按源仓库内容呈现,保留标题、案例、代码、表格、链接以及原文引用的演示图片。
Release Cyrus
Run Cyrus releases through the trusted-publishing workflow. Do not publish workspace packages manually.
Required reference
Read apps/cli/RELEASING.md completely before taking release actions. Treat it as the canonical operator guide and scripts/release-packages.mjs as the canonical package list and dependency order.
Workflow
- Fetch
origin/main, start from current main, and preserve unrelated local
changes.
- Prepare the release on a branch:
- Move both changelogs' Unreleased entries into the new version.
- Set the same version in every manifest printed by
node scripts/release-packages.mjs list.
- Run
pnpm installand commit any lockfile change. - Run the F1 release test-drive protocol and save its report with the
required -release-v<version>.md suffix.
- List every released
package@versioninCHANGELOG.md.
- Run
node scripts/release-packages.mjs validate <version>, then all checks
required by apps/cli/RELEASING.md. Fix failures before continuing.
- Commit, push, open the release PR, and merge it to
mainbefore dispatching
the workflow. Never publish unmerged source or a non-main ref.
- Dispatch
.github/workflows/release-cli.ymlfrommainin dry-run mode and
monitor it through completion.
- Only when the user has explicitly requested the live release, dispatch the
same exact version with dry_run=false. Monitor it through npm publication, git tagging, and GitHub Release creation.
- Independently verify the version on npm and run the published CLI's
--version command.
- Use the Linear integration to move every issue referenced by the version's
changelog section from MergedUnreleased to ReleasedMonitoring.
Safety
- Never add an npm token. Publishing must use GitHub Actions OIDC.
- Confirm every npm package trusts
cyrusagents/cyrusand
release-cli.yml before the first live workflow run.
- A dry run does not authenticate to npm and does not prove registry writes.
- Never rerun a partially published version blindly. npm versions are
immutable; inspect which packages landed and recover deliberately.
- Do not create or move a release tag until every package is published. The
workflow owns tag and GitHub Release creation.

