actions/checkout v4 -> v7, actions/setup-node v4 -> v7 and pnpm/action-setup v4 -> v6. Also bumps the two pins in .github/actions/setup-workspace, which dependabot's github-actions updater never proposed: `directory: /` scans .github/workflows only, so a composite action's own `uses:` lines are invisible to it. Left alone they would have kept the repo on setup-node v4 in every lane that goes through the composite — which is every lane except the checkout steps themselves.
63 lines
2.2 KiB
YAML
63 lines
2.2 KiB
YAML
name: Release
|
|
|
|
run-name: "Release · ${{ github.ref_name }}"
|
|
|
|
# Publishes @airshiplabs/cli to npm when a cli-v* tag is pushed. Cut the release
|
|
# with `make release` (bumps apps/cli/package.json, commits, tags) then push the
|
|
# tag — see scripts/release.sh.
|
|
#
|
|
# This lane is for locally-cut releases only. publish.yml pushes its tag with
|
|
# GITHUB_TOKEN, and GitHub does not fire workflows from GITHUB_TOKEN-authored
|
|
# pushes, so a CI-cut release never lands here and the two never both publish.
|
|
on:
|
|
push:
|
|
tags: ["cli-v*"]
|
|
|
|
permissions:
|
|
contents: read
|
|
id-token: write # npm provenance attestation
|
|
|
|
jobs:
|
|
publish:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- uses: actions/setup-node@v7
|
|
with:
|
|
node-version-file: .nvmrc
|
|
cache: pnpm
|
|
registry-url: "https://registry.npmjs.org"
|
|
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
- name: Verify the tag matches apps/cli's version
|
|
run: |
|
|
TAG="${GITHUB_REF_NAME#cli-v}"
|
|
PKG=$(node -p "require('./apps/cli/package.json').version")
|
|
if [ "$TAG" != "$PKG" ]; then
|
|
echo "::error::Tag cli-v$TAG does not match @airshiplabs/cli version $PKG (cut releases with 'make release')"
|
|
exit 1
|
|
fi
|
|
|
|
# `pnpm publish` does NOT build the package. apps/cli has no prepack,
|
|
# prepare or prepublishOnly hook, and the npm lifecycle never invokes a
|
|
# plain `build` script — so nothing here builds unless this step does.
|
|
# Skip it and `files: ["dist"]` matches an empty directory, npm reports a
|
|
# clean publish, and the tarball ships a package.json and a LICENSE.
|
|
# v0.2.0 went out exactly that way.
|
|
- name: Build the CLI
|
|
run: pnpm turbo run build --filter=@airshiplabs/cli
|
|
|
|
# Packs for real and looks inside. `publish --dry-run` cannot stand in
|
|
# here — it packs the same empty tarball and exits 0.
|
|
- name: Verify the tarball is complete
|
|
run: bash scripts/verify-tarball.sh
|
|
|
|
- name: Publish to npm
|
|
run: pnpm --filter @airshiplabs/cli publish --access public --no-git-checks --provenance
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|