Repository navigation
chore(APP-1037): Migrate aragon-domain to the app monorepo, with history - #1425
Conversation
Feat/ci npm flow
Credentials retrieval security upgrade
* Look up member profile ENS records Adds the GetMemberProfileTextRecordsUseCase along with the supporting infrastructure: MemberProfile domain objects (subdomain + text record value objects), an EnvioMemberProfileStore that resolves the live text records from the indexer, and the AragonController endpoint that fronts the use case. * Changeset * Upgrade to vitest * Remove unneeded fields from query * JSdoc * Moves business logic from mapper to domain object * Docs * Fix test * Improve readme * Filtered out old text versions and empty records on indexer * Fix code review comments * Fix pnpm lock * Lint * Fixing type error * Lint * Fix code review comments * Fix code review comments * Fix Address invariant * Handle no-ops in snapshot
* chore(APP-818): Update dependencies and align pnpm security configuration - Bump vitest to 3.2.6 to resolve critical advisory, update dependencies in-range - Move pnpm settings to pnpm-workspace.yaml with supply-chain policies as in app repo - Require Node >= 24.13 and pnpm >= 11 (engines), document nvm/.nvmrc + corepack setup in README - Add Dependabot configuration - Authenticate npm publish via pnpm_config_…_authToken env var * ci: adopt OIDC trusted publishing for npm Replace the broken token-based publish (pnpm_config_ env var that collides with setup-node's placeholder .npmrc, causing 404) with OIDC trusted publishing: - Add publish.yml entry point (single npm Trusted Publisher); it dispatches to library-publish.yml on release and library-snapshot.yml on workflow_dispatch. - Convert library-publish.yml / library-snapshot.yml to reusable workflows with id-token: write; publish via plain `pnpm publish`, drop NPM_TOKEN. - Publish with --provenance (pnpm 11.6) to emit signed build-provenance attestations. - Gate stable release publishing behind the `npm-publish` environment (@aragon/app-team required reviewers). - Setup action: default registry-url to empty so no placeholder .npmrc shadows OIDC. - Add CODEOWNERS (@aragon/app-team); update README publish instructions. Requires npm-side: register publish.yml as the trusted publisher for @aragon/aragon-subdomain (leave environment empty so snapshots also publish). * chore(APP-818): refresh dependencies, add ws override, pin Node 24.16 - Add ws override <8.21.0 (>=8.21.0) for the new ws DoS advisory; ws resolves to 8.21.0 - In-range pnpm up + dedupe - Pin Node to 24.16.0 (.nvmrc + pnpm nodeVersion); engines floor stays >=24.13.0 - Residual audit: esbuild (0.28.1 <7-day cooldown) auto-resolves once aged; js-yaml is dev-only (changesets read-yaml-file, trusted input) * chore(APP-818): pin third-party GitHub Actions to commit SHAs Resolves the open CodeQL actions/unpinned-tag alerts by pinning crazy-max/ghaction-import-gpg, pnpm/action-setup, martinbeentjes/npm-get-version-action and softprops/action-gh-release to commit SHAs (version in comments). * fix(ci): inline publish jobs so OIDC trusted publishing matches the publisher Mirror the working gov-ui-kit setup: run both publish jobs INLINE in publish.yml (release -> stable, workflow_dispatch -> snapshot) instead of via reusable workflows. npm matches the OIDC token's workflow identity against the registered trusted publisher (publish.yml); a reusable/called workflow makes npm reject the token exchange with a 404. Remove the now-unused library-publish.yml / library-snapshot.yml. Note: the npm Trusted Publisher Environment field must stay EMPTY so the snapshot job (which has no environment) matches; the release approval gate is enforced GitHub-side via the npm-publish environment. * chore(deps): fix audit + esbuild peer, bump pnpm to 11.8.0 - Remove stale overrides: `vite@<=6.4.1` (vite is 6.4.3) and `esbuild@<=0.24.2` (esbuild is 0.25.x/0.27.x). The stale esbuild override was being projected by `pnpm dedupe` as a phantom `^0.25.0` peer constraint on bundle-require (whose real peer is `esbuild >=0.18`), causing ERR_PNPM_PEER_DEP_ISSUES. - Add audit overrides: - `js-yaml@<=4.1.1: >=4.1.2` (moderate, via @changesets/cli) -> 4.2.0 - `read-yaml-file@<2.1.0: ^2.1.0` so the js-yaml 4 bump doesn't break `changeset status` (read-yaml-file@1.x calls js-yaml's removed `safeLoad`; 2.1.0 is the last CJS release using the js-yaml 4 `load` API) - `esbuild@^0.27.0: >=0.28.1` (low, dev-only via tsup) -> 0.28.1 - Bump packageManager to pnpm@11.8.0 (corepack).
…gon/aragon-domain`, updating all relevant references and exports. The public controller export is now `AragonDomain` instead of `AragonSubdomain`. Update documentation and tests accordingly. (#15)
* chore: Export MemberProfileTextRecordDTO * Changeset
* chore: Export MemberProfileTextRecordDTO * Changeset * chore: Export GetMemberProfileTextRecordsDTO
… updates (#17) Bumps the minor-and-patch group with 3 updates in the / directory: [bignumber.js](https://github.com/MikeMcl/bignumber.js), [viem](https://github.com/wevm/viem) and [@changesets/changelog-github](https://github.com/changesets/changesets). Updates `bignumber.js` from 11.1.2 to 11.1.4 - [Release notes](https://github.com/MikeMcl/bignumber.js/releases) - [Changelog](https://github.com/MikeMcl/bignumber.js/blob/main/CHANGELOG.md) - [Commits](MikeMcl/bignumber.js@v11.1.2...v11.1.4) Updates `viem` from 2.52.2 to 2.53.1 - [Release notes](https://github.com/wevm/viem/releases) - [Commits](https://github.com/wevm/viem/compare/viem@2.52.2...viem@2.53.1) Updates `@changesets/changelog-github` from 0.6.0 to 0.7.0 - [Release notes](https://github.com/changesets/changesets/releases) - [Commits](https://github.com/changesets/changesets/compare/@changesets/changelog-github@0.6.0...@changesets/changelog-github@0.7.0) --- updated-dependencies: - dependency-name: bignumber.js dependency-version: 11.1.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: viem dependency-version: 2.53.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: minor-and-patch - dependency-name: "@changesets/changelog-github" dependency-version: 0.7.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…#11) Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4.2.0 to 6.4.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v4.2.0...v6.4.0) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 6.4.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.1 to 7.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6.0.1...v7.0.0) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
) Bumps [pnpm/action-setup](https://github.com/pnpm/action-setup) from 4.2.0 to 6.0.9. - [Release notes](https://github.com/pnpm/action-setup/releases) - [Commits](pnpm/action-setup@41ff726...0ebf471) --- updated-dependencies: - dependency-name: pnpm/action-setup dependency-version: 6.0.9 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2 to 7.0.0. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6.0.2...v7.0.0) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
… updates (#7) Bumps the minor-and-patch group with 2 updates in the / directory: [1password/load-secrets-action](https://github.com/1password/load-secrets-action) and [softprops/action-gh-release](https://github.com/softprops/action-gh-release). Updates `1password/load-secrets-action` from 4.0.0 to 4.0.1 - [Release notes](https://github.com/1password/load-secrets-action/releases) - [Commits](1Password/load-secrets-action@92467eb...3a12b0a) Updates `softprops/action-gh-release` from 3.0.0 to 3.0.1 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@b430933...718ea10) --- updated-dependencies: - dependency-name: 1password/load-secrets-action dependency-version: 4.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: softprops/action-gh-release dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0. - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](actions/setup-node@v6.4.0...v7.0.0) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
… updates (#24) Bumps the minor-and-patch group with 2 updates in the / directory: [actions/checkout](https://github.com/actions/checkout) and [softprops/action-gh-release](https://github.com/softprops/action-gh-release). Updates `actions/checkout` from 7.0.0 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v7.0.0...v7.0.1) Updates `softprops/action-gh-release` from 3.0.1 to 3.0.2 - [Release notes](https://github.com/softprops/action-gh-release/releases) - [Changelog](https://github.com/softprops/action-gh-release/blob/master/CHANGELOG.md) - [Commits](softprops/action-gh-release@718ea10...3d0d988) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch - dependency-name: softprops/action-gh-release dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 1 update in the / directory: [bignumber.js](https://github.com/MikeMcl/bignumber.js). Updates `bignumber.js` from 11.1.4 to 11.1.5 - [Release notes](https://github.com/MikeMcl/bignumber.js/releases) - [Changelog](https://github.com/MikeMcl/bignumber.js/blob/main/CHANGELOG.md) - [Commits](MikeMcl/bignumber.js@v11.1.4...v11.1.5) --- updated-dependencies: - dependency-name: bignumber.js dependency-version: 11.1.