Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 0 additions & 62 deletions .github/workflows/deploy-docs.yml

This file was deleted.

69 changes: 69 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
name: Publish to GitHub Packages

on:
release:
types: [published]

permissions:
contents: read
packages: write

jobs:
publish:
runs-on: ubuntu-latest

steps:
- name: Checkout
uses: actions/checkout@v5

- name: Setup Bun
uses: oven-sh/setup-bun@v2

- name: Setup Node.js
uses: actions/setup-node@v5
with:
node-version: 24
registry-url: 'https://npm.pkg.github.com'
scope: '@loop-payments'

- name: Verify the release tag matches the package version
env:
TAG: ${{ github.event.release.tag_name }}
run: |
set -euo pipefail
VERSION="$(node -p "require('./package.json').version")"
if [ "${TAG}" != "v${VERSION}" ]; then
echo "The release tag ${TAG} does not match the package version ${VERSION}."
exit 1
fi

- name: Install dependencies
run: bun install --frozen-lockfile

- name: Lint
run: bun run lint

- name: Build the test utilities
run: bun run build:vendor

- name: Typecheck
run: bunx tsc --noEmit

- name: Test
run: |
set -euo pipefail
for f in $(find src -type f -name '*.test.ts' | sort); do
echo "Running $f"
if ! bun test "$f"; then
echo "Retrying $f once after failure..."
bun test "$f"
fi
done

- name: Build
run: bun run build

- name: Publish
run: npm publish --ignore-scripts
env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
113 changes: 0 additions & 113 deletions .github/workflows/release.yml

This file was deleted.

4 changes: 0 additions & 4 deletions .np-config.json

This file was deleted.

52 changes: 52 additions & 0 deletions FORK.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# The Loop fork of `@sebastianwessel/quickjs`

This repository is a fork of
[sebastianwessel/quickjs](https://github.com/sebastianwessel/quickjs). Loop
carries changes to the sandbox runtime that upstream does not have. The
backend runs customer-supplied TypeScript in this sandbox, so Loop must be
able to change the runtime without a wait for an upstream release.

The fork publishes as `@loop-payments/quickjs` to GitHub Packages. The backend
package `@loop-payments/ts-sandbox` is the consumer.

## The version numbers

The version number tracks the upstream release that the fork is based on. The
fork started at upstream 3.1.0, so the first Loop release is `3.1.0`. Loop
increments the patch number for each change that Loop makes. When the fork
takes a new upstream release, the version number moves to that upstream
version.

## How to release a version

1. Increment `version` in `package.json` and merge that change to `main`.
2. Create a GitHub Release with the tag `v<version>`.
3. The `publish.yml` workflow lints, tests, builds, and publishes the package.

The workflow authenticates with the built-in `GITHUB_TOKEN`. There is no
separate registry secret to rotate.

## How to consume the package

The backend `.npmrc` already sends the `@loop-payments` scope to
`https://npm.pkg.github.com`. Add the dependency and import it by name:

```json
"@loop-payments/quickjs": "^3.1.0"
```

## How to take upstream changes

```sh
git remote add upstream https://github.com/sebastianwessel/quickjs.git
git fetch upstream
git switch -c sync-upstream
git pull --no-rebase upstream main
```

The fork keeps the diff against upstream small, so most merges are clean. The
files that the fork changes are `package.json` (the package name, the
repository, and the publish configuration) and `.github/workflows`. Upstream
publishes to npm and to JSR; the fork removed `release.yml`, `jsr.json`, and
`.np-config.json`, so a modify/delete conflict on those files is expected.
Delete them again and continue.
23 changes: 0 additions & 23 deletions jsr.json

This file was deleted.

13 changes: 6 additions & 7 deletions package.json
Original file line number Diff line number Diff line change
@@ -1,12 +1,13 @@
{
"name": "@sebastianwessel/quickjs",
"name": "@loop-payments/quickjs",
"version": "3.1.0",
"description": "A typescript package to execute JavaScript and TypeScript code in a WebAssembly QuickJS sandbox",
"engines": {
"node": ">=18.0.0"
},
"publishConfig": {
"access": "public"
"registry": "https://npm.pkg.github.com",
"access": "restricted"
},
"keywords": [
"typescript",
Expand Down Expand Up @@ -53,7 +54,6 @@
"test:dev": "bun test --watch",
"lint": "bunx @biomejs/biome check",
"lint:fix": "bunx @biomejs/biome check --write",
"postpublish": "npx jsr publish",
"example:ai": "bun example/ai/index.ts",
"example:async": "bun example/async/index.ts",
"example:basic": "bun example/basic/index.ts",
Expand All @@ -65,7 +65,6 @@
"example:module": "bun example/custom-module/index.ts",
"example:user": "bun example/user-code/index.ts",
"knip": "knip",
"release": "bun run build && bun run lint:fix && np",
"docs:dev": "vitepress dev website",
"docs:build": "git-cliff > CHANGELOG.md && typedoc --options typedoc.json && vitepress build website",
"docs:preview": "vitepress preview website"
Expand All @@ -74,13 +73,13 @@
"name": "Sebastian Wessel",
"url": "https://sebastianwessel.de"
},
"homepage": "https://github.com/sebastianwessel/quickjs#readme",
"homepage": "https://github.com/loop-payments/quickjs#readme",
"bugs": {
"url": "https://github.com/sebastianwessel/quickjs/issues"
"url": "https://github.com/loop-payments/quickjs/issues"
},
"repository": {
"type": "git",
"url": "git+https://github.com/sebastianwessel/quickjs.git"
"url": "git+https://github.com/loop-payments/quickjs.git"
},
"license": "MIT",
"devDependencies": {
Expand Down
Loading