feat: publish the @containerbase/base package - #7579
Conversation
Consumers like Renovate can read the package version and compare it with an image's containerbase version. Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
semantic-release now writes the release version into the workspace packages and publishes @containerbase/base with pnpm, after the images are pushed. Publishing uses npm trusted publishing via the release job's id-token. Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Repository: containerbase/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: containerbase/coderabbit/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe release configuration adds ChangesPNPM semantic-release plugin
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~5 minutes Change: Feature Merge Risk: ⚪ Minimal · up to The plugin is wired into release runs after image publishing, with compatible dependencies and OIDC permission. No code-level merge blocker was found; confirm npm trusted-publisher setup before the first package publish. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Changes
Publishes
@containerbase/base(#7435) to npm with every containerbase release, the second step announced in #7435.@containerbase/semantic-release-pnpm, as used bycontainerbase/istanbul-reports. It writes the release version into the workspacepackage.jsonfiles and runspnpm -r publish, which only publishes@containerbase/base, as the root package is private..releaserc.json, so the images are built, pushed and signed before the npm package is published. A failed image push leaves no npm version behind.id-token: write, no npm token secret.Before the first release, the trusted publisher for
@containerbase/base(repositorycontainerbase/base, workflowbuild-push.yml) has to be set up on npmjs.com, which may need one manual first publish, as the package doesn't exist yet.Context
AI assistance disclosure
Did you use AI tools to create any part of this pull request?
Written by Claude Opus 5.5 in Claude Code.
Use of AI in replying to PR comments
Who answers review comments:
Documentation (please check one with an [x])
How I've tested my work (please select one)
I have verified these changes via:
A local
pnpm -r publish --dry-runonly lists@containerbase/base.🤖 Generated with Claude Code
Summary by CodeRabbit