Files
OpenHands/package.json
T
Rohit Malhotraandopenhands b5f01f366f feat: npm publish workflow with OIDC trusted publishing (#358)
* Add npm publish workflow and release infrastructure

- Add .github/workflows/npm-publish.yml for automated npm publishing on GitHub releases
- Update CI to verify library build (npm run build:lib) and package contents
- Add CHANGELOG.md for version history tracking
- Update README.md with npm installation and usage documentation

Closes #197

Co-authored-by: openhands <openhands@all-hands.dev>

* correct package version

* chore: update npm-publish workflow for trusted publishing

- Remove NODE_AUTH_TOKEN secret dependency
- Keep id-token: write permission for OIDC
- Add provenance flag for npm attestations
- Add comment explaining trusted publisher setup on npmjs.com

Co-authored-by: openhands <openhands@all-hands.dev>

* feat: add CLI entry point for npx execution

- Add bin/agent-canvas.mjs as executable CLI
- Add bin field to package.json for npm bin linking
- Include bin/ and build/ directories in published files
- CLI serves the built application with SPA routing support
- Supports --port, --host, and --help options

Co-authored-by: openhands <openhands@all-hands.dev>

* refactor: consolidate npm executable to use dev-docker infrastructure

- bin/agent-canvas.mjs now uses dev-with-automation.mjs main() with
  dev-docker.mjs's Docker-specific agent-server starter
- Added --static and --static-dir support to dev-with-automation.mjs
  so the npm executable serves pre-built static assets instead of Vite
- Added startStaticFrontend() function that uses static-server.mjs
- npm executable runs full stack: Docker agent-server + uvx automation
  backend + static frontend + ingress proxy

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: include scripts/ in npm package files

The bin/agent-canvas.mjs executable imports from scripts/dev-with-automation.mjs
and scripts/dev-docker.mjs, so the scripts directory must be included in the
published package.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address review comments

- Fix CHANGELOG.md version mismatch: 1.6.0 -> 1.0.0-alpha.1 to match package.json
- Add NODE_AUTH_TOKEN env var to npm-publish workflow for authentication
- Add CLI entry point mention to CHANGELOG

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use OIDC trusted publishing (no NPM_TOKEN needed)

npm trusted publishing with OIDC doesn't require NODE_AUTH_TOKEN.
Instead it uses short-lived OIDC tokens generated by GitHub Actions.

Requirements:
- id-token: write permission (already set)
- npm CLI 11.5.1+ (added npm install -g npm@latest step)
- Trusted publisher configured on npmjs.com

See: https://docs.npmjs.com/trusted-publishers/

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-alpha.2

Co-authored-by: openhands <openhands@all-hands.dev>

* Build app assets before npm publish

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: use Node 24 for npm trusted publishing

Trusted publishing requires Node 22.14.0+ and npm 11.5.1+.
Node 24 ships with npm 11.x which meets the requirement.
Node 22.12.0 (previous) ships with npm 10.x which doesn't support OIDC.

Also removed the manual npm upgrade step since Node 24 includes
a compatible npm version by default.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: align all workflows to Node 24 and regenerate lockfile

- Update ci.yml to use Node 24
- Update sdk-version-sync.yml to use Node 24
- Regenerate package-lock.json with npm 11.12.1

All workflows now use Node 24 which ships with npm 11.x,
required for OIDC trusted publishing (npm 11.5.1+).

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: remove incorrect LLM env vars from CLI help

LLM_MODEL and LLM_API_KEY were listed in the help text but aren't
actually used by the scripts. LLM settings are configured through
the web UI settings page instead.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: address PR review feedback

Critical fixes:
- Guard prepare script to only run in dev context (check for ../.git)
- Add missing existsSync import in dev-with-automation.mjs

Workflow improvements:
- Update checkout/setup-node actions to v6 for consistency
- Add npm version validation (must be 11.5.1+ for trusted publishing)
- Add package version validation (must match release tag)

CLI improvements:
- Add try-catch for dynamic imports with helpful error message
- Use console.error directly instead of imported logError/c

Documentation:
- Fix README export names: ChatInterface→ChatPanel, Terminal→TerminalPanel
- Add dist/ to .gitignore

Co-authored-by: openhands <openhands@all-hands.dev>

* ci: trigger npm publish on tag push instead of release

Simpler workflow - just push a tag like v1.0.0-alpha.2 to publish.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: remove tarball and add *.tgz to gitignore

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: npm publish errors

1. Fix bin path - remove './' prefix (npm pkg fix)
2. Add --tag for prerelease versions (alpha/beta/rc)

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add repository field for npm provenance verification

npm provenance requires repository.url to match the GitHub Actions
source. Also added description, homepage, and bugs fields.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: add .npmignore to include build/ directory in package

npm respects .gitignore when there's no .npmignore, which was
excluding the build/ directory from the published package.

The .npmignore explicitly lists what to exclude (src/, tests/,
dev configs) while allowing build/ and dist/ to be included.

Co-authored-by: openhands <openhands@all-hands.dev>

* fix: correct BUILD_DIR path in CLI entry point

The react-router build outputs to build/ directly (not build/client/)
because react-router.config.ts has unpackClientDirectory that moves
files from build/client/ to build/ and removes the client/ folder.

Co-authored-by: openhands <openhands@all-hands.dev>

* chore: bump version to 1.0.0-alpha.3

Co-authored-by: openhands <openhands@all-hands.dev>

---------

Co-authored-by: openhands <openhands@all-hands.dev>
2026-05-12 02:16:36 -04:00

223 lines
7.5 KiB
JSON

{
"name": "@openhands/agent-canvas",
"version": "1.0.0-alpha.3",
"description": "Agent Canvas UI for OpenHands - run AI coding agents with a visual interface",
"license": "MIT",
"private": false,
"type": "module",
"repository": {
"type": "git",
"url": "https://github.com/OpenHands/agent-canvas"
},
"homepage": "https://github.com/OpenHands/agent-canvas#readme",
"bugs": {
"url": "https://github.com/OpenHands/agent-canvas/issues"
},
"bin": {
"agent-canvas": "bin/agent-canvas.mjs"
},
"engines": {
"node": ">=22.12.0"
},
"dependencies": {
"@heroui/react": "2.8.10",
"@microlink/react-json-view": "1.31.20",
"@monaco-editor/react": "4.7.0",
"@openhands/typescript-client": "github:OpenHands/typescript-client#ef62e82fc3dfb03991a1c8025429caf354427263",
"@react-router/node": "7.14.2",
"@react-router/serve": "7.14.2",
"@tailwindcss/vite": "4.2.4",
"@tanstack/react-query": "5.100.9",
"@uidotdev/usehooks": "2.4.1",
"@xterm/addon-fit": "0.11.0",
"@xterm/xterm": "6.0.0",
"axios": "1.16.0",
"class-variance-authority": "0.7.1",
"clsx": "2.1.1",
"downshift": "9.3.2",
"framer-motion": "12.38.0",
"i18next": "26.0.8",
"i18next-browser-languagedetector": "8.2.1",
"i18next-http-backend": "4.0.0",
"isbot": "5.1.39",
"lucide-react": "1.14.0",
"monaco-editor": "0.55.1",
"posthog-js": "1.372.6",
"react": "19.2.5",
"react-dom": "19.2.5",
"react-hot-toast": "2.6.0",
"react-i18next": "17.0.6",
"react-icons": "5.6.0",
"react-markdown": "10.1.0",
"react-router": "7.14.2",
"react-syntax-highlighter": "16.1.1",
"rehype-raw": "7.0.0",
"rehype-sanitize": "6.0.0",
"remark-breaks": "4.0.0",
"remark-gfm": "4.0.1",
"sirv-cli": "3.0.1",
"socket.io-client": "4.8.3",
"tailwind-merge": "3.5.0",
"tailwind-scrollbar": "4.0.2",
"unist-util-visit": "5.1.0",
"uuid": "14.0.0",
"vite": "8.0.10",
"zustand": "5.0.12"
},
"scripts": {
"dev": "npm run dev:docker",
"dev:dangerously-dockerless": "npm run dev:automation",
"dev:safe": "node --env-file-if-exists=.env scripts/dev-safe.mjs",
"dev:extra-backend": "node --env-file-if-exists=.env scripts/dev-extra-backend.mjs",
"dev:automation": "node --env-file-if-exists=.env scripts/dev-with-automation.mjs",
"dev:docker": "node --env-file-if-exists=.env scripts/dev-docker.mjs",
"dev:static": "node --env-file-if-exists=.env scripts/dev-static.mjs",
"dev:minimal": "node --env-file-if-exists=.env scripts/dev-safe.mjs",
"dev:frontend": "npm run make-i18n && cross-env VITE_MOCK_API=false react-router dev",
"dev:mock": "npm run make-i18n && cross-env VITE_MOCK_API=true react-router dev",
"build": "npm run build:app",
"build:mock": "npm run make-i18n && cross-env VITE_MOCK_API=true react-router build",
"start": "npx sirv-cli build/ --single",
"test": "npm run make-i18n && vitest run",
"test:e2e": "playwright test",
"test:coverage": "npm run make-i18n && vitest run --coverage",
"dev_wsl": "VITE_WATCH_USE_POLLING=true vite",
"preview": "vite preview",
"make-i18n": "node scripts/make-i18n-translations.cjs",
"prelint": "npm run make-i18n",
"lint": "npm run typecheck && eslint src && prettier --check src/**/*.{ts,tsx}",
