
Product
Introducing Socket Firewall Enterprise: Flexible, Configurable Protection for Modern Package Ecosystems
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.
semantic-release-firefox
Advanced tools
Set of semantic-release plugins for publishing a Firefox extension release
A semantic-release plugin for you to be able to easily publish Firefox Extensions using it's automated release.
Will update the version in the manifest, create a .xpi, zip your sources and submit everything for review, including semantic release notes.
Since Mozilla does not expose an API to do fully automated extension releases, runs a headless Chrome through Puppeteer to upload the files through the web form.
Verify the presence of the authentication (set via environment variables).
Write the correct version to the manifest.json and creates a xpi file of the whole dist folder.
xpiPath: Required, the filename of the xpi file.distFolder: Required, the folder that will be zipped.manifestPath: Optional, the path of the manifest inside the dist folder. Defaults to ${distFolder}/manifest.json.sourcesGlob: Optional, a glob pattern of source files that will be zipped and submitted for review. Defaults to all files in the cwd (**)sourcesGlobOptions: Optional, glob options passed to node-glob. Defaults to ignore node_modules, distFolder, xpiPath and sourcesArchivePath. You can use this for example if
{ dot: true })node_modules (set ignore: 'node_modules/!(privatepkg|privatepkg2)/**'). Make sure to still exclude sourcesArchivePath or the plugin may get stuck in an infinite loop trying to add the archive to itself!sourcesArchivePath: Optional, the file path for the zip with the source files that will be created. Defaults to ./sources.zip. Set this to null to not create a sources archive.Uploads the generated xpi file, a zip of the sources and submits it together with release notes.
xpiPath: Required, the filename of the xpi file.addOnSlug: Required, The URL slug of the extension, as in https://addons.mozilla.org/en-US/firefox/addon/SLUG/sourcesArchivePath: Optional, the file path for the zip with the source code that will be uploaded. Defaults to ./sources.zip. Set this to null to not upload a sources archive.notesToReviewer: Optional, notes to the reviewer that will be submitted for every version. For example, you could link to the source code on GitHub.The following environment variables have to be made available in your CI environment: FIREFOX_EMAIL, FIREFOX_PASSWORD and FIREFOX_TOTP_TOKEN.
It is recommended to create a bot account for them.
The account must have 2FA set up, with the 2FA secret saved in FIREFOX_TOTP_TOKEN.
Click on "Can't scan code?" when being shown the setup QR code to reveal the TOTP secret in plain text.
Make sure the account accepted the terms & agreements by visiting the submit page once (otherwise the release will fail).
Use semantic-release-chrome as part of verifyConditions, prepare and publish.
A basic config file example is available below:
{
"verifyConditions": ["semantic-release-firefox", "@semantic-release/github"],
"prepare": [
{
"path": "semantic-release-firefox",
"xpiPath": "my-extension.xpi",
"distFolder": "dist"
}
],
"publish": [
{
"path": "semantic-release-firefox",
"xpiPath": "my-extension.xpi",
"addOnSlug": "my-extension"
},
{
"path": "@semantic-release/github",
"assets": [
{
"path": "my-extension.xpi"
}
]
}
]
}
Tests for the publish plugin are running against a mock AMO server written with Express.
Run them with npm test.
FAQs
Set of semantic-release plugins for publishing a Firefox extension release
We found that semantic-release-firefox demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.

Product
Detect malware, unsafe data flows, and license issues in GitHub Actions with Socket’s new workflow scanning support.