format: say that a scope's variables are visible only within its in (… #24
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish tagged packages | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| inputs: | |
| dry-run: | |
| description: "Run npm publish with --dry-run" | |
| type: boolean | |
| default: true | |
| # bin/version.ts commits the bump as "Publish" with no "[skip ci]"; | |
| # adding one would silently stop this workflow from publishing. | |
| jobs: | |
| check: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| outputs: | |
| tagged: ${{ steps.tags.outputs.tagged }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| # Capture the tag list first: under `shell: bash` (which adds | |
| # `-o pipefail`) `grep -q` can kill `git` with SIGPIPE and turn | |
| # a MATCH into tagged=false. | |
| - id: tags | |
| run: | | |
| tags=$(git tag --points-at HEAD) | |
| if printf '%s\n' "$tags" | grep -q '^@ethdebug/'; then | |
| echo tagged=true >> "$GITHUB_OUTPUT" | |
| else | |
| echo tagged=false >> "$GITHUB_OUTPUT" | |
| fi | |
| publish: | |
| needs: check | |
| if: >- | |
| needs.check.outputs.tagged == 'true' || | |
| github.event_name == 'workflow_dispatch' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| permissions: | |
| contents: read | |
| id-token: write | |
| # cancel-in-progress only protects a job that has started. GitHub | |
| # still cancels a PENDING run in this group when a newer one | |
| # queues, so a Publish commit whose run shows "cancelled" must be | |
| # re-run from the Actions UI. | |
| concurrency: | |
| group: publish | |
| cancel-in-progress: false | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: yarn | |
| cache-dependency-path: yarn.lock | |
| - name: Use npm 11 (trusted publishing) | |
| run: npm install -g npm@11 | |
| - name: Install dependencies | |
| run: yarn install --frozen-lockfile | |
| - name: Run tests | |
| run: yarn test | |
| - name: Publish | |
| run: >- | |
| yarn tsx bin/publish-tagged.ts | |
| ${{ (github.event_name == 'workflow_dispatch' && inputs.dry-run) && '--dry-run' || '' }} |