Skip to content

ci: ship trailing trunk fixes (push trigger, publish job, version bump, OIDC) - #2

Merged
visgotti merged 17 commits into
mainfrom
dev
May 2, 2026
Merged

visgotti merged 17 commits into
mainfrom
dev

Conversation

@visgotti

@visgotti visgotti commented May 2, 2026

Copy link
Copy Markdown
Owner

Summary

Three commits that didn't make it into PR #1 before the merge:

  • `69545c8` chore: bump version to 1.0.1
  • `e082742` ci: add push-to-main trigger and auto-publish job
  • `2ced167` ci: switch publish auth to npm Trusted Publishing (OIDC)

Why this matters

  • main's `ci.yml` currently has only the `pull_request` trigger, so the merge of PR ci: gate workflow on PRs to main, bump codecov-action to v5 #1 didn't fire any CI run on main — that's why the README badges are red ("CI") and "unknown" (codecov: no coverage uploaded for the default branch).
  • 1.0.1 was published manually from local; main still says 1.0.0. This brings them in sync.
  • The publish job is now OIDC-only (no NPM_TOKEN). After this merges, configure Trusted Publisher at https://www.npmjs.com/package/litellm-client/access — repo `visgotti/litellm-client`, workflow `ci.yml`, no environment.

After merge

CI will run on the merge commit (because the new ci.yml has the push trigger). The `publish` job's `version_check` step will see 1.0.1 is already on npm and skip with a notice — no double-publish. Coverage from the unit-tests (24) leg uploads to Codecov, badge populates. CI badge turns green.

Test plan

  • CI on this PR is green
  • After merge, push-to-main CI run appears and passes
  • README CI badge turns green
  • README codecov badge shows a coverage %

🤖 Generated with Claude Code

visgotti and others added 13 commits April 28, 2026 03:38
Export 41 resource classes and their associated types as part of the public SDK
surface. Resources can now be imported directly for advanced use cases like
creating custom clients or accessing resource methods independently.

Also expand the request API to use structured InternalRequestParams, improving
type safety and reducing coupling between resources and client internals. Export
RequestBodyKind, InternalRequestParams, and RawRequestFn for advanced use cases.

455 tests passing, all metrics > 90% coverage.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Codecov:
- Add codecov.yml with 90% project target, 80% patch target
- Update jest.config.ts to generate lcov coverage reports
- Update .github/workflows/ci.yml to upload coverage to Codecov on Node 24
- Add Codecov badge to README

GitHub Actions:
- Update lint and build jobs to use Node 24 (latest stable)
- Add Node 24 to unit-test matrix (now tests 18, 20, 22, 24)
- Configure coverage upload only on Node 24 (single source of truth)

Documentation:
- Add Codecov coverage badge alongside CI/E2E badges
- Add 9 new practical examples to README:
  * Embeddings with dimensional output
  * Image generation and editing
  * Audio (TTS, transcription, translation) with multipart uploads
  * Rerank with query and relevance scoring
  * Typed model strings (AnthropicModel, OpenAIModel, etc.) with IDE autocomplete
  * Vector stores with file upload and search
  * Spend tracking and observability (logs, global aggregates, cache hits)
  * Cache management (health checks, flushAll, settings)
  * Compliance and audit logging

455 tests passing, 99%+ coverage maintained.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Restrict CI to pull_request events targeting main and upgrade
codecov/codecov-action from v4 to v5.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Drop the push/workflow_dispatch gate on the e2e job so the full live-
provider matrix runs on every PR alongside lint/unit/build.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Rename LiteLLMProxyClient → LiteLLMClient (and LiteLLMProxyError →
LiteLLMError) across the public surface. Adds resource modules and
typed responses for the remaining LiteLLM admin/passthrough endpoints
(audit, claude_code, cloudzero, vantage, discovery, email_events,
projects, scim, settings, unified access groups, interactions,
openai_passthrough, fallbacks, jwt, callbacks, policies, prompts,
public, router_settings, tools, pass_through_config, access_groups).

Replace the live-only e2e workflow with a single in-repo suite that
runs against an isolated docker-compose proxy stack. Tests gate
Enterprise-only features behind LITELLM_LICENSE and use shared
expectShape / expectTypedError helpers.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Print the first 8 lines of each test's failureMessages alongside the
test name so CI logs are actionable without re-running locally.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Each matrix leg only forwards a single provider's key. Tests that hit
real OpenAI/Anthropic/Gemini endpoints now skip when their key isn't
set instead of asserting on a guessed proxy-error status.

- openai_apis: containers/realtime/evals.list need OPENAI_API_KEY
- vector_stores: OpenAI-shape create + nested files paths
- misc: usageAiChat (OpenAI-backed)
- parity_additions: client.interactions.retrieve (Gemini-backed)
- native: anthropic.countTokens, anthropic.skills.list, gemini.*

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Drop the per-provider key isolation in the matrix env block — every
leg now gets every *_API_KEY from secrets. Revert the it.skip gating
added in the prior commit; tests that hit live OpenAI/Anthropic/Gemini
endpoints run on every leg again.

Negative-path branches in native.e2e.test.ts now assert the actual
proxy status (500 for live calls, success for the local count_tokens
path) instead of the wrong 401 from before — they're dead code with
all keys forwarded but documented correctly for any future no-key run.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Every matrix leg now gets every *_API_KEY, so the HAS_X-gated alias
form was unreachable code. Inline plain `describe(...)` calls keep the
suite obvious — there are no provider-gated skips anywhere in CI.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Live API tests (containers list, gemini streaming, etc.) periodically
return transient 5xx / drop streams. Add jest.retryTimes(2) to the
files that hit real upstream providers so a single flake doesn't fail
the run; genuine bugs still surface after three attempts.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replaces the release-triggered publish.yml with a publish job at the
end of the main CI workflow. Fires only on push to main, only after
lint/unit-tests/build/e2e all succeed, and skips with a notice if the
package.json version is already on npm.

To ship: merge to main with a bumped version. To rerun without
publishing: leave the version unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Drop NODE_AUTH_TOKEN — the id-token: write permission combined with a
Trusted Publisher configured at npmjs.com/package/litellm-client/access
is sufficient. No NPM_TOKEN secret to rotate.

The first publish still has to be bootstrapped manually (the npm
package must exist before its trusted-publisher settings page can be
configured). After that initial release, every push-to-main with a
bumped version auto-publishes.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@visgotti visgotti closed this May 2, 2026
@visgotti visgotti reopened this May 2, 2026
visgotti and others added 2 commits May 2, 2026 00:31
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Resolves trivial conflicts from PR #1's squash merge — keeps dev's
ci.yml (push trigger + publish job), 1.0.1 version, and the deletion
of the standalone publish.yml.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@codecov-commenter

Copy link
Copy Markdown

Welcome to Codecov 🎉

Once you merge this PR into your default branch, you're all set! Codecov will compare coverage reports and display results in all future pull requests.

Thanks for integrating Codecov - We've got you covered ☂️

Single trigger model: every push to dev runs all gates; every push
to main runs gates + publish. PR pages still surface CI status via
the head SHA match, so branch protection on main can require these
checks without a separate pull_request trigger.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@visgotti
visgotti merged commit d6d2c78 into main May 2, 2026
12 checks passed

This branch was previously deployed

1 inactive deployment
live — 3da071c1 Deployed May 2, 2026 by visgotti via e2e (gemini) #14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants