Skip to content

4. Bun executables and tag-driven releases ​

Status: accepted

Context ​

Users who only want the CLI or the server should not need a Node.js install. The Node.js build uses better-sqlite3, a native addon that a single-file executable cannot load. The project first used release-please, which cut releases from merged pull requests, while the artifacts needed a build on a tag.

Decision ​

Standalone executables are compiled with bun build --compile for Linux x64 and arm64, macOS x64 and arm64, and Windows x64. On Bun, openDatabase() uses the built-in bun:sqlite driver, whose API covers every call the package makes. A pushed v* tag runs one workflow that builds the executables, the multi-arch image and the npm tarball, smoke-tests each on its platform, attaches them to the GitHub Release with SHA256SUMS, an SPDX SBOM and provenance attestations, signs the image with cosign and publishes the npm package. release-please was removed so that there is one release path.

Consequences ​

  • One download runs the CLI and the server on each supported platform.
  • Two SQLite drivers must stay compatible. The smoke test runs every executable against a real grant, check, revoke and audit sequence.
  • Releases need a manual version bump and CHANGELOG entry before the tag.

Released under the Apache-2.0 license.