Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Publish packages in lockstep - #37

Merged
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources
May 6, 2026
Merged

Publish packages in lockstep#37
willwashburn merged 2 commits into
mainfrom
feat/installable-persona-sources

Conversation

@willwashburn

Copy link
Copy Markdown
Member

Summary

  • publish all npm packages together in dependency order
  • add burn-style lockstep baseline healing before version bumps
  • normalize current package versions to 0.5.5 and make internal workspace deps exact at pack time
  • include the README tagline change

Verification

  • pnpm install --frozen-lockfile
  • pnpm run check
  • parsed publish and verify workflow YAML
  • packed @agentworkforce/harness-kit and confirmed @agentworkforce/workload-router rewrites to 0.5.5

@coderabbitai

coderabbitaiBot commented May 6, 2026

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: e2111bd3-c223-458c-b86f-601ab3d11afc

📥 Commits

Reviewing files that changed from the base of the PR and between febe429 and 390bd6b.

📒 Files selected for processing (1)
  • packages/harness-kit/package.json

📝 Walkthrough

Walkthrough

The publish workflow was redesigned to execute lockstep multi-package publishing (workload-router, harness-kit, cli, agentworkforce) in fixed dependency order, replacing the prior per-package input mechanism. CI actions were upgraded, version-healing logic was externalized to a temp script, and the GitHub Release action was updated. A README header was revised and a package dependency spec was widened.

Changes

Lockstep Multi-Package Publishing

Layer / File(s)Summary
Workflow Architecture
.github/workflows/publish.yml (lines 1–5, 84–91)
Workflow renamed to "Publish Packages"; per-package workflow inputs removed; resolve-packages logic simplified to always publish in fixed dependency order (workload-router → harness-kit → cli → agentworkforce).
CI Tooling Upgrades
.github/workflows/publish.yml (lines 58–66, 512–515)
Upgrade checkout v4 → v6, pnpm v4 → v5, setup-node v4 → v6, and softprops/action-gh-release v2 → v3.
Version Healing Mechanism
.github/workflows/publish.yml (lines 107–177, 205–209)
Heal-versions logic moved from inline to externalized /tmp/lockstep-heal.mjs script; comments updated to reference baseline heal; functionality preserved.
Release Anchoring
.github/workflows/publish.yml (lines 466–471)
Release anchor clarified to reference agentworkforce tag for lockstep multi-package publishes; GitHub Release action invocation aligned with updated action version.
Dependency Configuration
packages/harness-kit/package.json (line 21)
@agentworkforce/workload-router dependency spec changed from workspace:^ to workspace:* to support lockstep version alignment.
Documentation
README.md (lines 3–4)
Header replaced: removed "# workforce" + subtitle; added single line describing saved agent configurations.

Sequence Diagram

sequenceDiagram
actor User
participant GitHub as GitHub Actions
participant Checkout as Checkout & Setup
participant Build as Build & Test
participant Heal as Version Heal
participant Publish as npm Publish
participant Release as GitHub Release
User->>GitHub: Trigger publish workflow
GitHub->>Checkout: Set up workspace (v6)
Checkout->>Checkout: Install pnpm (v5), Node (v6)
GitHub->>Build: Build all packages<br/>(workload-router → harness-kit → cli → agentworkforce)
Build->>Build: Test all packages in order
GitHub->>Heal: Run lockstep baseline heal script<br/>(/tmp/lockstep-heal.mjs)
Heal->>Heal: Align local versions to npm baseline
GitHub->>Publish: Bump and publish all packages<br/>in dependency order
Publish->>Publish: Tag each package release
GitHub->>Release: Build combined release notes
Release->>Release: Create GitHub Release<br/>(anchored to agentworkforce)
Release-->>User: Multi-package release complete
Loading

Estimated Code Review Effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Poem

🐰 Four packages hop in perfect time,
Lockstep rhythm, bells that chime,
Scripts heal and healers mend,
From start to GitHub release end,
Workflows dance in sync, divine!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Title check✅ PassedThe title 'Publish packages in lockstep' directly describes the main objective of the changeset—converting from package-specific to lockstep multi-package publishing.
Description check✅ PassedThe description is directly related to the changeset, outlining the key changes: lockstep publishing, baseline healing, version normalization, and README updates, with verification steps provided.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch feat/installable-persona-sources

Comment @coderabbitai help to get the list of available commands and usage tips.

