Skip to content

Publish to npm from a GitHub release - #24

Merged
jbn2336mz merged 1 commit into
mainfrom
publish-from-github
Sep 17, 2026
Merged

jbn2336mz merged 1 commit into
mainfrom
publish-from-github

Conversation

@jbn2336mz

Copy link
Copy Markdown
Member

npm publish from Actions has been off since #14 packed the docs into the tarball. The build needs the product docs bundle, and that lives only in s3://mz-prod-docs-assets/export/mcp.json. Nothing serves it, and the CloudFront distribution in front of that bucket caches for a day, so the release reads the key from S3 like every other consumer does.

It assumes github-mcp-release, a new role in infra (mockzilla/infra PR below) that can GetObject that one key and nothing else. Adding this repo to the existing github-ci role would also have worked, but that role deploys lambdas, pushes images and assumes the sim deploy roles.

npm auth is Trusted Publishing over OIDC, so there is no token to store and the tarball gets provenance.

Also bumps to 0.2.25, which is what this release ships.

Before merging

Two one-time setup steps, both written up in the README:

  1. Apply the infra PR, then set the repo secret AWS_ROLE_ARN to the github_mcp_release_role_arn output.
  2. On npmjs.com, add a trusted publisher to @mockzilla/mcp: repository mockzilla/mockzilla-mcp, workflow publish.yml.

Notes

  • make publish-all by hand still works and stays the documented fallback.
  • The workflow skips a version npm already has, so a hand publish followed by a release is not a conflict.
  • The CLI-backed smokes skip on a runner with no mockzilla installed. The stdio, login, docs and github smokes all run.
  • publish-mcp.yml is untouched. It still runs by hand, and it already waits for the version to land on npm.

npm publish from Actions has been off since the docs got packed into the
tarball: the build needs the product docs bundle, and that lives only in
s3://mz-prod-docs-assets/export/mcp.json. Nothing serves it, and the CDN
in front of that bucket caches for a day, so the release now reads the
key from S3 like every other consumer.

It assumes github-mcp-release, a new role in infra's iam-github-oidc that
can GetObject that one key and nothing else. The existing github-ci role
would also have worked, but it deploys lambdas, pushes images and assumes
the sim deploy roles.

npm auth is Trusted Publishing over OIDC, so there is no token to store
and the tarball gets provenance. Two one-time setup steps, both in the
README: the trusted publisher on npmjs.com, and the AWS_ROLE_ARN secret.

Releasing by hand with make publish-all still works, and the workflow
skips a version npm already has.
@jbn2336mz
jbn2336mz merged commit 3fff57f into main Sep 17, 2026
3 checks passed
@jbn2336mz
jbn2336mz deleted the publish-from-github branch September 17, 2026 15:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant