Files
airship/.github/workflows/release.yml
T
Nayan 24215ecbf9 ci(deps): bump the github-actions group with 3 updates
actions/checkout v4 -> v7, actions/setup-node v4 -> v7 and
pnpm/action-setup v4 -> v6.

Also bumps the two pins in .github/actions/setup-workspace, which
dependabot's github-actions updater never proposed: `directory: /`
scans .github/workflows only, so a composite action's own `uses:`
lines are invisible to it. Left alone they would have kept the repo
on setup-node v4 in every lane that goes through the composite —
which is every lane except the checkout steps themselves.
2026-08-11 05:27:08 +05:30

63 lines
2.2 KiB
YAML

name: Release
run-name: "Release · ${{ github.ref_name }}"
# Publishes @airshiplabs/cli to npm when a cli-v* tag is pushed. Cut the release
# with `make release` (bumps apps/cli/package.json, commits, tags) then push the
# tag — see scripts/release.sh.
#
# This lane is for locally-cut releases only. publish.yml pushes its tag with
# GITHUB_TOKEN, and GitHub does not fire workflows from GITHUB_TOKEN-authored
# pushes, so a CI-cut release never lands here and the two never both publish.
on:
push:
tags: ["cli-v*"]
permissions:
contents: read
id-token: write # npm provenance attestation
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
node-version-file: .nvmrc
cache: pnpm
registry-url: "https://registry.npmjs.org"
- run: pnpm install --frozen-lockfile
- name: Verify the tag matches apps/cli's version
run: |
TAG="${GITHUB_REF_NAME#cli-v}"
PKG=$(node -p "require('./apps/cli/package.json').version")
if [ "$TAG" != "$PKG" ]; then
echo "::error::Tag cli-v$TAG does not match @airshiplabs/cli version $PKG (cut releases with 'make release')"
exit 1
fi
# `pnpm publish` does NOT build the package. apps/cli has no prepack,
# prepare or prepublishOnly hook, and the npm lifecycle never invokes a
# plain `build` script — so nothing here builds unless this step does.
# Skip it and `files: ["dist"]` matches an empty directory, npm reports a
# clean publish, and the tarball ships a package.json and a LICENSE.
# v0.2.0 went out exactly that way.
- name: Build the CLI
run: pnpm turbo run build --filter=@airshiplabs/cli
# Packs for real and looks inside. `publish --dry-run` cannot stand in
# here — it packs the same empty tarball and exits 0.
- name: Verify the tarball is complete
run: bash scripts/verify-tarball.sh
- name: Publish to npm
run: pnpm --filter @airshiplabs/cli publish --access public --no-git-checks --provenance
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}