@chatgpt-codex-connectorchatgpt-codex-connectorBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit:febe429b53

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +166 to +169
execSync(`npm version ${baseline} --no-git-tag-version --allow-same-version`, {
cwd: `packages/${e.pkg}`,
stdio: 'inherit',
});

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Skip lockstep heal when version bump is none

The new baseline-heal step runs npm version and can mutate package versions even when the dispatch input uses version: none (the documented no-bump path). In that mode, the later commit/tag steps are skipped by their if conditions, but Pack + publish still runs, so you can publish healed versions that are never committed or tagged in git. This reintroduces npm/git drift and breaks later changelog/tag baselines for any run where heal changes versions but no explicit bump/custom version was requested.

Useful? React with 👍 / 👎.

@willwashburn

Copy link
Copy Markdown
MemberAuthor

@copilot resolve the merge conflicts in this pull request

@coderabbitaicoderabbitaiBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/publish.yml (1)

385-386: ⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Pin npm to a stable version instead of latest.

Line 386 makes the publish path non-reproducible; a future npm minor/patch release could introduce unexpected behavior. The workflow requires npm >= 11.5.1 for OIDC trusted-publisher flow, so pin to a known-good version within that range (e.g., npm@11.13.0 or npm@11.x).

🔧 Proposed change
- - name: Install latest npm- run: npm install -g npm@latest+ - name: Install npm 11.x (pinned for reproducible publish behavior)+ run: npm install -g npm@11
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.github/workflows/publish.yml around lines 385 - 386, Replace the
non-reproducible "Install latest npm" step that runs "npm install -g npm@latest"
with a pinned, known-good npm version; update the run command in that step (the
"Install latest npm" workflow step) to install a specific npm release in the
supported range (for example "npm@11.13.0" or "npm@11.x") and ensure the chosen
version is >= 11.5.1 to keep OIDC trusted-publisher support while making the
publish workflow reproducible.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@README.md`:
- Line 3: Update the tagline string "Saved configurations of coding agents you
can save and share with your collegues." by correcting the misspelling
"collegues" to "colleagues" so the sentence reads "Saved configurations of
coding agents you can save and share with your colleagues."; locate and edit the
exact line containing that tagline in README.md.
---
Outside diff comments:
In @.github/workflows/publish.yml:
- Around line 385-386: Replace the non-reproducible "Install latest npm" step
that runs "npm install -g npm@latest" with a pinned, known-good npm version;
update the run command in that step (the "Install latest npm" workflow step) to
install a specific npm release in the supported range (for example "npm@11.13.0"
or "npm@11.x") and ensure the chosen version is >= 11.5.1 to keep OIDC
trusted-publisher support while making the publish workflow reproducible.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 362f07fd-4d6c-47f3-8204-91e5f7cecf01

📥 Commits

Reviewing files that changed from the base of the PR and between 429fd79 and febe429.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (5)
  • .github/workflows/publish.yml
  • README.md
  • packages/agentworkforce/package.json
  • packages/harness-kit/package.json
  • packages/workload-router/package.json

Comment threadREADME.md
![AgentWorkforce banner](./workforce-readme-banner.png)

# workforce
Saved configurations of coding agents you can save and share with your collegues.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🟡 Minor | ⚡ Quick win

Fix typo in the new tagline.

Line 3 has a spelling error: colleguescolleagues.

✏️ Proposed fix
-Saved configurations of coding agents you can save and share with your collegues.+Saved configurations of coding agents you can save and share with your colleagues.
📝 Committable suggestion

‼️IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
Saved configurations of coding agents you can save and share with your collegues.
Saved configurations of coding agents you can save and share with your colleagues.
🧰 Tools
🪛 LanguageTool

[grammar] ~3-~3: Ensure spelling is correct
Context: ...agents you can save and share with your collegues. ## Core frame A persona is the runtime...

(QB_NEW_EN_ORTHOGRAPHY_ERROR_IDS_1)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@README.md` at line 3, Update the tagline string "Saved configurations of
coding agents you can save and share with your collegues." by correcting the
misspelling "collegues" to "colleagues" so the sentence reads "Saved
configurations of coding agents you can save and share with your colleagues.";
locate and edit the exact line containing that tagline in README.md.

…ona-sources
# Conflicts:
#	packages/agentworkforce/package.json
#	packages/workload-router/package.json
Co-authored-by: willwashburn <957608+willwashburn@users.noreply.github.com>

CopilotAI commented May 6, 2026

Copy link
Copy Markdown
Contributor

@copilot resolve the merge conflicts in this pull request

Resolved in 390bd6b. The conflicts were in packages/agentworkforce/package.json and packages/workload-router/package.json where both sides bumped the version — I kept main's 0.6.0 (the actual published release) in both files. The harness-kit auto-merged cleanly, preserving both the 0.6.0 version from main and the workspace:* dep change from this branch.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@willwashburn