openclaw/scripts/release-verify-publish.ts
Peter Steinberger ee98dce3bc
fix(release): defer plugin npm visibility to parent verification (#152438)
* fix(release): preserve plugin publish success during registry lag

Record published, visibility pending only after accepted plugin npm publication in a full parent release. The parent retains final registry authority; standalone repairs and identity, byte, malformed-selector, and ahead-selector conflicts remain strict. Reuse selector classification and remove the duplicate bootstrap selector readback. Related: #152176.

* fix(release): bind final plugin readback to publication evidence

Verify consumed qualification and planning receipts at the parent, including retained attempts. Require actual registry tarball integrity and archive identity on fresh-parent resumes that skip already-published versions; retain exact artifact byte checks for publisher jobs.

* fix(release): preserve qualified readback across failed child retries

Reconcile retained failed publishers with a verified newer skip plan and require their exact successful qualification-upload step. Keep original artifact byte verification. Register the dynamic verifier entrypoint and its isolated test inventory for CI.
2026-09-19 02:32:05 -07:00

36 lines
1.3 KiB
JavaScript

#!/usr/bin/env -S node --import tsx
import { mkdtempSync, rmSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { parseReleaseVerifyBetaArgs, verifyBetaRelease } from "./lib/release-beta-verifier.ts";
import { createPluginNpmPublicationReadback } from "./plugin-npm-publication-readback.mjs";
async function main() {
const args = parseReleaseVerifyBetaArgs(process.argv.slice(2));
const cacheDir = mkdtempSync(join(tmpdir(), "openclaw-plugin-npm-readback-"));
try {
const pluginNpmReadback = await createPluginNpmPublicationReadback({
repository: args.repo,
runId: Number(args.workflowRuns.pluginNpm),
sourceSha: args.releaseSha,
workflowSha: process.env.GITHUB_WORKFLOW_SHA,
workflowRef: args.workflowRef,
sourceRoot: process.cwd(),
plugins: args.pluginSelection,
token: process.env.GH_TOKEN,
cacheDir,
});
for (const line of await verifyBetaRelease(args, { pluginNpmReadback })) {
console.log(line);
}
} finally {
rmSync(cacheDir, { recursive: true, force: true });
}
}
main().catch((error: unknown) => {
console.error(error instanceof Error ? error.message : String(error));
console.error("[release-verify-publish] FAILED (exit 1)");
process.exitCode = 1;
});