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* feat(APP-610): Implement ERC20 token voting membership use case Adds the first full token-voting membership query to aragon-domain: a paginated, voting-power-ordered list of a TokenVoting plugin's ERC20Votes members, each with their primary ENS name resolved. - model membership as a domain aggregate: TokenVotingMember composes the on-chain TokenVotingMemberRecord, optional MemberGovernanceActivity and ENSName, with VotingPower as its own wei-backed value type - GetTokenVotingMembershipUseCase orchestrates the MemberStore and ENSStore; EnvioMemberStore reads ERC20VotesDelegate and MemberGovernanceMetrics from the indexer - resolve primary ENS names through viem (ViemENSStore) with the SEAL safeguards instead of indexed reverse records; a failed lookup degrades to a null name - expose getTokenVotingMembership on AragonController; load now takes an RpcUrls map (RPC endpoints keyed by chain id) alongside the EnvioClient - move the test runner to vitest; integration tests cover the membership and member-profile paths end to end, unit tests cover the new domain objects and stores * refactor(APP-610): scope token-voting membership by chain and address review feedback - add the ChainId value object and require chainId on the request DTO, use-case props, store query and both Envio queries - split the members query: a paged delegates query with the delegate address as a stable tiebreaker, then page-sized MemberGovernanceMetrics via _in (skipped for an empty page) - count members in id batches with an explicit limit (COUNT_BATCH_SIZE), since an unbounded list cannot detect Hasura's row cap; contract test checks the endpoint serves a full batch - enforce non-negative VotingPower, move earliest/latest into the domain primitives, extract PageMetadataDTO - require a mainnet RPC URL in ViemENSStore.fromRpcUrls instead of falling back to viem's public endpoint - add an env-gated contract test (pnpm test:contract) that runs the real query documents against a deployed indexer - drop the unused MemberGovernanceMetricsDTO export - document DTOs, store data, use-case props and fixtures; derive the test client stub from EnvioClient.query - README usage for load(envioClient, rpcUrls), CHANGELOG rename typo, vitest coverage exclude path, fuller changeset summary --------- Co-authored-by: Andrew <ilin.andrii@gmail.com>
6e2f01a to
7efe60c
Compare
7efe60c to
dc3e426
Compare
milosh86
left a comment
There was a problem hiding this comment.
Did a quick pass and found only one minor issue.... Additional question: do we even need NPM publish for aragon-domain?
dc3e426 to
5dc1bfe
Compare
|
Fair question. Today the app is the only consumer, so strictly speaking nothing needs the npm package right now. The reason I'd keep it is the same as for gov-ui-kit: aragon-domain is meant to be the shared TS entry point to the Envio data for any Aragon app, not an internal of this one. The next UI that needs members or voting power should be able to |
ok, makes sense, just wanted to double check if there are use cases for consuming it from the outside of monorepo 👍 |
Every commit of aragon/aragon-domain main, rewritten under packages/aragon-domain/ and re-signed; authors, dates and messages unchanged.
Root biome.json holds the shared rules and formatting (ultracite core + react + next);
apps/app, packages/gov-ui-kit and packages/aragon-domain keep only their own policy in a
nested biome.jsonc that extends it. The kit keeps its 120-column lines and drops its
ultracite devDependency.
Mechanical part, reproducible from the four configs:
pnpm exec biome format --write .
pnpm exec biome check --write .
pnpm exec biome lint --write --unsafe --only=style/useNumericSeparators \
--only=style/useNodeAssertStrict --only=style/useConsistentMethodSignatures \
--only=correctness/noGlobalDirnameFilename packages/aragon-domain
pnpm exec biome format --write .
By hand, only in files reformatted here (the pre-commit hook lints them): the domain drops
`public` modifiers, `async` from four test mocks (now Promise.resolve/reject) and an unused
suppression.
5dc1bfe to
b793e62
Compare
milosh86
left a comment
There was a problem hiding this comment.
One more tiny comment :)
| # anything merged to main in the meantime would otherwise be published under the tagged | ||
| # version. Same pattern as gov-ui-kit-publish.yml. | ||
| ref: ${{ github.event.release.tag_name }} | ||
| # MUST stay empty. The setup action defaults registry-url to the npm registry, which |
There was a problem hiding this comment.
The setup action defaults registry-url to the npm registry this seems not to be true now, it defaults to ""?
There was a problem hiding this comment.
