm i https://pkg.pr.new/ios-device-lib@<sha> before it is released.
Requires the pkg.pr.new GitHub App to be installed on the repository.
@edusperoni edusperoni reopened this Sep 4, 2026
@edusperoni

Copy link
Copy Markdown
Owner Author

Verified on 7e9c2a0: Tests green; Preview release builds the binary and reaches pkg-pr-new publish, which fails only because the pkg.pr.new App is not installed on this fork.

@edusperoni edusperoni closed this Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant