Files
airship/.github/workflows/publish.yml
T
Nayan 24215ecbf9 ci(deps): bump the github-actions group with 3 updates
actions/checkout v4 -> v7, actions/setup-node v4 -> v7 and
pnpm/action-setup v4 -> v6.

Also bumps the two pins in .github/actions/setup-workspace, which
dependabot's github-actions updater never proposed: `directory: /`
scans .github/workflows only, so a composite action's own `uses:`
lines are invisible to it. Left alone they would have kept the repo
on setup-node v4 in every lane that goes through the composite —
which is every lane except the checkout steps themselves.
2026-08-11 05:27:08 +05:30

118 lines
4.3 KiB
YAML

name: Publish (CI)
run-name: "Publish · ${{ inputs.version || inputs.bump }}${{ inputs.dry_run && ' (dry-run)' || '' }}"
# All-in-CI release for @airshiplabs/cli: pick a bump (or an explicit version)
# and this bumps apps/cli/package.json, commits, tags cli-vX.Y.Z, pushes, and
# publishes — the CI equivalent of `make release` plus pushing the tag, with no
# local steps.
#
# Run it from your release/* branch: the version-bump commit lands there and
# reaches main through the normal release PR. branch-policy.yml is what makes
# that the only route in.
#
# Note: the cli-v* tag is pushed with GITHUB_TOKEN, which by design does NOT
# trigger release.yml — so this workflow publishes here, and the two lanes can
# never double-publish.
on:
workflow_dispatch:
inputs:
bump:
description: "Version bump (ignored if a version is given)"
type: choice
options: [patch, minor, major]
default: patch
version:
description: "Explicit version, e.g. 1.4.0 (overrides bump)"
type: string
default: ""
dry_run:
description: "Dry run — validate packaging only; no commit, tag, push or publish"
type: boolean
default: false
permissions:
contents: write # push the release commit + tag
id-token: write # npm provenance attestation
concurrency:
group: publish
cancel-in-progress: false
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: pnpm/action-setup@v6
# Not the setup-workspace composite: this job needs registry-url, which
# is what writes the .npmrc that NODE_AUTH_TOKEN binds to.
- uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
cache: pnpm
registry-url: "https://registry.npmjs.org"
- run: pnpm install --frozen-lockfile
- name: Compute the next version
id: ver
env:
BUMP: ${{ inputs.bump }}
VERSION: ${{ inputs.version }}
run: |
if [ -n "$VERSION" ]; then
NEXT=$(node scripts/next-version.mjs --version "$VERSION")
else
NEXT=$(node scripts/next-version.mjs --bump "$BUMP")
fi
echo "next=$NEXT" >> "$GITHUB_OUTPUT"
echo "tag=cli-v$NEXT" >> "$GITHUB_OUTPUT"
echo "::notice::Releasing @airshiplabs/cli v$NEXT (tag cli-v$NEXT)"
- name: Guard against an existing tag
run: |
if git rev-parse -q --verify "refs/tags/${{ steps.ver.outputs.tag }}" >/dev/null; then
echo "::error::Tag ${{ steps.ver.outputs.tag }} already exists."
exit 1
fi
- name: Bump apps/cli/package.json
run: |
node -e "const f='apps/cli/package.json';const p=require('./'+f);p.version='${{ steps.ver.outputs.next }}';require('fs').writeFileSync(f, JSON.stringify(p,null,2)+'\n');"
pnpm install --lockfile-only
# This step used to be `publish --dry-run`, which validated nothing:
# `pnpm publish` does not build the package (apps/cli has no prepack or
# prepare hook), so the dry run packed an empty tarball and exited 0.
# That is how v0.2.0 shipped with no dist/. Build explicitly, then pack
# for real and look inside.
- name: Build the CLI
run: pnpm turbo run build --filter=@airshiplabs/cli
- name: Validate packaging
run: bash scripts/verify-tarball.sh
- name: Commit, tag and push
if: ${{ inputs.dry_run == false }}
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add -A
# --no-verify skips the husky commit-msg and pre-push hooks. The
# pre-push hook blocks pushes to main, and commit-msg would reject
# nothing here, but both are pointless in CI.
git commit --no-verify -m "chore(release): cli v${{ steps.ver.outputs.next }}"
git tag -a "${{ steps.ver.outputs.tag }}" -m "${{ steps.ver.outputs.tag }}"
git push --no-verify origin "HEAD:${{ github.ref_name }}" --follow-tags
- name: Publish to npm
if: ${{ inputs.dry_run == false }}
run: pnpm --filter @airshiplabs/cli publish --access public --no-git-checks --provenance
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}