Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,9 @@ jobs:
install -d -m 700 ~/.moon
umask 077
printf '%s' "$MOON_CREDENTIALS" > ~/.moon/credentials.json
moon publish --frozen
# `moon publish` validates the archive from a fresh extracted module;
# that validation must be allowed to install its declared dependencies.
moon publish

- name: Verify exact published version from a fresh downstream module
run: |
Expand Down
5 changes: 4 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -357,7 +357,10 @@ build, and the package allowlist before uploading the archive and

The same workflow publishes to mooncakes.io using the repository or inherited
organization Secret `MOON_CREDENTIALS`; registry credentials never leave the
ephemeral Actions runner. It then resolves `tiye/react@X.Y.Z` from a fresh
ephemeral Actions runner. The publish command intentionally is not frozen:
MoonBit validates the archive from a fresh extracted module that must install
its declared dependencies. All source/package inputs are frozen and checked by
the preceding release gates. The workflow then resolves `tiye/react@X.Y.Z` from a fresh
temporary consumer, compiles a generated-DOM smoke use, runs JS check/build,
and preserves the exact logs as an Actions artifact. A release is not complete
until this downstream check passes.
Expand Down
Loading