From 6fd225caf62134eebc581c93b46388f22dd2d129 Mon Sep 17 00:00:00 2001 From: Evan Richards Date: Fri, 11 Sep 2026 18:06:07 -0700 Subject: [PATCH] [S] Publish the fork as @loop-payments/quickjs to GitHub Packages Loop must change the QuickJS sandbox runtime without a wait for an upstream release. This fork carries those changes. The backend package `@loop-payments/ts-sandbox` is the consumer. This change renames the package to `@loop-payments/quickjs` and sends it to GitHub Packages. The `repository` field points at this fork, because GitHub Packages uses that field to attach the package to a repository. The backend `.npmrc` already sends the `@loop-payments` scope to that registry, so the backend needs no new credentials. The workflow `publish.yml` runs on a published GitHub Release. It checks that the release tag agrees with the version in `package.json`, then it lints, typechecks, tests, builds, and publishes. It authenticates with the built-in `GITHUB_TOKEN`. Upstream publishes to npm and to JSR. This change removes `release.yml`, `jsr.json`, and `.np-config.json`, because Loop publishes to one registry only. It also removes `deploy-docs.yml`, because Loop does not host the upstream documentation website. `FORK.md` records the version policy, the release steps, and the steps to take upstream changes. --- .github/workflows/deploy-docs.yml | 62 ---------------- .github/workflows/publish.yml | 69 ++++++++++++++++++ .github/workflows/release.yml | 113 ------------------------------ .np-config.json | 4 -- FORK.md | 52 ++++++++++++++ jsr.json | 23 ------ package.json | 13 ++-- 7 files changed, 127 insertions(+), 209 deletions(-) delete mode 100644 .github/workflows/deploy-docs.yml create mode 100644 .github/workflows/publish.yml delete mode 100644 .github/workflows/release.yml delete mode 100644 .np-config.json create mode 100644 FORK.md delete mode 100644 jsr.json diff --git a/.github/workflows/deploy-docs.yml b/.github/workflows/deploy-docs.yml deleted file mode 100644 index ea0c789..0000000 --- a/.github/workflows/deploy-docs.yml +++ /dev/null @@ -1,62 +0,0 @@ -name: Update Website - -on: - push: - branches: - # make sure this is the branch you are using - - main - # Allows you to run this workflow manually from the Actions tab - workflow_dispatch: - -# Sets permissions of the GITHUB_TOKEN to allow deployment to GitHub Pages -permissions: - contents: read - pages: write - id-token: write - -# Allow only one concurrent deployment, skipping runs queued between the run in-progress and latest queued. -# However, do NOT cancel in-progress runs as we want to allow these production deployments to complete. -concurrency: - group: pages - cancel-in-progress: false - -jobs: - # Build job - deploydoc: - runs-on: ubuntu-latest - steps: - - name: Checkout - uses: actions/checkout@v4 - with: - fetch-depth: 0 # Not needed if lastUpdated is not enabled - - name: Bun - uses: oven-sh/setup-bun@v2 - with: - bun-version: latest - - name: Setup Pages - uses: actions/configure-pages@v4 - - name: Install dependencies - run: bun install - - name: Build the lib - run: | - bun run build - - name: Build documentation - run: | - bun run docs:build - - name: Upload artifact - uses: actions/upload-pages-artifact@v3 - with: - path: docs - - # Deployment job - deploy: - environment: - name: github-pages - url: ${{ steps.deployment.outputs.page_url }} - needs: deploydoc - runs-on: ubuntu-latest - name: Deploy - steps: - - name: Deploy to GitHub Pages - id: deployment - uses: actions/deploy-pages@v4 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..514294f --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,69 @@ +name: Publish to GitHub Packages + +on: + release: + types: [published] + +permissions: + contents: read + packages: write + +jobs: + publish: + runs-on: ubuntu-latest + + steps: + - name: Checkout + uses: actions/checkout@v5 + + - name: Setup Bun + uses: oven-sh/setup-bun@v2 + + - name: Setup Node.js + uses: actions/setup-node@v5 + with: + node-version: 24 + registry-url: 'https://npm.pkg.github.com' + scope: '@loop-payments' + + - name: Verify the release tag matches the package version + env: + TAG: ${{ github.event.release.tag_name }} + run: | + set -euo pipefail + VERSION="$(node -p "require('./package.json').version")" + if [ "${TAG}" != "v${VERSION}" ]; then + echo "The release tag ${TAG} does not match the package version ${VERSION}." + exit 1 + fi + + - name: Install dependencies + run: bun install --frozen-lockfile + + - name: Lint + run: bun run lint + + - name: Build the test utilities + run: bun run build:vendor + + - name: Typecheck + run: bunx tsc --noEmit + + - name: Test + run: | + set -euo pipefail + for f in $(find src -type f -name '*.test.ts' | sort); do + echo "Running $f" + if ! bun test "$f"; then + echo "Retrying $f once after failure..." + bun test "$f" + fi + done + + - name: Build + run: bun run build + + - name: Publish + run: npm publish --ignore-scripts + env: + NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml deleted file mode 100644 index 795c801..0000000 --- a/.github/workflows/release.yml +++ /dev/null @@ -1,113 +0,0 @@ -name: Release - -on: - workflow_dispatch: - -permissions: - contents: write - id-token: write - -jobs: - release: - runs-on: ubuntu-latest - - steps: - - name: Ensure release runs on main - if: github.ref_name != 'main' - run: | - echo "Release workflow must be triggered on the main branch." - exit 1 - - - name: Checkout - uses: actions/checkout@v4 - - - name: Setup Bun - uses: oven-sh/setup-bun@v2 - - - name: Setup Node.js - uses: actions/setup-node@v4 - with: - node-version: 22 - registry-url: "https://registry.npmjs.org" - - - name: Upgrade npm for trusted publishing - run: | - npm install --global npm@^11.5.1 - npm --version - - - name: Verify version sync and export version - id: version - run: | - node -e " - const fs = require('node:fs'); - const pkg = JSON.parse(fs.readFileSync('package.json', 'utf8')); - const jsr = JSON.parse(fs.readFileSync('jsr.json', 'utf8')); - if (pkg.name !== jsr.name) { - throw new Error('package.json and jsr.json names are not in sync'); - } - if (pkg.version !== jsr.version) { - throw new Error('package.json and jsr.json versions are not in sync'); - } - fs.appendFileSync(process.env.GITHUB_OUTPUT, 'value=' + pkg.version + '\n'); - console.log('Version verified:', pkg.version); - " - - - name: Install dependencies - run: bun install --frozen-lockfile - - - name: Ensure version is unpublished - env: - VERSION: ${{ steps.version.outputs.value }} - run: | - if npm view "@sebastianwessel/quickjs@${VERSION}" version >/dev/null 2>&1; then - echo "Version ${VERSION} is already published on npm." - exit 1 - fi - - - name: Lint - run: bun run lint - - - name: Build test utilities - run: bun run build:vendor - - - name: Typecheck - run: bunx tsc --noEmit - - - name: Run tests (serial by file) - run: | - set -euo pipefail - for f in $(find src -type f -name '*.test.ts' | sort); do - echo "Running $f" - if ! bun test "$f"; then - echo "Retrying $f once after failure..." - bun test "$f" - fi - done - - - name: Build - run: bun run build - - - name: Publish to npm (trusted publishing) - env: - NODE_AUTH_TOKEN: "" - run: npm publish --provenance --access public --ignore-scripts - - - name: Publish to JSR - run: npx jsr publish - - - name: Create GitHub Release - env: - GH_TOKEN: ${{ github.token }} - VERSION: ${{ steps.version.outputs.value }} - run: | - set -euo pipefail - TAG="v${VERSION}" - if gh release view "${TAG}" --repo "${GITHUB_REPOSITORY}" >/dev/null 2>&1; then - echo "Release ${TAG} already exists." - exit 1 - fi - gh release create "${TAG}" \ - --repo "${GITHUB_REPOSITORY}" \ - --target "${GITHUB_SHA}" \ - --title "${TAG}" \ - --generate-notes diff --git a/.np-config.json b/.np-config.json deleted file mode 100644 index abbcf65..0000000 --- a/.np-config.json +++ /dev/null @@ -1,4 +0,0 @@ -{ - "testScript": "test", - "contents": "." -} diff --git a/FORK.md b/FORK.md new file mode 100644 index 0000000..0a283e9 --- /dev/null +++ b/FORK.md @@ -0,0 +1,52 @@ +# The Loop fork of `@sebastianwessel/quickjs` + +This repository is a fork of +[sebastianwessel/quickjs](https://github.com/sebastianwessel/quickjs). Loop +carries changes to the sandbox runtime that upstream does not have. The +backend runs customer-supplied TypeScript in this sandbox, so Loop must be +able to change