ci(release): add manual npm republish and temporary OIDC claim debug … #9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release Please | |
| # Maintains a standing "chore(release): X.Y.Z" PR against main, auto-updated | |
| # as commits land. Merging it bumps package.json + CHANGELOG.md, pushes the | |
| # vX.Y.Z tag and creates the GitHub release (all by release-please itself), | |
| # then the publish job below pushes the tagged commit to npm. Same setup as | |
| # rvnflt's release-please.yml. | |
| # | |
| # token is a GitHub App installation token, not the default GITHUB_TOKEN: | |
| # events authored by GITHUB_TOKEN don't trigger other workflows, so the | |
| # release PR would open without CI ever running on it. RELEASE_BOT_CLIENT_ID / | |
| # RELEASE_BOT_APP_PRIVATE_KEY are org-level secrets shared with the sibling | |
| # repos. | |
| # | |
| # The npm trusted publisher on npmjs.com must name this repo, this workflow | |
| # file (release-please.yml) and the `npm` environment. | |
| on: | |
| push: | |
| branches: [main] | |
| # Manual republish of an existing release's tag (e.g. after fixing npm | |
| # trusted-publisher config); skips release-please and only runs `publish`. | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: "Existing release tag to publish to npm (e.g. v0.7.0)" | |
| required: true | |
| type: string | |
| permissions: {} | |
| jobs: | |
| release-please: | |
| name: Release Please | |
| if: github.event_name == 'push' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| outputs: | |
| release_created: ${{ steps.release.outputs.release_created }} | |
| tag_name: ${{ steps.release.outputs.tag_name }} | |
| steps: | |
| - name: Generate App token | |
| id: app-token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 | |
| with: | |
| client-id: ${{ secrets.RELEASE_BOT_CLIENT_ID }} | |
| private-key: ${{ secrets.RELEASE_BOT_APP_PRIVATE_KEY }} | |
| permission-contents: write | |
| permission-pull-requests: write | |
| - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 | |
| id: release | |
| with: | |
| token: ${{ steps.app-token.outputs.token }} | |
| target-branch: main | |
| config-file: release-please-config.json | |
| manifest-file: .release-please-manifest.json | |
| publish: | |
| name: Publish to npm | |
| needs: release-please | |
| if: >- | |
| !cancelled() && | |
| (needs.release-please.outputs.release_created == 'true' || github.event_name == 'workflow_dispatch') | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| environment: npm | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ inputs.tag || needs.release-please.outputs.tag_name }} | |
| persist-credentials: false | |
| # Trusted publishing needs npm >= 11.5.1, which ships with Node 24. | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 | |
| registry-url: https://registry.npmjs.org | |
| - name: Check package.json version matches tag | |
| env: | |
| TAG: ${{ inputs.tag || needs.release-please.outputs.tag_name }} | |
| run: | | |
| set -euo pipefail | |
| PKG_VERSION=$(jq -r .version package.json) | |
| if [ "v${PKG_VERSION}" != "$TAG" ]; then | |
| echo "::error::package.json version ${PKG_VERSION} does not match tag ${TAG}." >&2 | |
| exit 1 | |
| fi | |
| # TEMPORARY: print the OIDC claims npm will match against the trusted | |
| # publisher config (payload only, no secrets). Remove once publishing works. | |
| - name: Debug OIDC claims | |
| run: | | |
| set -euo pipefail | |
| npm --version | |
| tok=$(curl -sS -H "Authorization: bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" "$ACTIONS_ID_TOKEN_REQUEST_URL&audience=npm:registry.npmjs.org" | jq -r .value) | |
| p=$(cut -d. -f2 <<<"$tok" | tr '_-' '/+') | |
| while [ $((${#p} % 4)) -ne 0 ]; do p="${p}="; done | |
| base64 -d <<<"$p" | jq '{sub,repository,repository_owner,repository_id,repository_owner_id,job_workflow_ref,workflow_ref,environment,ref,event_name,runner_environment}' | |
| - name: Publish @taraxvoid/voidflow | |
| run: npm publish | |
| # Unscoped mirror of the same tarball, so `bun add -d voidflow` and | |
| # `bunx voidflow` work. Needs its own trusted publisher entry on npmjs.com | |
| # (same repo, workflow file and environment as above). | |
| - name: Publish voidflow (unscoped mirror) | |
| run: | | |
| set -euo pipefail | |
| npm pkg set name=voidflow | |
| npm publish |