Framework releases
Publish version-matched crates, npm packages, CLI binaries, and a GitHub Release through CI.
Vesty releases are tag-driven. A release tag publishes the framework SDK and CLI as one compatible set; uploading a CLI binary without its Rust and npm dependencies is not a valid release.
Distribution status
The framework is currently available through a source checkout. No framework crates, vesty-plugin-ui npm package, or prebuilt CLI GitHub Release is published yet. Use Get started for the working local-path workflow.
The intended release has three matching channels:
| Channel | User receives | User workflow after publication |
|---|---|---|
| GitHub Releases | Platform CLI archives, checksums, provenance | Install CLI, run vesty templates / vesty new |
| crates.io | Framework crates and vesty-cli at the same version | Generated exact version pins; optional cargo install vesty-cli --locked |
| npm | vesty-plugin-ui with framework adapters | Install dependencies in the generated ui/ directory |
Users distribute their finished plugins as platform-specific .vst3 bundles; they do not need to publish their plugin project to crates.io. Once the first release exists, promote the published installer workflow in the quick start, remove the local source overrides, and verify headless plus UI onboarding against the public registries.
The steps below are the maintainer release procedure, not a claim that these artifacts already exist.
Configure repository environments
Complete the first crates.io and npm publications manually. Both registries require a package to exist before its owner can add a trusted publisher. After the packages exist, create two protected GitHub environments with no registry secrets:
crates-ioprotects thepublish-cratesjob. For every Vesty crate, add a GitHub trusted publisher with repository ownerbackrunner, repository namevesty, workflow filenamerelease.yml, and environmentcrates-io.npmprotects thepublish-npmjob. Forvesty-plugin-ui, add a GitHub Actions trusted publisher with repository ownerbackrunner, repository namevesty, workflow filenamerelease.yml, and environmentnpm.
Require reviewer approval on both environments. The workflow requests GitHub OIDC identity tokens and exchanges them for short-lived registry credentials; it does not read a crates.io or npm publishing secret.
The GitHub repository must exist at backrunner/vesty before either registry publisher is configured. If the final repository owner changes, update the documentation and use that exact owner in all 14 publisher records.
Prepare a version
Use one SemVer value across [workspace.package].version, every Vesty crate, and packages/plugin-ui/package.json.
For example, an alpha release uses a tag such as v0.1.0-alpha.1; a stable release uses v0.1.0. Do not add build metadata to release tags.
Before tagging, run:
Bashnode scripts/release/verify-version.mjs v0.1.0-alpha.1cargo test --workspacecargo clippy --workspace --all-targets -- -D warningsnpm testcargo run -p vesty-cli -- publish-plan --out target/publish-plan.jsoncargo run -p vesty-cli -- crate-package --out target/crate-package.jsoncargo run -p vesty-cli -- npm-pack --out target/npm-pack.json
The final stable release still requires the external DAW, platform WebView, validator, signing, and notarization evidence described in Release evidence.
Publish through CI
Create and push an annotated tag only after the version commit is on main:
Bashgit tag -a v0.1.0-alpha.1 -m "Vesty v0.1.0-alpha.1"git push origin v0.1.0-alpha.1
The release workflow then:
- Verifies every Rust and npm package matches the tag.
- Generates and checks publish-plan, crate-package, and npm-pack evidence.
- Builds Linux x64, universal macOS, and Windows x64 CLI archives.
- Publishes 13 crates in dependency order and waits for each crates.io index entry.
- Publishes
vesty-plugin-ui, including its React, Vue, and Svelte subpath adapters. - Runs each released CLI against a generated Rust project and runs an additional React template build.
- Generates
SHA256SUMS, build provenance attestations, and the GitHub Release.
Registry publication is immutable and cannot be rolled back. If a job fails after some packages were published, fix the failure and rerun the same tag workflow. The scripts skip versions already present in a registry and continue from the first missing package. The GitHub Release is withheld until every smoke test passes.
Prerelease versions use their SemVer channel as the npm dist-tag, such as alpha, beta, or rc. Stable versions use latest.
Verify the published release
Download the archives from the completed workflow or GitHub Release, verify them against SHA256SUMS, and run:
Bashvesty --versionvesty templatesvesty new release-smoke --template gaincargo check --manifest-path release-smoke/Cargo.toml
For a prerelease installer test, pass its explicit tag:
Bashcurl --proto '=https' --tlsv1.2 -LsSf \ https://raw.githubusercontent.com/backrunner/vesty/main/scripts/install.sh \ | VESTY_VERSION=v0.1.0-alpha.1 sh