Skip to content

Fix runtime release and workflow regressions - #2501

Merged
devm33 merged 8 commits into
mainfrom
devm33/fix-node-runtime-provenance
Sep 3, 2026
Merged

devm33 merged 8 commits into
mainfrom
devm33/fix-node-runtime-provenance

Conversation

@devm33

@devm33 devm33 commented Sep 3, 2026 •

Copy link
Copy Markdown
Member

Summary

  • copy the main SDK repository metadata into every generated Node platform runtime package
  • validate that repository metadata is present and matching across all nine Node tarballs
  • run release-package verification in the publication workflow before artifact upload
  • honor an explicit COPILOT_CLI_PATH for legacy .NET E2E connections, avoiding an SDK-local tsx dependency in prepared external test artifacts
  • upgrade agentic workflow locks to gh-aw v0.88.2 after the previous compiler version was blocked, and pin compiled-workflow verification to the same release
  • fix npm trusted publishing provenance validation, which rejected @github/copilot-sdk-darwin-arm64 with HTTP 422 in release run 33755919740

Testing

  • cd nodejs && npm run build && npm run typecheck
  • built all nine npm release tarballs with npm run pack:release
  • verified all nine tarballs with npm run verify:release-packages
  • ran all seven RpcExtensionsLoadedE2ETests with an explicit COPILOT_CLI_PATH
  • compiled and validated all 11 agentic workflows with gh-aw v0.88.2
  • confirmed agentic workflow recompilation is deterministic

Release recovery

The failed release partially published 1.0.13-preview.5: the .NET, Python, Rust, and Java packages succeeded, but none of the nine Node packages reached npm. Because the main Node package is absent, automatic version calculation still selects 1.0.13-preview.5, which would collide with the immutable versions already published by the other SDKs.

After this PR merges, do not rerun the old failed jobs because they use the original commit and broken tarballs. Start a fresh prerelease with the version explicitly set to 1.0.13-preview.6. Recovering Node specifically at 1.0.13-preview.5 would require a Node-only publication from the fixed commit.

@devm33
devm33 requested a review from a team as a code owner September 3, 2026 13:26
Copilot AI balanced review requested due to automatic review settings September 3, 2026 13:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The verifier can pass missing metadata and is not executed by the publication workflow.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Review tier: Balanced
Findings: 1 High severity · 1 Medium severity

New issues introduced by this change (2)
Severity Finding
High severity nodejs/​scripts/​verify-release-packages.ts — The verifier is not run by .github/workflows/publish.yml: that workflow calls pack:release,…
Medium severity nodejs/​scripts/​verify-release-packages.ts — This equality check also succeeds when repository is absent from both manifests: JSON parsing is…
What changed in this PR

Adds repository metadata to generated Node.js runtime packages to satisfy npm provenance validation.

Changes:

  • Copies SDK repository metadata into platform manifests.
  • Validates metadata across generated tarballs.
File Description
nodejs/​scripts/​package-sdk.ts Adds repository metadata to runtime packages.
nodejs/​scripts/​verify-release-packages.ts Checks runtime package repository metadata.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread nodejs/scripts/verify-release-packages.ts
Comment thread nodejs/scripts/verify-release-packages.ts
@devm33
devm33 enabled auto-merge September 3, 2026 13:30
@devm33 devm33 changed the title Fix Node runtime package provenance Fix runtime package release regressions Sep 3, 2026
@devm33 devm33 changed the title Fix runtime package release regressions Fix runtime release and workflow regressions Sep 3, 2026
@devm33
devm33 force-pushed the devm33/fix-node-runtime-provenance branch from 2ea2f86 to c80e6da Compare September 3, 2026 15:38
@devm33 devm33 changed the title Fix runtime release and workflow regressions Fix runtime release regressions Sep 3, 2026

@SteveSandersonMS SteveSandersonMS left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Both fixes are valid. The .NET change correctly honors COPILOT_CLI_PATH for the legacy CLI path used by RpcExtensionsLoadedE2ETests, avoiding an SDK-local tsx dependency in prepared external artifacts. The Node provenance fix and publish-time package verification are also correct. The prior required workflow was broadly cancelled, so I approve this PR subject to a fresh clean required CI run.

@devm33 devm33 changed the title Fix runtime release regressions Fix runtime release and workflow regressions Sep 3, 2026
@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026
@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026
@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026
@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Run Node package verification before artifact upload, validate source repository metadata at runtime, and honor explicit CLI paths for legacy .NET E2E connections.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Regenerate all workflow locks with the latest compiler, apply required explicit no-shell settings, and pin compiled-workflow verification to the same release.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
@devm33
devm33 removed this pull request from the merge queue due to a manual request Sep 3, 2026
@devm33
devm33 force-pushed the devm33/fix-node-runtime-provenance branch from 17e9592 to abb31dc Compare September 3, 2026 19:21
@devm33
devm33 enabled auto-merge September 3, 2026 19:32
@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 3, 2026
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Comment thread python/e2e/test_multi_client_e2e.py Fixed
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
@github-actions

This comment has been minimized.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

SDK Consistency Review

Reviewed the full changed-file list and diff for this PR via pull_request_read (get_files/get_diff). None of the changes touch actual SDK client source directories (nodejs/src/, python/copilot/, go/, dotnet/src/, java/sdk/src/main/java/, rust/src/).

The changes are limited to:

  • E2E/integration tests: dotnet/test/E2E/*, dotnet/test/Harness/E2ETestContext.cs, python/e2e/test_multi_client_e2e.py, rust/tests/e2e/rpc_shell_edge_cases.rs, test/harness/replayingCapiProxy.test.ts
  • CI/workflow tooling: .github/workflows/*, .github/aw/actions-lock.json, .github/skills/*
  • Build/release scripts: nodejs/scripts/package-sdk.ts, nodejs/scripts/verify-release-packages.ts
  • Misc: .gitattributes

Since no SDK public API surface was added or modified in any language, there is no cross-language feature-parity or API-naming consistency concern to raise here. The test changes (e.g., adding a session.idle wait in the Python multi-client permission test) look like test-robustness fixes rather than SDK behavior changes, and are scoped to their own language's test harness.

No consistency issues found — no action needed.

Generated by SDK Consistency Review Agent for #2501 · copilot · sonnet50 · 20.2 AIC · ⌖ 12 AIC · ⊞ 9.7K · ◷

@devm33
devm33 added this pull request to the merge queue Sep 3, 2026
Merged via the queue into main with commit 39c027b Sep 3, 2026
159 of 161 checks passed
@devm33
devm33 deleted the devm33/fix-node-runtime-provenance branch September 3, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants