-
Notifications
You must be signed in to change notification settings - Fork 0
81 lines (76 loc) · 2.89 KB
/
Copy pathrelease.yml
File metadata and controls
81 lines (76 loc) · 2.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
name: Release
# On every push to main, changesets/action either:
# - opens (or updates) a "Version Packages" PR when there are pending
# changesets in .changeset/, or
# - publishes every package whose version is not on npm yet, once that PR
# has been merged, and pushes the git tags.
on:
push:
branches: [main]
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
permissions:
# npm trusted publishing (OIDC) and provenance attestations.
id-token: write
# Push the version commit, the git tags and GitHub releases.
contents: write
# Open and update the "Version Packages" PR.
pull-requests: write
jobs:
release:
name: Version Or Publish
runs-on: ubuntu-latest
# Never run in forks.
if: github.repository == 'lnreader/cli'
steps:
- name: Check Out Repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set Up pnpm
uses: pnpm/action-setup@v4
- name: Set Up Node.js
uses: actions/setup-node@v4
with:
node-version: 24
cache: pnpm
registry-url: https://registry.npmjs.org
# Trusted publishing needs npm 11.5.1 or newer.
- name: Update npm
run: npm install -g npm@latest
- name: Install Dependencies
run: pnpm install --frozen-lockfile
- name: Build
run: pnpm build
- name: Pack Smoke Test
run: pnpm pack:check
# Publishing uses npm trusted publishing (OIDC): no NPM_TOKEN secret.
# npm exchanges this job's OIDC token for a short-lived publish token
# and attaches a provenance attestation automatically.
#
# One-time setup on npmjs.com, for EACH package (@lnreader/cli,
# @lnreader/plugin-runtime, @lnreader/cli-browser):
# Package page -> Settings -> Trusted Publisher -> GitHub Actions
# Organization or user: lnreader
# Repository: cli
# Workflow filename: release.yml
# Environment: (leave empty)
# A trusted publisher can only be added once the package exists on npm,
# so the very first publish of each package uses a temporary granular
# token instead; see RELEASING.md.
- name: Create Version PR Or Publish
uses: changesets/action@v1
with:
version: pnpm changeset version
publish: pnpm changeset publish
title: 'chore: Version Packages'
commit: 'chore: Version Packages'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Fallback for the first publish only (see RELEASING.md): add a
# granular token scoped to @lnreader as the NPM_TOKEN repository
# secret, uncomment both lines, publish, then revoke the token,
# delete the secret and comment these out again.
# NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
# NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}