Skip to content

ci(pi): publish @tiny-fish/pi to npm (PF-3852) - #42

Merged
Zechereh merged 3 commits into
mainfrom
zach/pf-3852-pi-publish
Sep 14, 2026
Merged

Zechereh merged 3 commits into
mainfrom
zach/pf-3852-pi-publish

Conversation

@Zechereh

@Zechereh Zechereh commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Stacked on #41. Release control for @tiny-fish/pi, kept separate so the content PRs can merge independently.

Modelled on ux-labs CD_cli.yml rather than the PyPI workflows in this repo — it is the house pattern for npm publishing.

No NPM_TOKEN needed

Auth is npm Trusted Publisher (OIDC), same as the CLI. The job requests id-token: write and npm verifies the workflow identity directly, so this repo does not grow an npm secret. (An earlier revision of this PR asked for NPM_TOKEN; that ask is withdrawn.)

⚠️ Manual bootstrap, one-time

A trusted publisher cannot be configured against a package that does not exist yet, so the first release is by hand:

  1. cd pi && npm publish --access public
  2. npmjs.com → @tiny-fish/pi → Settings → Trusted Publisher → GitHub Actions
    repo tinyfish-io/tinyfish-web-agent-integrations, workflow pi-publish.yml
  3. Every release after that is this workflow, triggered by a version bump

Steps 1–2 are yours to run — I can't publish to the @tiny-fish scope. The same steps are in the workflow header so the next person doesn't have to reconstruct them. @tiny-fish/pi is currently unclaimed (registry 404).

When it publishes

Gated on the version in pi/package.json not already existing on the registry, so content-only edits don't need a version bump and a re-run is a no-op rather than an error. An unexpected registry response fails the job instead of reading as "already published". workflow_dispatch is there as a re-run escape hatch.

Tarball verification — the part worth reviewing

Borrowed from CD_cli.yml's "Verify npm package contents" step, and it matters more here than there. This package ships no code, so a dropped files entry is the entire failure mode: the tarball still publishes, still installs, and pi just silently has fewer skills. Nothing else would catch it.

The job asserts mcp.json, the README, rules/security.md and all five SKILL.md files are present, plus that the references/ docs the skills link to came along — a skill pointing at a file that isn't in the tarball is worse than no pointer.

Negative-tested: removing rules from files fails the job with Missing from tarball: rules/security.md.

Smaller notes

  • Node 24, for npm ≥ 11.5.1 which trusted publishing requires.
  • Action refs use tags, matching every other hand-written workflow here. The one pinned SHA in this repo is in secrets-scanner.yml, which is Terraform-managed.
  • concurrency with cancel-in-progress: false — a publish must never be cancelled mid-upload.

🤖 Generated with Claude Code

https://claude.ai/code/session_01CBf5rnVYQYcxE8bLjfQuUP

@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

  • Run on-demand review

On-demand reviews are free for the next 6 days. After that, they cost $0.25 per reviewed file.

Or wait 54 minutes for your next included review.

Check out review usage here.

View limit details

Limit details: You’ve used all 2 included reviews currently available. Your 55 included PR review attempts over the past 7 days set your current allowance at 2 reviews per hour.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: e2800a89-8e52-44e3-9b09-b7c186af2613

📥 Commits

Reviewing files that changed from the base of the PR and between 822f5c2 and 253037b.

📒 Files selected for processing (1)
  • .github/workflows/pi-publish.yml

Comment @coderabbitai help to get the list of available commands.

@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from fc5eb03 to cd11196 Compare September 14, 2026 17:33
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from a45adb1 to af63024 Compare September 14, 2026 17:33
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from cd11196 to 602cf1f Compare September 14, 2026 17:35
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from af63024 to 7dd382a Compare September 14, 2026 17:35
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from 602cf1f to 38298c2 Compare September 14, 2026 17:57
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 7dd382a to fc00d50 Compare September 14, 2026 17:57
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from 38298c2 to b9f326a Compare September 14, 2026 18:00
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from fc00d50 to 38347c1 Compare September 14, 2026 18:00
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from b9f326a to c96a5ed Compare September 14, 2026 18:53
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 38347c1 to 023b6ca Compare September 14, 2026 18:54
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from c96a5ed to c0ca5d5 Compare September 14, 2026 19:03
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 023b6ca to 1949f09 Compare September 14, 2026 19:03
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from c0ca5d5 to a1e9c86 Compare September 14, 2026 19:13
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 1949f09 to f581015 Compare September 14, 2026 19:13
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from a1e9c86 to 6364d72 Compare September 14, 2026 19:28
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from f581015 to 15945df Compare September 14, 2026 19:28
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from 6364d72 to 1b07022 Compare September 14, 2026 19:39
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 15945df to 4e7f2b2 Compare September 14, 2026 19:39
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from 1b07022 to 4c6fc61 Compare September 14, 2026 19:54
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 4e7f2b2 to 88789a7 Compare September 14, 2026 19:54
Zechereh and others added 2 commits September 14, 2026 14:00
Ports the five skills from `grok/` — router plus research, automation,
authenticated and browser — with their `references/` subdirs, which pi supports
natively. Prefixed names are kept deliberately: pi skills land in the shared
`~/.agents/skills` namespace alongside every other package's, where `search`
would be ambiguous and would also collide with the CLI-installed `use-tinyfish`.

