#!/usr/bin/env bash if [ -z "${REPO_ROOT:-}" ]; then REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" fi release_info() { echo "$@" } release_warn() { echo "Warning: $*" >&2 } release_fail() { echo "Error: $*" >&2 exit 1 } git_remote_exists() { git -C "$REPO_ROOT" remote get-url "$1" >/dev/null 2>&1 } github_repo_from_remote() { local remote_url remote_url="$(git -C "$REPO_ROOT" remote get-url "$1" 2>/dev/null || true)" [ -n "$remote_url" ] || return 1 remote_url="${remote_url%.git}" remote_url="${remote_url#ssh://}" node - "$remote_url" <<'NODE' const remoteUrl = process.argv[2]; const patterns = [ /^https?:\/\/github\.com\/([^/]+\/[^/]+)$/, /^git@github\.com:([^/]+\/[^/]+)$/, /^[^:]+:([^/]+\/[^/]+)$/ ]; for (const pattern of patterns) { const match = remoteUrl.match(pattern); if (!match) continue; process.stdout.write(match[1]); process.exit(0); } process.exit(1); NODE } resolve_release_remote() { local remote="${RELEASE_REMOTE:-${PUBLISH_REMOTE:-}}" if [ -n "$remote" ]; then git_remote_exists "$remote" || release_fail "git remote '$remote' does not exist." printf '%s\n' "$remote" return fi if git_remote_exists public-gh; then printf 'public-gh\n' return fi if git_remote_exists public; then printf 'public\n' return fi if git_remote_exists origin; then printf 'origin\n' return fi release_fail "no git remote found. Configure RELEASE_REMOTE or PUBLISH_REMOTE." } fetch_release_remote() { git -C "$REPO_ROOT" fetch "$1" --prune --tags } git_current_branch() { git -C "$REPO_ROOT" symbolic-ref --quiet --short HEAD 2>/dev/null || true } git_local_tag_exists() { git -C "$REPO_ROOT" show-ref --verify --quiet "refs/tags/$1" } git_remote_tag_exists() { git -C "$REPO_ROOT" ls-remote --exit-code --tags "$2" "refs/tags/$1" >/dev/null 2>&1 } get_last_stable_tag() { git -C "$REPO_ROOT" tag --list 'v*' --sort=-version:refname | head -1 } get_current_stable_version() { local tag tag="$(get_last_stable_tag)" if [ -z "$tag" ]; then printf '0.0.0\n' else printf '%s\n' "${tag#v}" fi } stable_version_slot_for_date() { node - "${1:-}" <<'NODE' const input = process.argv[2]; const date = input ? new Date(`${input}T00:00:00Z`) : new Date(); if (Number.isNaN(date.getTime())) { console.error(`invalid date: ${input}`); process.exit(1); } const month = String(date.getUTCMonth() + 1); const day = String(date.getUTCDate()).padStart(2, '0'); process.stdout.write(`${date.getUTCFullYear()}.${month}${day}`); NODE } utc_date_iso() { node <<'NODE' const date = new Date(); const y = date.getUTCFullYear(); const m = String(date.getUTCMonth() + 1).padStart(2, '0'); const d = String(date.getUTCDate()).padStart(2, '0'); process.stdout.write(`${y}-${m}-${d}`); NODE } next_stable_version() { local release_date="$1" shift node - "$release_date" "$@" <<'NODE' const input = process.argv[2]; const packageNames = process.argv.slice(3); const { execSync } = require("node:child_process"); const { readFileSync } = require("node:fs"); const date = input ? new Date(`${input}T00:00:00Z`) : new Date(); if (Number.isNaN(date.getTime())) { console.error(`invalid date: ${input}`); process.exit(1); } // Optional pre-fetched version data (see release-registry-versions.mjs). // Avoids one serial `npm view` round-trip per package. let versionsCache = null; if (process.env.RELEASE_PACKAGE_VERSIONS_FILE) { try { versionsCache = JSON.parse(readFileSync(process.env.RELEASE_PACKAGE_VERSIONS_FILE, "utf8")); } catch { versionsCache = null; } } const stableSlot = `${date.getUTCFullYear()}.${date.getUTCMonth() + 1}${String(date.getUTCDate()).padStart(2, "0")}`; const pattern = new RegExp(`^${stableSlot.replace(/\./g, '\\.')}\.(\\d+)$`); let max = -1; for (const packageName of packageNames) { let versions = []; if (versionsCache && Array.isArray(versionsCache[packageName])) { versions = versionsCache[packageName]; } else { try { const raw = execSync(`npm view ${JSON.stringify(packageName)} versions --json`, { encoding: "utf8", stdio: ["ignore", "pipe", "ignore"], }).trim(); if (raw) { const parsed = JSON.parse(raw); versions = Array.isArray(parsed) ? parsed : [parsed]; } } catch { versions = []; } } for (const version of versions) { const match = version.match(pattern); if (!match) continue; max = Math.max(max, Number(match[1])); } } process.stdout.write(`${stableSlot}.