Skip to content

ci: auto-publish to Chrome Web Store on version bump - #100

Merged
junaidkbr merged 2 commits into
mainfrom
ci/chrome-web-store-publish
Sep 28, 2026
Merged

junaidkbr merged 2 commits into
mainfrom
ci/chrome-web-store-publish

Conversation

@junaidkbr

Copy link
Copy Markdown
Member

What does this PR do?

Adds a publish job to .github/workflows/ci.yml that submits the extension to the Chrome Web Store when a push to main changes the package.json version.

  • Runs after lint-and-build passes, on push only, so fork PRs never see the secrets.
  • Compares the version at github.event.before with HEAD. Merges without a version bump skip the job, since the store rejects a version it already has.
  • Builds with wxt zip and uploads with wxt submit on CWS API v2 (service account). API v1.1, which the local .env.submit OAuth refresh token uses, shuts down on 2026-10-15.
  • CHROME_CANCEL_PENDING: true: a new bump cancels any review still in progress, so the newest version is the one under review. Remove it to fail the job instead.
  • concurrency: chrome-web-store keeps two publish runs from racing.
  • AGENTS.md documents the job.

Required repo secrets: CHROME_EXTENSION_ID, CHROME_PUBLISHER_ID, CHROME_SERVICE_ACCOUNT_CLIENT_EMAIL, CHROME_SERVICE_ACCOUNT_PRIVATE_KEY (with real newlines, e.g. jq -r .private_key key.json | gh secret set CHROME_SERVICE_ACCOUNT_PRIVATE_KEY).

How to test

  1. Set the four secrets above, and link the service account email in the CWS Developer Dashboard under Account.
  2. Check credentials locally with the v2 values in .env.submit: bunx wxt zip && bunx wxt submit status --chrome-zip .output/*-chrome.zip. This reads the item status and uploads nothing.
  3. Merge this PR: the publish job runs and skips, since there's no version bump.
  4. The next PR that bumps the version publishes on merge.

Checklist

  • bun run lint passes
  • bun run format:check passes
  • Tested in Chrome (no extension code changes)
  • No new permissions required

Pushes to main that change the package.json version zip the extension
and submit it with wxt submit on CWS API v2 (service account). API
v1.1 OAuth shuts down 2026-10-15. Merges without a bump skip the job,
since the store rejects re-uploads of an existing version.
@junaidkbr
junaidkbr merged commit 278830a into main Sep 28, 2026
2 checks passed

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 2039d50. Configure here.

Comment thread package.json
{
"name": "alfred",
"version": "2026.09.26",
"version": "2026.09.28",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Version bump will publish incomplete release

High Severity

This PR bumps package.json and wxt.config.ts to 2026.09.28 without a changelog.json entry. The new publish job submits on any package.json version change, so merging uploads this build to the Chrome Web Store and the in-app changelog still shows 2026.09.26.

Additional Locations (2)
Fix in Cursor Fix in Web

Reviewed by Cursor Bugbot for commit 2039d50. Configure here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant