actions/checkout v4 -> v7, actions/setup-node v4 -> v7 and pnpm/action-setup v4 -> v6. Also bumps the two pins in .github/actions/setup-workspace, which dependabot's github-actions updater never proposed: `directory: /` scans .github/workflows only, so a composite action's own `uses:` lines are invisible to it. Left alone they would have kept the repo on setup-node v4 in every lane that goes through the composite — which is every lane except the checkout steps themselves.
118 lines
4.3 KiB
YAML
118 lines
4.3 KiB
YAML
name: Publish (CI)
|
|
|
|
run-name: "Publish · ${{ inputs.version || inputs.bump }}${{ inputs.dry_run && ' (dry-run)' || '' }}"
|
|
|
|
# All-in-CI release for @airshiplabs/cli: pick a bump (or an explicit version)
|
|
# and this bumps apps/cli/package.json, commits, tags cli-vX.Y.Z, pushes, and
|
|
# publishes — the CI equivalent of `make release` plus pushing the tag, with no
|
|
# local steps.
|
|
#
|
|
# Run it from your release/* branch: the version-bump commit lands there and
|
|
# reaches main through the normal release PR. branch-policy.yml is what makes
|
|
# that the only route in.
|
|
#
|
|
# Note: the cli-v* tag is pushed with GITHUB_TOKEN, which by design does NOT
|
|
# trigger release.yml — so this workflow publishes here, and the two lanes can
|
|
# never double-publish.
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
bump:
|
|
description: "Version bump (ignored if a version is given)"
|
|
type: choice
|
|
options: [patch, minor, major]
|
|
default: patch
|
|
version:
|
|
description: "Explicit version, e.g. 1.4.0 (overrides bump)"
|
|
type: string
|
|
default: ""
|
|
dry_run:
|
|
description: "Dry run — validate packaging only; no commit, tag, push or publish"
|
|
type: boolean
|
|
default: false
|
|
|
|
permissions:
|
|
contents: write # push the release commit + tag
|
|
id-token: write # npm provenance attestation
|
|
|
|
concurrency:
|
|
group: publish
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
publish:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
# Not the setup-workspace composite: this job needs registry-url, which
|
|
# is what writes the .npmrc that NODE_AUTH_TOKEN binds to.
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: pnpm
|
|
registry-url: "https://registry.npmjs.org"
|
|
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
- name: Compute the next version
|
|
id: ver
|
|
env:
|
|
BUMP: ${{ inputs.bump }}
|
|
VERSION: ${{ inputs.version }}
|
|
run: |
|
|
if [ -n "$VERSION" ]; then
|
|
NEXT=$(node scripts/next-version.mjs --version "$VERSION")
|
|
else
|
|
NEXT=$(node scripts/next-version.mjs --bump "$BUMP")
|
|
fi
|
|
echo "next=$NEXT" >> "$GITHUB_OUTPUT"
|
|
echo "tag=cli-v$NEXT" >> "$GITHUB_OUTPUT"
|
|
echo "::notice::Releasing @airshiplabs/cli v$NEXT (tag cli-v$NEXT)"
|
|
|
|
- name: Guard against an existing tag
|
|
run: |
|
|
if git rev-parse -q --verify "refs/tags/${{ steps.ver.outputs.tag }}" >/dev/null; then
|
|
echo "::error::Tag ${{ steps.ver.outputs.tag }} already exists."
|
|
exit 1
|
|
fi
|
|
|
|
- name: Bump apps/cli/package.json
|
|
run: |
|
|
node -e "const f='apps/cli/package.json';const p=require('./'+f);p.version='${{ steps.ver.outputs.next }}';require('fs').writeFileSync(f, JSON.stringify(p,null,2)+'\n');"
|
|
pnpm install --lockfile-only
|
|
|
|
# This step used to be `publish --dry-run`, which validated nothing:
|
|
# `pnpm publish` does not build the package (apps/cli has no prepack or
|
|
# prepare hook), so the dry run packed an empty tarball and exited 0.
|
|
# That is how v0.2.0 shipped with no dist/. Build explicitly, then pack
|
|
# for real and look inside.
|
|
- name: Build the CLI
|
|
run: pnpm turbo run build --filter=@airshiplabs/cli
|
|
|
|
- name: Validate packaging
|
|
run: bash scripts/verify-tarball.sh
|
|
|
|
- name: Commit, tag and push
|
|
if: ${{ inputs.dry_run == false }}
|
|
run: |
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
git add -A
|
|
# --no-verify skips the husky commit-msg and pre-push hooks. The
|
|
# pre-push hook blocks pushes to main, and commit-msg would reject
|
|
# nothing here, but both are pointless in CI.
|
|
git commit --no-verify -m "chore(release): cli v${{ steps.ver.outputs.next }}"
|
|
git tag -a "${{ steps.ver.outputs.tag }}" -m "${{ steps.ver.outputs.tag }}"
|
|
git push --no-verify origin "HEAD:${{ github.ref_name }}" --follow-tags
|
|
|
|
- name: Publish to npm
|
|
if: ${{ inputs.dry_run == false }}
|
|
run: pnpm --filter @airshiplabs/cli publish --access public --no-git-checks --provenance
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|