Skip to content

Merge pull request #80 from taraxvoid/release-please--branches--main-… #18

Merge pull request #80 from taraxvoid/release-please--branches--main-…

Merge pull request #80 from taraxvoid/release-please--branches--main-… #18

name: Release Please
# Maintains a standing "chore(release): X.Y.Z" PR against main, auto-updated
# as commits land. Merging it bumps package.json + CHANGELOG.md, pushes the
# vX.Y.Z tag and creates the GitHub release (all by release-please itself),
# then the publish job below pushes the tagged commit to npm. Same setup as
# rvnflt's release-please.yml.
#
# token is a GitHub App installation token, not the default GITHUB_TOKEN:
# events authored by GITHUB_TOKEN don't trigger other workflows, so the
# release PR would open without CI ever running on it. RELEASE_BOT_CLIENT_ID /
# RELEASE_BOT_APP_PRIVATE_KEY are org-level secrets shared with the sibling
# repos.
#
# npm publishing currently uses an NPM_TOKEN secret, not trusted publishing
# (see the publish steps); the trusted publisher entries on npmjs.com should
# still name this repo, this workflow file (release-please.yml) and the `npm`
# environment so it can switch back once npm supports immutable OIDC subjects.
on:
push:
branches: [main]
# Manual republish of an existing release's tag (e.g. after fixing npm
# trusted-publisher config); skips release-please and only runs `publish`.
workflow_dispatch:
inputs:
tag:
description: "Existing release tag to publish to npm (e.g. v0.7.0)"
required: true
type: string
permissions: {}
jobs:
release-please:
name: Release Please
if: github.event_name == 'push'
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: write
pull-requests: write
outputs:
release_created: ${{ steps.release.outputs.release_created }}
tag_name: ${{ steps.release.outputs.tag_name }}
steps:
- name: Generate App token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
client-id: ${{ secrets.RELEASE_BOT_CLIENT_ID }}
private-key: ${{ secrets.RELEASE_BOT_APP_PRIVATE_KEY }}
permission-contents: write
permission-pull-requests: write
- uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0
id: release
with:
token: ${{ steps.app-token.outputs.token }}
target-branch: main
config-file: release-please-config.json
manifest-file: .release-please-manifest.json
publish:
name: Publish to npm
needs: release-please
if: >-
!cancelled() &&
(needs.release-please.outputs.release_created == 'true' || github.event_name == 'workflow_dispatch')
runs-on: ubuntu-latest
timeout-minutes: 10
environment: npm
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.tag || needs.release-please.outputs.tag_name }}
persist-credentials: false
# Trusted publishing needs npm >= 11.5.1, which ships with Node 24.
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
registry-url: https://registry.npmjs.org
- name: Check package.json version matches tag
env:
TAG: ${{ inputs.tag || needs.release-please.outputs.tag_name }}
run: |
set -euo pipefail
PKG_VERSION=$(jq -r .version package.json)
if [ "v${PKG_VERSION}" != "$TAG" ]; then
echo "::error::package.json version ${PKG_VERSION} does not match tag ${TAG}." >&2
exit 1
fi
JSR_VERSION=$(jq -r .version jsr.json)
if [ "${JSR_VERSION}" != "${PKG_VERSION}" ]; then
echo "::error::jsr.json version ${JSR_VERSION} does not match package.json ${PKG_VERSION}." >&2
exit 1
fi
# JSR is linked to this repo so trusted publishing Just Works^TM
- name: Publish @taraxvoid/voidflow to JSR
run: |
set -euo pipefail
npm install --no-save --no-package-lock --ignore-scripts @playwright/test
npx --yes jsr publish
# Publishes with the NPM_TOKEN secret (granular token scoped to both
# packages, stored on the `npm` environment) as a stopgap: npm's trusted
# publishing rejects GitHub's immutable OIDC subject claims, which this
# repo can't opt out of (npm/cli#9969). Provenance still works via
# id-token: write. Once npm fixes that, delete the NPM_TOKEN secret and
# these NODE_AUTH_TOKEN lines to fall back to pure OIDC; the trusted
# publisher entries (this repo, release-please.yml, `npm` environment)
# are already configured on both packages.
- name: Publish @taraxvoid/voidflow to NPM (scoped canonical package)
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: npm publish
# Unscoped mirror of the same tarball, so `npm add -d voidflow` and
# `npx voidflow` work.
- name: Publish voidflow (unscoped mirror)
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
set -euo pipefail
npm pkg set name=voidflow
npm publish