${max + 1}`); NODE } require_prerelease_channel() { case "$1" in canary|nightly|beta) ;; *) release_fail "unknown prerelease channel: $1" ;; esac } next_prerelease_version() { local channel="$1" local stable_version="$2" shift 2 require_prerelease_channel "$channel" node - "$channel" "$stable_version" "$@" <<'NODE' const channel = process.argv[2]; const stable = process.argv[3]; const packageNames = process.argv.slice(4); const { execSync } = require("node:child_process"); const { readFileSync } = require("node:fs"); // Optional pre-fetched version data (see release-registry-versions.mjs). // Avoids one serial `npm view` round-trip per package. let versionsCache = null; if (process.env.RELEASE_PACKAGE_VERSIONS_FILE) { try { versionsCache = JSON.parse(readFileSync(process.env.RELEASE_PACKAGE_VERSIONS_FILE, "utf8")); } catch { versionsCache = null; } } const pattern = new RegExp(`^${stable.replace(/\./g, '\\.')}-${channel}\\.(\\d+)$`); let max = -1; for (const packageName of packageNames) { let versions = []; if (versionsCache && Array.isArray(versionsCache[packageName])) { versions = versionsCache[packageName]; } else { try { const raw = execSync(`npm view ${JSON.stringify(packageName)} versions --json`, { encoding: "utf8", stdio: ["ignore", "pipe", "ignore"], }).trim(); if (raw) { const parsed = JSON.parse(raw); versions = Array.isArray(parsed) ? parsed : [parsed]; } } catch { versions = []; } } for (const version of versions) { const match = version.match(pattern); if (!match) continue; max = Math.max(max, Number(match[1])); } } process.stdout.write(`${stable}-${channel}.${max + 1}`); NODE } next_canary_version() { local stable_version="$1" shift next_prerelease_version canary "$stable_version" "$@" } release_notes_file() { printf '%s/releases/v%s.md\n' "$REPO_ROOT" "$1" } stable_tag_name() { printf 'v%s\n' "$1" } prerelease_tag_name() { require_prerelease_channel "$1" printf '%s/v%s\n' "$1" "$2" } canary_tag_name() { prerelease_tag_name canary "$1" } npm_package_version_exists() { local package_name="$1" local version="$2" local resolved resolved="$(npm view "${package_name}@${version}" version 2>/dev/null || true)" [ "$resolved" = "$version" ] } wait_for_npm_package_version() { local package_name="$1" local version="$2" local attempts="${3:-12}" local delay_seconds="${4:-5}" local attempt=1 while [ "$attempt" -le "$attempts" ]; do if npm_package_version_exists "$package_name" "$version"; then return 0 fi if [ "$attempt" -lt "$attempts" ]; then sleep "$delay_seconds" fi attempt=$((attempt + 1)) done return 1 } is_npm_tlog_duplicate_error() { local output="$1" grep -q "TLOG_CREATE_ENTRY_ERROR" <<< "$output" && grep -q "equivalent entry already exists in the transparency log" <<< "$output" } package_publish_tool() { node -e ' const pkg = require(process.cwd() + "/package.json"); const bundled = pkg.bundleDependencies ?? pkg.bundledDependencies ?? []; process.stdout.write(bundled.length > 0 ? "npm" : "pnpm"); ' } BUNDLED_NPM_PACK_VERSION="10.9.7" BUNDLED_NPM_PUBLISH_VERSION="11.18.0" run_bundled_npm_pack() { npx --yes "npm@$BUNDLED_NPM_PACK_VERSION" "$@" --ignore-scripts } run_bundled_npm_publish() { npx --yes "npm@$BUNDLED_NPM_PUBLISH_VERSION" "$@" --ignore-scripts --loglevel verbose } run_package_publish() { local publish_tool="$1" local dist_tag="$2" local disable_provenance="${3:-false}" if [ "$publish_tool" = "npm" ]; then if [ "$disable_provenance" = "true" ]; then run_bundled_npm_publish publish --tag "$dist_tag" --access public --provenance=false else run_bundled_npm_publish publish --tag "$dist_tag" --access public fi return fi if [ "$disable_provenance" = "true" ]; then pnpm publish --no-git-checks --tag "$dist_tag" --access public --provenance=false else pnpm publish --no-git-checks --tag "$dist_tag" --access public fi } publish_package_to_npm() { local dist_tag="$1" local package_name="$2" local package_version="$3" local publish_tool="${4:-pnpm}" local publish_log publish_log="$(mktemp "${TMPDIR:-/tmp}/paperclip-npm-publish.XXXXXX")" if (set -o pipefail; run_package_publish "$publish_tool" "$dist_tag" false 2>&1 | tee "$publish_log"); then rm -f "$publish_log" return 0 fi if ! is_npm_tlog_duplicate_error "$(cat "$publish_log")"; then rm -f "$publish_log" return 1 fi release_warn "npm publish hit a duplicate Sigstore transparency-log entry for ${package_name}@${package_version}." if npm_package_version_exists "$package_name" "$package_version"; then release_warn "npm already exposes ${package_name}@${package_version}; continuing to registry verification." rm -f "$publish_log" return 0 fi case "$dist_tag" in canary|nightly) ;; *) release_warn "Not retrying ${package_name}@${package_version} without provenance for dist-tag ${dist_tag}." rm -f "$publish_log" return 1 ;; esac release_warn "Retrying ${package_name}@${package_version} once with npm provenance disabled." if run_package_publish "$publish_tool" "$dist_tag" true; then rm -f "$publish_log" return 0 fi rm -f "$publish_log" return 1 } publish_package_to_npm_and_wait() { local dist_tag="$1" local package_name="$2" local package_version="$3" local publish_tool="${4:-pnpm}" local attempts="${5:-12}" local delay_seconds="${6:-5}" publish_package_to_npm "$dist_tag" "$package_name" "$package_version" "$publish_tool" || return 1 if wait_for_npm_package_version "$package_name" "$package_version" "$attempts" "$delay_seconds"; then return 0 fi release_warn "npm accepted ${package_name}@${package_version}, but the version did not become registry-visible." return 1 } verify_npm_installable() { local package_spec="$1" local expected_version="$2" local install_dir local installed_version install_dir="$(mktemp -d "${TMPDIR:-/tmp}/paperclip-release-install.XXXXXX")" if ! npm install --prefix "$install_dir" "$package_spec" --no-audit --no-fund; then rm -rf "$install_dir" return 1 fi installed_version="$(node -e "console.log(require(process.argv[1]).version)" "$install_dir/node_modules/paperclipai/package.json")" rm -rf "$install_dir" [ "$installed_version" = "$expected_version" ] } wait_for_release_registry_state() { local attempts="${1:-12}" local delay_seconds="${2:-5}" shift 2 local attempt=1 local output local status while [ "$attempt" -le "$attempts" ]; do if output="$(node "$REPO_ROOT/scripts/verify-release-registry-state.mjs" "$@" 2>&1)"; then [ -n "$output" ] && printf '%s\n' "$output" return 0 fi status=$? printf '%s\n' "$output" >&2 if [ "$status" -eq 2 ]; then return "$status" fi if [ "$attempt" -lt "$attempts" ]; then release_warn "npm registry metadata has not converged yet (attempt ${attempt}/${attempts}); retrying in ${delay_seconds}s." sleep "$delay_seconds" fi attempt=$((attempt + 1)) done return "${status:-1}" } require_clean_worktree() { if [ -n "$(git -C "$REPO_ROOT" status --porcelain)" ]; then release_fail "working tree is not clean. Commit, stash, or remove changes before releasing." fi } require_on_master_branch() { local current_branch current_branch="$(git_current_branch)" if [ "$current_branch" != "master" ]; then release_fail "this release step must run from branch master, but current branch is ${current_branch:-}." fi } # Promotion channels only republish commits that already shipped on the # previous lane, so the source commit must carry that lane's release tag. require_channel_tag_at_head() { local channel="$1" require_prerelease_channel "$channel" if ! git -C "$REPO_ROOT" tag --points-at HEAD | grep -q "^${channel}/v"; then release_fail "HEAD has no ${channel}/v* tag; this channel only publishes commits that already shipped a ${channel} release." fi } # The inverse guard: a commit ships on a promotion channel at most once, so # concurrent or repeated runs cannot double-publish it. Delete the lane tag # first if a republish is genuinely intended. require_channel_tag_absent_at_head() { local channel="$1" local existing require_prerelease_channel "$channel" existing="$(git -C "$REPO_ROOT" tag --points-at HEAD | grep "^${channel}/v" | head -1 || true)" if [ -n "$existing" ]; then release_fail "HEAD already shipped as ${existing}; delete that tag first if you really want to republish this commit on the ${channel} channel." fi } require_npm_publish_auth() { local dry_run="$1" if [ "$dry_run" = true ]; then return fi if npm whoami >/dev/null 2>&1; then release_info " ✓ Logged in to npm as $(npm whoami)" return fi if [ "${GITHUB_ACTIONS:-}" = "true" ]; then release_info " ✓ npm publish auth will be provided by GitHub Actions trusted publishing" return fi release_fail "npm publish auth is not available. Use 'npm login' locally or run from GitHub Actions with trusted publishing." } list_public_package_info() { node "$REPO_ROOT/scripts/release-package-map.mjs" list } set_public_package_version() { node "$REPO_ROOT/scripts/release-package-map.mjs" set-version "$1" }