the runtime without a wait for an upstream release. + +The fork publishes as `@loop-payments/quickjs` to GitHub Packages. The backend +package `@loop-payments/ts-sandbox` is the consumer. + +## The version numbers + +The version number tracks the upstream release that the fork is based on. The +fork started at upstream 3.1.0, so the first Loop release is `3.1.0`. Loop +increments the patch number for each change that Loop makes. When the fork +takes a new upstream release, the version number moves to that upstream +version. + +## How to release a version + +1. Increment `version` in `package.json` and merge that change to `main`. +2. Create a GitHub Release with the tag `v`. +3. The `publish.yml` workflow lints, tests, builds, and publishes the package. + +The workflow authenticates with the built-in `GITHUB_TOKEN`. There is no +separate registry secret to rotate. + +## How to consume the package + +The backend `.npmrc` already sends the `@loop-payments` scope to +`https://npm.pkg.github.com`. Add the dependency and import it by name: + +```json +"@loop-payments/quickjs": "^3.1.0" +``` + +## How to take upstream changes + +```sh +git remote add upstream https://github.com/sebastianwessel/quickjs.git +git fetch upstream +git switch -c sync-upstream +git pull --no-rebase upstream main +``` + +The fork keeps the diff against upstream small, so most merges are clean. The +files that the fork changes are `package.json` (the package name, the +repository, and the publish configuration) and `.github/workflows`. Upstream +publishes to npm and to JSR; the fork removed `release.yml`, `jsr.json`, and +`.np-config.json`, so a modify/delete conflict on those files is expected. +Delete them again and continue. diff --git a/jsr.json b/jsr.json deleted file mode 100644 index 1aa6efc..0000000 --- a/jsr.json +++ /dev/null @@ -1,23 +0,0 @@ -{ - "$schema": "https://jsr.io/schema/config-file.v1.json", - "name": "@sebastianwessel/quickjs", - "version": "3.1.0", - "description": "A TypeScript package to execute JavaScript and TypeScript code in a WebAssembly QuickJS sandbox", - "keywords": ["quickjs", "sandbox", "typescript", "javascript", "webassembly"], - "exports": "./dist/esm/index.js", - "publish": { - "include": ["dist/**/*.js", "dist/**/*.d.ts", "README.md", "package.json"], - "exclude": [ - "src", - ".github", - ".vscode", - ".zed", - "!dist", - "!dist/**/*.js", - "!dist/**/*.d.ts", - ".tshy", - "vendor", - "docs" - ] - } -} diff --git a/package.json b/package.json index 1237a85..bedfc5b 100644 --- a/package.json +++ b/package.json @@ -1,12 +1,13 @@ { - "name": "@sebastianwessel/quickjs", + "name": "@loop-payments/quickjs", "version": "3.1.0", "description": "A typescript package to execute JavaScript and TypeScript code in a WebAssembly QuickJS sandbox", "engines": { "node": ">=18.0.0" }, "publishConfig": { - "access": "public" + "registry": "https://npm.pkg.github.com", + "access": "restricted" }, "keywords": [ "typescript", @@ -53,7 +54,6 @@ "test:dev": "bun test --watch", "lint": "bunx @biomejs/biome check", "lint:fix": "bunx @biomejs/biome check --write", - "postpublish": "npx jsr publish", "example:ai": "bun example/ai/index.ts", "example:async": "bun example/async/index.ts", "example:basic": "bun example/basic/index.ts", @@ -65,7 +65,6 @@ "example:module": "bun example/custom-module/index.ts", "example:user": "bun example/user-code/index.ts", "knip": "knip", - "release": "bun run build && bun run lint:fix && np", "docs:dev": "vitepress dev website", "docs:build": "git-cliff > CHANGELOG.md && typedoc --options typedoc.json && vitepress build website", "docs:preview": "vitepress preview website" @@ -74,13 +73,13 @@ "name": "Sebastian Wessel", "url": "https://sebastianwessel.de" }, - "homepage": "https://github.com/sebastianwessel/quickjs#readme", + "homepage": "https://github.com/loop-payments/quickjs#readme", "bugs": { - "url": "https://github.com/sebastianwessel/quickjs/issues" + "url": "https://github.com/loop-payments/quickjs/issues" }, "repository": { "type": "git", - "url": "git+https://github.com/sebastianwessel/quickjs.git" + "url": "git+https://github.com/loop-payments/quickjs.git" }, "license": "MIT", "devDependencies": {