Right, the default is empty since the setup action moved to the monorepo. Reworded to match gov-ui-kit-publish.yml
The package drops what the root now owns (changesets config, .github, lockfile, workspace file, .gitignore, .nvmrc), takes its tooling from the catalog, and apps/app consumes it as workspace:*. The manifest declares separate import/require type entries, `type` and `sideEffects`, so publint and attw report nothing. Its CI moves over the way the kit's did: lint, types and the 100 % coverage gate run in App Development; releases get an aragon-domain scope and aragon-domain-release-start / -release-pr-finalize / -publish (tag @aragon/aragon-domain@x.y.z, npm publish behind npm-publish); the contract suite runs nightly against the development indexer. RELEASING.md describes the flow. By hand, for the rules the unified config adds: stable keys or a reasoned biome-ignore for index keys in apps/app and assistant-chat, stray JSX semicolons in two app tests, TooltipIconButton takes ref as a prop instead of forwardRef, and the kit's Breadcrumbs uses links.at(-1). The previous commit goes into .git-blame-ignore-revs.
b793e62 to
b6f8776
Compare
The package moved to aragon/app (packages/aragon-domain) with aragon/app#1425; this repository is being archived.
Description
Move
aragon-domaininto this monorepo aspackages/aragon-domain, with its git history, and make it a workspace dependency ofapps/app. Every Envio slice changes the domain and the app together; today that means a snapshot publish, a version bump and an amend across two repos. As a workspace package the pair ships in one PR, and the app picks up a domain change on merge, with no publish in between. The domain keeps publishing to npm through its own release flow, set up like the kit's.The PR also unifies the Biome config: shared rules and formatting live in the root
biome.json, andapps/app,packages/gov-ui-kitandpackages/aragon-domainkeep only their own policy in a nestedbiome.jsoncthat extends it.Commits
import aragon-domain history. The 26 commits ofaragon/aragon-domainmain, rewritten underpackages/aragon-domain/and re-signed; authors, dates and messages unchanged. No review needed. The package tree is byte-identical toaragon-domainmain(v0.4.0), and nothing outside the package changes.unify the Biome config across workspaces. Four configs plus a mechanical pass: the domain moves from 2 to 4 spaces and picks up the ultracite auto-fixes; the kit keeps its 120-column lines, so only three of its JSON files change. The commit body has the recipe. Run it on the parent with the four configs, and only the short by-hand list from the same body remains. Listed in.git-blame-ignore-revs.adapt aragon-domain to the monorepo. Everything else, all by hand: package wiring, release and CI workflows, docs, and the findings the unified config raises inapps/app,assistant-chatand the kit.What to review
biome.json,apps/app/biome.jsonc,packages/gov-ui-kit/biome.jsonc,packages/aragon-domain/biome.jsonc.package.json,turbo.json,tsconfig.json,README.md,AGENTS.md,RELEASING.md. The manifest now has separate import/require type entries plustypeandsideEffects; publint and attw report no problems on the packed tarball.aragon-domain-release-start.yml,aragon-domain-release-pr-finalize.yml(tag@aragon/aragon-domain@x.y.z),aragon-domain-publish.yml(npm publish with provenance behindnpm-publish, snapshots on dispatch). The standalone repo'slibrary-test.ymlhas no replacement of its own: lint, types and the 100 % coverage gate run in thetestjob ofApp Development, as for the kit.aragon-domain-contract-test.ymlruns the contract suite nightly against the development indexer, with the endpoint and token the development app reads (NEXT_SECRET_ENVIO_*inkv_app_development). Not a required check..github/release-scopes.yml(newaragon-domainscope),.github/filters.yml(domain commits reach app release notes),pnpm-workspace.yaml(vitest and coverage-v8 pinned exact,minimumReleaseAgeExcluderemoved),apps/app/package.json(workspace:*).;in test JSX inapps/app; inassistant-chat,TooltipIconButtontakesrefas a prop, plus one index key; the kit'sBreadcrumbsuseslinks.at(-1).Merging
Merge with "Create a merge commit". Squash drops the imported history, and the hash in
.git-blame-ignore-revsonly reachesmainthrough a merge commit.After merge
@aragon/aragon-domainataragon/app+aragon-domain-publish.yml(as done for the kit); the registration for the old repo stops working once it is archived.kv_app_developmentholdsNEXT_SECRET_ENVIO_GRAPHQL_ENDPOINT/NEXT_SECRET_ENVIO_API_TOKENand that the endpoint serves chain 1, then runAragon Domain Contract Testby hand.aragon/aragon-domainwith a pointer topackages/aragon-domain; close its open dependabot PRs. Itskv_aragon-domain_infravault (GPG key + PAT of the old release flow) is no longer needed.🤖 Generated with Claude Code