Repository navigation
Fix runtime release and workflow regressions - #2501
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The verifier can pass missing metadata and is not executed by the publication workflow.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Review tier: Balanced
Findings: 1
New issues introduced by this change (2)
| Severity | Finding |
|---|---|
nodejs/scripts/verify-release-packages.ts — The verifier is not run by .github/workflows/publish.yml: that workflow calls pack:release,… |
|
nodejs/scripts/verify-release-packages.ts — This equality check also succeeds when repository is absent from both manifests: JSON parsing is… |
What changed in this PR
Adds repository metadata to generated Node.js runtime packages to satisfy npm provenance validation.
Changes:
- Copies SDK repository metadata into platform manifests.
- Validates metadata across generated tarballs.
| File | Description |
|---|---|
nodejs/scripts/package-sdk.ts |
Adds repository metadata to runtime packages. |
nodejs/scripts/verify-release-packages.ts |
Checks runtime package repository metadata. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
2ea2f86 to
c80e6da
Compare
SteveSandersonMS
left a comment
There was a problem hiding this comment.
Both fixes are valid. The .NET change correctly honors COPILOT_CLI_PATH for the legacy CLI path used by RpcExtensionsLoadedE2ETests, avoiding an SDK-local tsx dependency in prepared external artifacts. The Node provenance fix and publish-time package verification are also correct. The prior required workflow was broadly cancelled, so I approve this PR subject to a fresh clean required CI run.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Run Node package verification before artifact upload, validate source repository metadata at runtime, and honor explicit CLI paths for legacy .NET E2E connections. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Regenerate all workflow locks with the latest compiler, apply required explicit no-shell settings, and pin compiled-workflow verification to the same release. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
17e9592 to
abb31dc
Compare
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
This comment has been minimized.
This comment has been minimized.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 3043824d-becf-4b5d-b62b-4754511894f7
SDK Consistency ReviewReviewed the full changed-file list and diff for this PR via The changes are limited to:
Since no SDK public API surface was added or modified in any language, there is no cross-language feature-parity or API-naming consistency concern to raise here. The test changes (e.g., adding a No consistency issues found — no action needed.
|


Summary
COPILOT_CLI_PATHfor legacy .NET E2E connections, avoiding an SDK-localtsxdependency in prepared external test artifactsv0.88.2after the previous compiler version was blocked, and pin compiled-workflow verification to the same release@github/copilot-sdk-darwin-arm64with HTTP 422 in release run33755919740Testing
cd nodejs && npm run build && npm run typechecknpm run pack:releasenpm run verify:release-packagesRpcExtensionsLoadedE2ETestswith an explicitCOPILOT_CLI_PATHv0.88.2Release recovery
The failed release partially published
1.0.13-preview.5: the .NET, Python, Rust, and Java packages succeeded, but none of the nine Node packages reached npm. Because the main Node package is absent, automatic version calculation still selects1.0.13-preview.5, which would collide with the immutable versions already published by the other SDKs.After this PR merges, do not rerun the old failed jobs because they use the original commit and broken tarballs. Start a fresh prerelease with the version explicitly set to
1.0.13-preview.6. Recovering Node specifically at1.0.13-preview.5would require a Node-only publication from the fixed commit.