Skip to content

Move the CDN deploy out of the public release workflow - #968

Merged
kiftio merged 1 commit into
mainfrom
dk/web-publish-npm-only
Oct 9, 2026
Merged

kiftio merged 1 commit into
mainfrom
dk/web-publish-npm-only

Conversation

@kiftio

@kiftio kiftio commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

What changes are you making?

The CDN upload is moving out of this workflow and into Shopify's internal release tooling; this repository's release workflow goes back to publishing npm only.

  • web-publish.yml goes back to npm-only (about 150 lines removed): the auth, pre-flight, bucket-permission check, redeploy guard and upload steps are gone. It still runs build:cdn and verify, so CI proves the CDN artefacts build and the built-package tests keep covering both distributions. npm publish --ignore-scripts stays.
  • The CDN deploy is triggered by a maintainer with the release tag after npm publication. It checks out that tag of this repo, rebuilds dist-cdn/, refuses to deploy a version npm does not have, reads the npm dist-tag back, runs this repo's scripts/cdn-release-policy.mjs for the channel, and uploads chunks before the loader. Re-triggering with an older tag is rollback.
  • Docs: CDN-PUBLISHING.md "Publishing" rewritten for the two-step flow; RELEASING.md gains a "Deploy the CDN assets" step and the bad-deploy runbook points at re-triggering the deploy; the environment-secrets section is removed.

After merge: the four CDN_* secrets on the npm-web environment are unused and can be deleted. web/4.0.0-alpha.5 will be the first release to go through the tag path; earlier alphas were published by manual dispatch without tags.

How to test

actionlint .github/workflows/web-publish.yml
cd platforms/web && pnpm lint && pnpm build && pnpm verify

No runtime code changes; workflow and docs only.


Before you merge

Important

  • I've added tests to support my implementation (n/a: workflow and docs)
  • I have read and agree with the Contribution Guidelines
  • I have read and agree with the Code of Conduct
  • I've updated the relevant platform README (RELEASING.md / CDN-PUBLISHING.md)

@kiftio
kiftio requested a review from a team as a code owner October 9, 2026 13:53
@github-actions github-actions Bot added the #gsd:50662 Rebase Checkout Kit on UCP label Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Bundle Size Budgets

Budget Size Limits Result
— — — ➖ No configured budgets affected

Bundle and package size

Web bundle sizes cover shipped runtime JavaScript. Package sizes cover the full published archive, including any source maps, declarations, and documentation it contains.

Platform Measurement Compression Base Head Delta
- - - - - -
How sizes are measured

Measured from the PR base SHA and PR head SHA. Web bundle rows sum shipped .js, .mjs, and .cjs files under dist/, excluding source maps and declarations. The gzip bundle size sums files compressed individually with gzip -n -9. npm package sizes are gzip-compressed .tgz archives; Android AAR sizes are ZIP archives. Package sizes are not final app binary sizes.

@bitrise

bitrise Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Bitrise builds

E2E · iOS CI

Checkout Kit E2E results

No native E2E runs were selected for this change.

The release workflow goes back to publishing npm only. It still builds and
verifies the CDN output so CI proves the artefacts, but the upload to the
CDN now runs from Shopify's internal release tooling, triggered with the
release tag after npm publication. That deploy rebuilds from the tag,
refuses to deploy a version npm does not have, and reuses the kit's channel
policy script. Docs updated; the environment secrets added for the in-repo
upload are no longer needed.
@kiftio
kiftio force-pushed the dk/web-publish-npm-only branch from c990ecb to 3c5c674 Compare October 9, 2026 14:28
@kiftio
kiftio merged commit b2c4202 into main Oct 9, 2026
23 of 24 checks passed
@kiftio
kiftio deleted the dk/web-publish-npm-only branch October 9, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

#gsd:50662 Rebase Checkout Kit on UCP

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants