From 92240a0919ddb32649b37a5cde9cb0b4e09bc2c5 Mon Sep 17 00:00:00 2001 From: Swatantra Yadav Date: Sat, 26 Sep 2026 16:14:42 +0530 Subject: [PATCH] ci(ts): add automated npm release workflow with provenance (#288) --- .github/workflows/release-ts.yml | 136 +++++++++++++++++++++++++++++++ README.md | 7 +- laya-ts/package.json | 21 +++++ 3 files changed, 163 insertions(+), 1 deletion(-) create mode 100644 .github/workflows/release-ts.yml diff --git a/.github/workflows/release-ts.yml b/.github/workflows/release-ts.yml new file mode 100644 index 0000000..08b4a6d --- /dev/null +++ b/.github/workflows/release-ts.yml @@ -0,0 +1,136 @@ +name: Release TypeScript (laya-ts) + +# Tag a commit laya-ts-v0.1.0 and push it; this runs tests, verifies the version +# matches the tag, packs the artifact, publishes to npm with provenance, and +# attaches the tarball to a GitHub Release. +# +# Set up once on npm: +# Add NPM_TOKEN in GitHub repository secrets (or configure npm Provenance / OIDC Trusted Publisher). + +on: + push: + tags: ["laya-ts-v*"] + workflow_dispatch: + +permissions: + contents: read + +jobs: + build: + name: Build & verify package + runs-on: ubuntu-latest + timeout-minutes: 15 + defaults: + run: + working-directory: laya-ts + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 + with: + node-version: "22" + cache: npm + cache-dependency-path: laya-ts/package-lock.json + + - run: npm ci + + - name: Unit tests + run: npm test -- --run + + - name: Packed package end-to-end test + run: npm run test:package + + - name: Version matches tag + if: startsWith(github.ref, 'refs/tags/laya-ts-v') + run: | + pkg=$(node -p "require('./package.json').version") + tag="${GITHUB_REF_NAME#laya-ts-v}" + echo "package.json=$pkg tag=$tag" + test "$pkg" = "$tag" || { echo "::error::package.json version $pkg does not match tag $tag"; exit 1; } + + - name: Pack release tarball + run: npm pack --pack-destination dist/ + + - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + with: + name: laya-ts-dist + path: laya-ts/dist/*.tgz + + npm: + name: Publish to npm + needs: build + if: startsWith(github.ref, 'refs/tags/laya-ts-v') + runs-on: ubuntu-latest + timeout-minutes: 10 + environment: npm + permissions: + id-token: write + contents: read + steps: + - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0 + with: + node-version: "22" + registry-url: "https://registry.npmjs.org" + + - name: Upgrade npm for OIDC Trusted Publishing support + run: npm install -g npm@latest + + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 + with: + name: laya-ts-dist + path: dist + + - name: Publish to npm with provenance + env: + NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} + run: | + tarball=$(ls dist/laya-ts-*.tgz) + tag="${GITHUB_REF_NAME#laya-ts-v}" + if [[ "$tag" == *-* ]]; then + DIST_TAG="next" + echo "Prerelease detected ($tag). Publishing under dist-tag: $DIST_TAG" + else + DIST_TAG="latest" + echo "Stable release detected ($tag). Publishing under dist-tag: $DIST_TAG" + fi + npm publish "$tarball" --access public --provenance --tag "$DIST_TAG" + + github_release: + name: Attach to GitHub Release + needs: [build, npm] + if: startsWith(github.ref, 'refs/tags/laya-ts-v') + runs-on: ubuntu-latest + timeout-minutes: 10 + permissions: + contents: write + steps: + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0 + with: + fetch-depth: 0 + + - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0 + with: + name: laya-ts-dist + path: dist + + - name: Publish or update GitHub release + env: + GH_TOKEN: ${{ github.token }} + run: | + tag="${GITHUB_REF_NAME#laya-ts-v}" + PRERELEASE_FLAG="" + if [[ "$tag" == *-* ]]; then + PRERELEASE_FLAG="--prerelease" + fi + + if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then + echo "release $GITHUB_REF_NAME already exists - syncing prerelease status and uploading tarball" + if [[ "$tag" == *-* ]]; then + gh release edit "$GITHUB_REF_NAME" --prerelease + else + gh release edit "$GITHUB_REF_NAME" --prerelease=false + fi + gh release upload "$GITHUB_REF_NAME" dist/*.tgz --clobber + else + echo "creating release $GITHUB_REF_NAME" + gh release create "$GITHUB_REF_NAME" dist/*.tgz --title "$GITHUB_REF_NAME" --generate-notes $PRERELEASE_FLAG + fi diff --git a/README.md b/README.md index 54c20cf..e1ed89a 100644 --- a/README.md +++ b/README.md @@ -27,7 +27,12 @@ python -m pip install laya ``` -Python 3.10 or newer. Optional extras: `laya[serve]` (HTTP server), `laya[mcp]` (MCP server), `laya[langchain]` (LangChain and LangGraph), `laya[onnx]` (ONNX Runtime), `laya[fast]` (TileLang GPU fast path). Step-by-step setup for each platform, CPU-only or GPU PyTorch builds, and troubleshooting are in [Installation details](#installation-details). +For TypeScript / Node.js / browser: +```bash +npm install laya-ts +``` + +Python 3.10 or newer. Optional extras: `laya[serve]` (HTTP server), `laya[mcp]` (MCP server), `laya[langchain]` (LangChain and LangGraph), `laya[onnx]` (ONNX Runtime), `laya[fast]` (TileLang GPU fast path). See [`laya-ts/`](laya-ts/) for the TypeScript runtime guide. Step-by-step setup for each platform, CPU-only or GPU PyTorch builds, and troubleshooting are in [Installation details](#installation-details). **Long documents.** `laya-multilingual` reads up to 8,192 tokens with `max_len=8192`. Measured accuracy and time by document length, reproducible with [`research/scripts/bench_long_context.py`](https://github.com/NandhaKishorM/laya/blob/main/research/scripts/bench_long_context.py): diff --git a/laya-ts/package.json b/laya-ts/package.json index 2b4f912..4f43477 100644 --- a/laya-ts/package.json +++ b/laya-ts/package.json @@ -1,6 +1,7 @@ { "name": "laya-ts", "version": "0.1.0", + "description": "Fast, local, on-device decision engine (TypeScript runtime)", "type": "module", "main": "./dist/index.js", "module": "./dist/index.js", @@ -14,6 +15,26 @@ "prepack": "npm run build" }, "files": ["dist", "scripts"], + "repository": { + "type": "git", + "url": "git+https://github.com/NandhaKishorM/laya.git", + "directory": "laya-ts" + }, + "keywords": [ + "decision-model", + "system-one", + "routing", + "guardrails", + "moderation", + "triage", + "onnx" + ], + "author": "Convai Innovations", + "license": "Apache-2.0", + "bugs": { + "url": "https://github.com/NandhaKishorM/laya/issues" + }, + "homepage": "https://nandhakishorm.github.io/laya/", "devDependencies": { "typescript": "^5.6.0", "vitest": "^2.1.0" }, "optionalDependencies": { "onnxruntime-node": "^1.20.0", "onnxruntime-web": "^1.20.0" } }