ci(workflows): provisioned native addons for the npm publish job

The pi-coding-agent prepack (bundle-dist.ts) imports the pi-utils barrel,
which eagerly loads the pi-natives addon; release_npm never downloaded the
linux x64 .node artifacts, so the publish died in prepack. Mirror the
test job's download-artifact step (release runs always rebuild natives in
the same run, so the default run-id resolves).
This commit is contained in:
can1357
2026-06-10 08:22:19 +02:00
parent 4824c58132
commit 96defff9a5
+12 -1
View File
@@ -525,7 +525,7 @@ jobs:
needs.release_binary.result == 'success' &&
needs.release_github_verify.result == 'success' &&
!inputs.skip_npm }}
needs: [release_metadata, release_binary, release_github_verify]
needs: [release_metadata, release_binary, release_github_verify, native_artifact_lookup]
runs-on: ubuntu-22.04
# `id-token: write` lets npm mint the GitHub OIDC token it exchanges for a
# short-lived publish token (trusted publishing + provenance). When a
@@ -552,6 +552,17 @@ jobs:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- run: bun install --frozen-lockfile
# The pi-coding-agent prepack executes workspace code (bundle-dist
# imports the pi-utils barrel, which loads the pi-natives addon), so
# this job needs the linux x64 native addons just like `test` does.
# Release runs always rebuild natives in this same run, so the
# default run-id resolves the artifacts.
- name: Download native addons
uses: actions/download-artifact@v4
with:
pattern: pi-natives-linux-x64-*-h${{ needs.native_artifact_lookup.outputs.source-hash }}
path: packages/natives/native
merge-multiple: true
- name: Publish to npm
env:
# Fallback auth: setup-node wrote an .npmrc referencing