Repository navigation
122 lines (115 loc) · 4.21 KB
/
Copy pathrelease.yml
File metadata and controls
122 lines (115 loc) · 4.21 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
name: Release
on:
push:
branches:
- master
# Reset permissions and grant them per job, so `id-token: write` only exists on
# the job that actually publishes.
permissions: {}
concurrency: ${{ github.workflow }}-${{ github.ref }}
jobs:
select-mode:
name: Select mode
runs-on: ubuntu-latest
outputs:
mode: ${{ steps.select-mode.outputs.mode }}
publish-plan-artifact-id: ${{ steps.select-mode.outputs.publish-plan-artifact-id }}
permissions:
contents: read # to check out repo (actions/checkout)
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions/setup-node@v7
with:
node-version-file: ".nvmrc"
cache: "npm"
- run: npm ci
- name: Select Changesets mode
id: select-mode
uses: changesets/action/select-mode@v2
version:
name: Version packages
if: needs.select-mode.outputs.mode == 'version'
needs: select-mode
runs-on: ubuntu-latest
permissions:
contents: write # to commit version changes (changesets/action/version)
pull-requests: write # to open the "Version Packages" PR
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
# Full history so the changelog can link each entry to the commit that
# added its changeset; a shallow clone silently drops those links.
fetch-depth: 0
- uses: actions/setup-node@v7
with:
node-version-file: ".nvmrc"
package-manager-cache: false # avoid cache poisoning
- run: npm ci
- name: Version packages
uses: changesets/action/version@v2
with:
# Not just `changeset version` (the action's default): that bumps
# package.json and leaves package-lock.json pointing at the old
# version. The script refreshes the lockfile in the same commit.
script: npm run changeset:version
env:
# Not for the action itself -- this is for `@changesets/changelog-github`,
# which runs inside `changeset version` and queries the GraphQL API to
# turn each changeset's commit into a PR link. It throws without it.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
pack:
name: Pack tarball
if: needs.select-mode.outputs.mode == 'publish'
needs: select-mode
runs-on: ubuntu-latest
outputs:
pack-dir-artifact-id: ${{ steps.pack.outputs.pack-dir-artifact-id }}
permissions:
contents: read # to check out repo (actions/checkout)
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions/setup-node@v7
with:
node-version-file: ".nvmrc"
package-manager-cache: false # avoid cache poisoning
- run: npm ci
# NOTE: the library's `prepack` script copies README/LICENSE in and runs
# the build. `prepublishOnly` would NOT run here -- `npm pack` does not
# trigger it -- which is why that script is `prepack`.
- name: Pack packages
id: pack
uses: changesets/action/pack@v2
with:
publish-plan-artifact-id: ${{ needs.select-mode.outputs.publish-plan-artifact-id }}
publish:
name: Publish to npm
needs: pack
runs-on: ubuntu-latest
# Requires manual approval before anything reaches npm. Merging the
# "Version Packages" PR is already a human gate; this is a second one at the
# moment of publish, and it scopes `id-token: write` to an approved run.
environment: Production
permissions:
contents: write # to create git tags and GitHub releases
id-token: write # for npm trusted publishing (OIDC)
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions/setup-node@v7
with:
node-version-file: ".nvmrc"
registry-url: "https://registry.npmjs.org"
package-manager-cache: false # avoid cache poisoning
- name: Upgrade npm for OIDC
run: npm i -g npm@">=11.5.1"
- run: npm ci
- name: Publish packages
uses: changesets/action/publish@v2
with:
pack-dir-artifact-id: ${{ needs.pack.outputs.pack-dir-artifact-id }}