"lint:fix": "eslint src --fix && prettier --write src/**/*.{ts,tsx}",
"prepare": "[ -d '../.git' ] && cd .. && husky frontend/.husky || true",
"typecheck": "react-router typegen && tsc",
"typecheck:staged": "react-router typegen && npx tsc --noEmit --skipLibCheck",
"check-translation-completeness": "node scripts/check-translation-completeness.cjs",
"build:app": "npm run make-i18n && react-router build",
"build:lib": "npm run make-i18n && react-router typegen && cross-env BUILD_LIB=true vite build && tsc -p tsconfig.lib.json"
},
"lint-staged": {
"src/**/*.{ts,tsx,js}": [
"eslint --fix",
"prettier --write"
],
"src/**/*.{ts,tsx}": [
"bash -c 'npm run typecheck:staged'"
],
"src/**/*": [
"npm run check-translation-completeness"
]
},
"devDependencies": {
"@eslint/eslintrc": "3.3.1",
"@eslint/js": "9.39.4",
"@mswjs/socket.io-binding": "0.2.0",
"@playwright/test": "1.59.1",
"@react-router/dev": "7.14.2",
"@tailwindcss/typography": "0.5.19",
"@tanstack/eslint-plugin-query": "5.100.9",
"@testing-library/dom": "10.4.1",
"@testing-library/jest-dom": "6.9.1",
"@testing-library/react": "16.3.2",
"@testing-library/user-event": "14.6.1",
"@types/mdast": "4.0.4",
"@types/node": "25.6.0",
"@types/react": "19.2.14",
"@types/react-dom": "19.2.3",
"@types/react-syntax-highlighter": "15.5.13",
"@typescript-eslint/eslint-plugin": "8.59.2",
"@typescript-eslint/parser": "8.59.2",
"@vercel/react-router": "1.3.0",
"@vitest/coverage-v8": "4.1.5",
"cross-env": "10.1.0",
"eslint": "9.39.4",
"eslint-config-prettier": "10.1.8",
"eslint-import-resolver-typescript": "4.4.4",
"eslint-plugin-i18next": "6.1.4",
"eslint-plugin-import-x": "4.16.2",
"eslint-plugin-jsx-a11y": "6.10.2",
"eslint-plugin-prettier": "5.5.5",
"eslint-plugin-react": "7.37.5",
"eslint-plugin-react-hooks": "7.1.1",
"eslint-plugin-unused-imports": "4.4.1",
"globals": "16.5.0",
"husky": "9.1.7",
"jsdom": "29.1.1",
"lint-staged": "16.4.0",
"msw": "2.14.2",
"postcss-prefix-selector": "2.1.1",
"prettier": "3.8.3",
"tailwindcss": "4.2.4",
"typescript": "6.0.3",
"vite-plugin-svgr": "5.2.0",
"vitest": "4.1.5"
},
"packageManager": "npm@10.5.0",
"volta": {
"node": "22.12.0"
},
"msw": {
"workerDirectory": [
"public"
]
},
"overrides": {
"dompurify": "3.3.2"
},
"main": "./dist/index.cjs",
"module": "./dist/index.js",
"types": "./dist/index.d.ts",
"files": [
"dist",
"bin",
"build",
"scripts"
],
"exports": {
".": {
"types": "./dist/index.d.ts",
"import": "./dist/index.js",
"require": "./dist/index.cjs"
},
"./browser": {
"types": "./dist/components/browser/index.d.ts",
"import": "./dist/components/browser/index.js",
"require": "./dist/components/browser/index.cjs"
},
"./conversation": {
"types": "./dist/components/conversation/index.d.ts",
"import": "./dist/components/conversation/index.js",
"require": "./dist/components/conversation/index.cjs"
},
"./files": {
"types": "./dist/components/files/index.d.ts",
"import": "./dist/components/files/index.js",
"require": "./dist/components/files/index.cjs"
},
"./settings": {
"types": "./dist/components/settings/index.d.ts",
"import": "./dist/components/settings/index.js",
"require": "./dist/components/settings/index.cjs"
},
"./sidebar": {
"types": "./dist/components/sidebar/index.d.ts",
"import": "./dist/components/sidebar/index.js",
"require": "./dist/components/sidebar/index.cjs"
},
"./terminal": {
"types": "./dist/components/terminal/index.d.ts",
"import": "./dist/components/terminal/index.js",
"require": "./dist/components/terminal/index.cjs"
},
"./i18n": {
"types": "./dist/i18n/index.d.ts",
"import": "./dist/i18n/index.js",
"require": "./dist/i18n/index.cjs"
},
"./package.json": "./package.json"
},
"peerDependencies": {
"react": "19.2.5",
"react-dom": "19.2.5",
"react-router": "7.14.2"
}
}