Files
huly-platform/.github/workflows/publish-npm.yml
T
Igor LoskutovandGitHub cc9c8b870b fix(ci): emit TypeScript declarations before npm publish (#10768)
Published tarballs of several @hcengineering/* packages (0.7.411+)
are missing their .d.ts files, despite every package.json declaring
"types": "types/index.d.ts" and listing "types/**/*" in "files".

  Repro: npm pack @hcengineering/core@0.7.413 --dry-run --json
         (no `types/` entries in the file list)

Root cause
----------
`publish-npm.yml` runs `rush build`, which is defined in
`common/config/rush/command-line.json` as a phased command with
`"phases": ["_phase:build"]`. `_phase:build` resolves to
`compile transpile src` (an esbuild-only transpile → `lib/`). The
`.d.ts` emit lives in a separate phase, `_phase:validate`
(`compile validate` → `tsc --emitDeclarationOnly` →
`declarationDir: ./types`), which the publish workflow never runs.
Because `types/` does not exist when safe-publish.js invokes
`npm publish`, the `types/**/*` glob in each package's `files` field
matches nothing and the tarball ships without declarations.

Why this didn't regress earlier
-------------------------------
These packages used to live in the now-dormant `hcengineering/huly.core`
repo. That repo's `ci.yml` explicitly ran `rush validate` before
`rush publish`, so `types/` was always present at publish time.

After migration into this monorepo, the publish pipeline was rewritten
(PR #10542, then extracted to `publish-npm.yml` in PR #10580) and the
validate step was not carried over. Versions 0.7.18–0.7.382 still
shipped declarations because:

  - 0.7.18–0.7.26 were published from `huly.core` (validate present).
  - 0.7.382 was published manually from a developer machine
    (`_nodeVersion: 22.13.0, _npmVersion: 11.0.0` in npm metadata —
     doesn't match the CI runner). `types/` happened to be left on
     disk from prior local development.
  - 0.7.411+ are the first versions published via `publish-npm.yml`
    on a fresh runner (`_nodeVersion: 22.22.2, _npmVersion: 10.9.7`,
     consistent with actions/setup-node@v6 resolving `.nvmrc: v22`).
    Fresh workspace, no validate step, no `types/`.

Fix
---
Add a `rush validate` step between build and publish in
`publish-npm.yml`. Scoped to the publish workflow so regular CI build
times are unaffected. An alternative would be to add `_phase:validate`
to the `build` phased command in `command-line.json` (matching
`build:watch`, which already does `["_phase:build", "_phase:validate"]`),
but that would make any validate failure block all builds, not just
publishes — strictly worse blast radius for this particular bug.

Affected packages observed on npm (0.7.411+):
  @hcengineering/core
  @hcengineering/account-client
  @hcengineering/api-client
  @hcengineering/text
  @hcengineering/text-core
  @hcengineering/text-html

Fixes #10767
2026-04-15 12:47:45 +07:00

55 lines
1.7 KiB
YAML

name: Publish npm
on:
workflow_dispatch:
inputs:
ref:
description: 'Ref to publish (e.g. refs/tags/v0.7.382 or a branch)'
required: true
default: 'refs/heads/develop'
jobs:
publish-npm:
permissions:
contents: read
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v6
with:
ref: ${{ github.event.inputs.ref }}
fetch-depth: 0
- uses: actions/setup-node@v6
with:
node-version-file: '.nvmrc'
- name: Cache node modules
uses: actions/cache@v5
env:
cache-name: cache-node-platform
with:
path: common/temp
key: ${{ runner.os }}-build-cache-node-platform-${{ hashFiles('**/pnpm-lock.yaml') }}
restore-keys: ${{ runner.os }}-build-cache-node-platform-
- name: Installing...
run: node common/scripts/install-run-rush.js install
- name: Building...
run: node common/scripts/install-run-rush.js build
- name: Emit TypeScript declarations
run: node common/scripts/install-run-rush.js validate
- name: Publish to npm
env:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
if [ -z "$NPM_TOKEN" ]; then
echo "::error::NPM_TOKEN secret is not set. Add it in repository Settings > Secrets and variables > Actions."
exit 1
fi
echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > .npmrc
REF="${{ github.event.inputs.ref }}"
VERSION="${REF#refs/tags/v}"
VERSION="${VERSION#v}"
if [[ "$REF" == refs/tags/v* ]]; then
node common/scripts/bump.js --check "$VERSION"
fi
node common/scripts/safe-publish.js