Skip to content

feat: publish the @containerbase/base package - #7579

Merged
viceice merged 2 commits into
mainfrom
feat/publish-base-package
Oct 1, 2026
Merged

viceice merged 2 commits into
mainfrom
feat/publish-base-package

Conversation

@viceice

@viceice viceice commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Changes

Publishes @containerbase/base (#7435) to npm with every containerbase release, the second step announced in #7435.

  • Adds @containerbase/semantic-release-pnpm, as used by containerbase/istanbul-reports. It writes the release version into the workspace package.json files and runs pnpm -r publish, which only publishes @containerbase/base, as the root package is private.
  • The plugin comes last in .releaserc.json, so the images are built, pushed and signed before the npm package is published. A failed image push leaves no npm version behind.
  • Publishing uses npm trusted publishing through the release job's existing id-token: write, no npm token secret.

Before the first release, the trusted publisher for @containerbase/base (repository containerbase/base, workflow build-push.yml) has to be set up on npmjs.com, which may need one manual first publish, as the package doesn't exist yet.

Context

  • This closes an existing Issue, Closes: #
  • This doesn't close an Issue, but I accept the risk that this PR may be closed if maintainers disagree with its opening or implementation

AI assistance disclosure

Did you use AI tools to create any part of this pull request?

  • No — I did not use AI for this contribution.
  • Yes — minimal assistance (e.g., IDE autocomplete, small code completions, grammar fixes).
  • Yes — substantive assistance (AI-generated non‑trivial portions of code, tests, or documentation).
  • Yes — other (please describe):

Written by Claude Opus 5.5 in Claude Code.

Use of AI in replying to PR comments

Who answers review comments:

  • @username will read and reply directly. Name the account.
  • An agent will draft replies and @viceice will read them before they are posted.
  • Nobody has explicitly committed to replying.

Documentation (please check one with an [x])

  • I have updated the documentation, or
  • No documentation update is required

How I've tested my work (please select one)

I have verified these changes via:

  • Code inspection only, or
  • Newly added/modified tests

A local pnpm -r publish --dry-run only lists @containerbase/base.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated release tooling and configuration for pnpm-based package releases. This change affects the project’s release process only; it does not add or alter user-facing features, product behavior, or the available functionality. There are no changes to the app’s interface or to how users interact with the product.

viceice and others added 2 commits October 1, 2026 16:05
Consumers like Renovate can read the package version and compare it with an image's containerbase version.

Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
semantic-release now writes the release version into the workspace packages and publishes @containerbase/base with pnpm, after the images are pushed. Publishing uses npm trusted publishing via the release job's id-token.

Co-Authored-By: Claude Opus 5.5 <michael.kriese+claude-code@mend.io>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Repository: containerbase/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: bfec382e-319a-48fe-a009-1105a63ca359

📥 Commits

Reviewing files that changed from the base of the PR and between 3077885 and 3077885.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • packages/base/README.md
  • packages/base/package.json
 _________________________________________________________________
< This is Sparta! And I'm here to kick bugs into the pit of doom. >
 -----------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: containerbase/coderabbit/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 30af380d-f277-40ca-a556-112a3c84808e

📥 Commits

Reviewing files that changed from the base of the PR and between 95828d3 and 3077885.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • .releaserc.json
  • package.json

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 7 remain after this review.


📝 Walkthrough

Walkthrough

The release configuration adds @containerbase/semantic-release-pnpm to the plugin list. The package is added to devDependencies at version 1.4.3.

Changes

PNPM semantic-release plugin

Layer / File(s) Summary
Configure the PNPM release plugin
.releaserc.json, package.json
The exec plugin entry is closed before @containerbase/semantic-release-pnpm is added to the release plugin list. The package is added to devDependencies at version 1.4.3.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 30778

The plugin is wired into release runs after image publishing, with compatible dependencies and OIDC permission. No code-level merge blocker was found; confirm npm trusted-publisher setup before the first package publish.

Architecture Summary

Architecture risk: 🔵 Low · up to 30778

The change affects 1 system.

Changed systems: package.json

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — package.json (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in package.json: Added @containerbase/semantic-release-pnpm at version 1.4.3 to devDependencies.
  • observed — Modified behavior in .releaserc.json: The exec plugin entry now closes before @containerbase/semantic-release-pnpm, which is added as another release plugin.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: publishing the @containerbase/base package to npm.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@viceice
viceice added this pull request to stack #7580 October 1, 2026 14:11
Base automatically changed from feat/base-package-json-export to main October 1, 2026 14:28
@viceice
viceice merged commit 034153a into main Oct 1, 2026
39 of 58 checks passed
@viceice
viceice deleted the feat/publish-base-package branch October 1, 2026 14:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant