Skip to content

Secret scanning hooks, dist-only publish, GitHub Actions CI with npm trusted publishing - #7

Merged
furkando merged 2 commits into
mainfrom
chore/secret-scan-and-publish-ci
Sep 11, 2026
Merged

furkando merged 2 commits into
mainfrom
chore/secret-scan-and-publish-ci

Conversation

@furkando

Copy link
Copy Markdown
Contributor

Summary

  • Secret scanning. A pre-commit hook (.githooks/pre-commit, wired by a guarded postinstall) scans the staged snapshot with secretlint, and prepack runs the same scan over the whole tree including dist/ on every npm publish / yarn pack. Config in .secretlintrc.json, exclusions in .secretlintignore.
  • Publish only dist/. files: ["dist"] in package.json. The 1.0.1 currently on npm ships src/ and examples/ but no dist/ at all (it was gitignored with no files field), so exports pointed at a missing file. Version bumped to 1.0.2 so the merge publishes a working package.
  • GitHub Actions CI. checks.yml typechecks, lints, tests and builds on every PR and push to main. publish.yml publishes the version in package.json on main when it is not on npm yet, through npm trusted publishing (OIDC, id-token: write, npm 11). No npm token anywhere; provenance is attached automatically.
  • zklighter-perps bumped to 1.0.303 (devDependency and peer floor), which also fixes the typecheck failure on main. zklighter-perps is preapproved in .yarnrc.yml for Yarn's minimum-age gate, matching the other repos.

Verification

  • yarn typecheck, yarn lint, yarn test --run (28 tests), yarn build, yarn scan:secrets, yarn install --immutable all pass locally.
  • npm publish --dry-run runs the prepack scan and packs only dist/, package.json, README.md, LICENSE.
  • Hook verified to block a staged secret, pass a secret that is only in the working tree, skip .secretlintignore entries, and clean up its temp dir.

Before merge

  • Trusted publisher registered on npmjs.com for elliottech/lighter-ts/publish.yml with direct npm publish allowed.

@furkando
furkando merged commit d0493ae into main Sep 11, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant