From 96defff9a552f7da591076d1999323dddbc9e5aa Mon Sep 17 00:00:00 2001 From: can1357 Date: Wed, 10 Jun 2026 08:22:19 +0200 Subject: [PATCH] ci(workflows): provisioned native addons for the npm publish job The pi-coding-agent prepack (bundle-dist.ts) imports the pi-utils barrel, which eagerly loads the pi-natives addon; release_npm never downloaded the linux x64 .node artifacts, so the publish died in prepack. Mirror the test job's download-artifact step (release runs always rebuild natives in the same run, so the default run-id resolves). --- .github/workflows/ci.yml | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b3e83857c..f667766f8 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -525,7 +525,7 @@ jobs: needs.release_binary.result == 'success' && needs.release_github_verify.result == 'success' && !inputs.skip_npm }} - needs: [release_metadata, release_binary, release_github_verify] + needs: [release_metadata, release_binary, release_github_verify, native_artifact_lookup] runs-on: ubuntu-22.04 # `id-token: write` lets npm mint the GitHub OIDC token it exchanges for a # short-lived publish token (trusted publishing + provenance). When a @@ -552,6 +552,17 @@ jobs: path: ~/.bun/install/cache key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }} - run: bun install --frozen-lockfile + # The pi-coding-agent prepack executes workspace code (bundle-dist + # imports the pi-utils barrel, which loads the pi-natives addon), so + # this job needs the linux x64 native addons just like `test` does. + # Release runs always rebuild natives in this same run, so the + # default run-id resolves the artifacts. + - name: Download native addons + uses: actions/download-artifact@v4 + with: + pattern: pi-natives-linux-x64-*-h${{ needs.native_artifact_lookup.outputs.source-hash }} + path: packages/natives/native + merge-multiple: true - name: Publish to npm env: # Fallback auth: setup-node wrote an .npmrc referencing