Most of the diff is a verbatim port. The adaptations are:

| Change | Why |
|---|---|
| New "Finding the tools" section in the router | Same tool has three names depending on install path. The suffix is the tool, the prefix names the install. |
| New CLI-fallback section with a mapping table | Pi ships no MCP client, so most users have no TinyFish tools at all. The CLI grammar is two-level (`tinyfish search query "<q>"`) and does not mirror the tool names, so without the table a model invents `tinyfish run_web_automation`. |
| Rewrote both Auth sections | grok's said the server is "configured by this plugin, authenticated by OAuth on first connection" — the exact opposite of the truth on this route, which is key-only with no OAuth. |
| `rules/security.md` -> `../../rules/security.md` | Pi resolves skill references relative to the skill directory, so the bare path dangled. |
| "plugin" -> "package" throughout | This is an npm package, not a plugin; pi users would not recognise the term. |

The auth failure mode is quieter than expected and the copy reflects it. With
`TINYFISH_API_KEY` unset the server never finishes connecting, so no metadata
cache is built and *no tools register at all* — no 401, no error text, nothing at
startup. That is indistinguishable at a glance from having no adapter installed,
so the router carries a two-branch diagnostic: no `mcp` tool at all means no
adapter; `mcp` present but `mcp({ search: "tinyfish" })` empty means the key.

Verified in an isolated `PI_CODING_AGENT_DIR` against a live pi session: all five
skills load, all eight MCP tools register top-level, a real search call returns
through the package's own registration, and with the adapter removed the model
reaches `tinyfish search query "..."` unaided — then recovers to
`npx -y @tiny-fish/cli@latest` when the binary is absent too.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CBf5rnVYQYcxE8bLjfQuUP
Follows ux-labs CD_cli.yml rather than the PyPI workflows in this repo, because
it is the house pattern for npm here.

**Auth is npm Trusted Publisher (OIDC), so there is no NPM_TOKEN secret.** The
job requests `id-token: write` and npm verifies the workflow identity directly.
This repo has no npm secret and did not need to grow one.

Bootstrap is manual and one-time, because a trusted publisher cannot be
configured against a package that does not exist yet:

  1. `cd pi && npm publish --access public`
  2. npmjs.com -> @tiny-fish/pi -> Settings -> Trusted Publisher -> GitHub
     Actions, repo tinyfish-io/tinyfish-web-agent-integrations, workflow
     pi-publish.yml
  3. every release after that is this workflow, triggered by a version bump

Documented in the workflow header so the next person does not have to
reconstruct it.

Publishing is gated on the version in pi/package.json not already existing on
the registry, so content-only edits do not require a version bump and a re-run
is a no-op rather than an error. An unexpected registry response fails the job
instead of reading as "already published".

Borrowed from CD_cli.yml, and the most valuable part here: verifying tarball
contents before publishing. This package ships no code, so a dropped `files`
entry is the entire failure mode — the tarball still publishes and still
installs, just with skills silently missing. The job asserts every SKILL.md,
mcp.json, the README and rules/security.md are present, and that the
references/ docs the skills link to came along. Negative-tested by removing
`rules` from `files`, which fails the job naming the missing path.

Node 24 for npm >= 11.5.1, which trusted publishing requires. Action refs use
tags to match every other hand-written workflow here; the one pinned SHA in the
repo is in Terraform-managed secrets-scanner.yml.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CBf5rnVYQYcxE8bLjfQuUP
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-skills branch from 4c6fc61 to 0c97464 Compare September 14, 2026 21:01
@Zechereh
Zechereh force-pushed the zach/pf-3852-pi-publish branch from 88789a7 to fb470eb Compare September 14, 2026 21:01
Base automatically changed from zach/pf-3852-pi-skills to main September 14, 2026 21:05
@Zechereh
Zechereh merged commit e5666f0 into main Sep 14, 2026
3 checks passed
@Zechereh
Zechereh deleted the zach/pf-3852-pi-publish branch September 14, 2026 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants