POC: publish pup to npm - #879
Draft
tedkahwaji wants to merge 1 commit into
Draft
tedkahwaji wants to merge 1 commit into
tedkahwaji wants to merge 1 commit into
Conversation
Publish pup as @datadog/pup so it can run with `npx @datadog/pup` on any machine with Node.js, without Homebrew or a manual download. The root package is a small launcher; each release binary ships in its own optionalDependencies package (@datadog/pup-<platform>) so npm installs only the one matching the host. - npm/pup: launcher that resolves the platform package, passes arguments and exit codes through, and forwards SIGINT/SIGTERM/SIGHUP - npm/scripts/build-packages.js: builds the platform and root packages from GitHub release archives and stamps the version - npm-publish.yml: manual-only publish of an existing release, dry run by default, verifies the cosign-signed checksums before packaging - ci.yml: runs the launcher and builder tests Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
pup installs through Homebrew or a manual download from GitHub releases. Many developer and agent environments already have Node.js, and
npxis the lowest-friction way to run a CLI there: one command, no package manager setup, nothing to put onPATH. This POC publishes pup to npm so thatnpx @datadog/pup <command>works.What
Follows the per-platform
optionalDependenciespattern used by esbuild and Biome:npm/pup: the@datadog/puproot package. A small Node.js launcher (bin/pup.js) resolves the platform package for the host, runs its binary with arguments passed through, propagates the exit code, and forwardsSIGINT/SIGTERM/SIGHUPso a supervisor that signals only the launcher still stops pup. If the platform package is missing (for example--omit=optional), it exits 1 with guidance.@datadog/pup-{darwin-arm64,darwin-x64,linux-arm64,linux-x64,win32-x64}withos/cpuset, so npm installs only the matching one. These match the release matrix exactly. Linux binaries are static musl builds, so nolibcfield is needed.npm/scripts/build-packages.js: builds all packages from the GitHub release archives (pup_<version>_<Os>_<arch>.tar.gz/.zip) and stamps the version into everypackage.json, including the root package'soptionalDependencies. The npm binaries are byte-identical to the signed release binaries..github/workflows/npm-publish.yml:workflow_dispatchonly, for an existing release tag.dry_rundefaults totrue; a real publish also requires anNPM_TOKENsecret and runs in annpm-publishenvironment (which can require reviewer approval). Before packaging, it verifies the cosign-signed checksums against therelease.ymlsigning identity. Platform packages publish before the root package, with--provenance. Nothing has been published.ci.yml: newnpm Packagingjob that runs the launcher and builder tests..gitignore: thepupbinary pattern also matched thenpm/pupdirectory, so it is re-included.Testing
Unit tests (
node --test 'npm/**/*.test.js'): 12 passed, 0 failed. They cover platform resolution for every supported platform, unsupported platforms, a missing optional dependency, argument and exit-code passthrough, SIGTERM forwarding (asserted with a marker file written by the child's trap), the version stamping, a missing release archive, and invalid CLI input.Smoke test on macOS arm64, from a
cargo build --releasebinary packed withnpm packand installed into a fresh project:Also ran the build script against the real v1.23.7 release archives (
Darwin_arm64.tar.gz,Windows_x86_64.zip). Checksums verified, and the extracted binary reportspup 1.23.7. Release archive sizes are 24 MB to 28 MB, so the per-platform npm download is about the same as the GitHub release asset.The publish workflow has not been run.
Open questions
@datadogscope on npm, and who holdsNPM_TOKEN? Trusted publishing (OIDC, no long-lived token) is preferable if the scope supports it.--provenancelinks each package to this workflow run. Is that enough, or should the launcher also verify the binary against the release checksums at runtime?release.ymltrigger it automatically, and should a failed npm publish block the release?🤖 Generated with Claude Code