Merge pull request #80 from taraxvoid/release-please--branches--main-… #18
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release Please | |
| # Maintains a standing "chore(release): X.Y.Z" PR against main, auto-updated | |
| # as commits land. Merging it bumps package.json + CHANGELOG.md, pushes the | |
| # vX.Y.Z tag and creates the GitHub release (all by release-please itself), | |
| # then the publish job below pushes the tagged commit to npm. Same setup as | |
| # rvnflt's release-please.yml. | |
| # | |
| # token is a GitHub App installation token, not the default GITHUB_TOKEN: | |
| # events authored by GITHUB_TOKEN don't trigger other workflows, so the | |
| # release PR would open without CI ever running on it. RELEASE_BOT_CLIENT_ID / | |
| # RELEASE_BOT_APP_PRIVATE_KEY are org-level secrets shared with the sibling | |
| # repos. | |
| # | |
| # npm publishing currently uses an NPM_TOKEN secret, not trusted publishing | |
| # (see the publish steps); the trusted publisher entries on npmjs.com should | |
| # still name this repo, this workflow file (release-please.yml) and the `npm` | |
| # environment so it can switch back once npm supports immutable OIDC subjects. | |
| on: | |
| push: | |
| branches: [main] | |
| # Manual republish of an existing release's tag (e.g. after fixing npm | |
| # trusted-publisher config); skips release-please and only runs `publish`. | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: "Existing release tag to publish to npm (e.g. v0.7.0)" | |
| required: true | |
| type: string | |
| permissions: {} | |
| jobs: | |
| release-please: | |
| name: Release Please | |
| if: github.event_name == 'push' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| outputs: | |
| release_created: ${{ steps.release.outputs.release_created }} | |
| tag_name: ${{ steps.release.outputs.tag_name }} | |
| steps: | |
| - name: Generate App token | |
| id: app-token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0 | |
| with: | |
| client-id: ${{ secrets.RELEASE_BOT_CLIENT_ID }} | |
| private-key: ${{ secrets.RELEASE_BOT_APP_PRIVATE_KEY }} | |
| permission-contents: write | |
| permission-pull-requests: write | |
| - uses: googleapis/release-please-action@45996ed1f6d02564a971a2fa1b5860e934307cf7 # v5.0.0 | |
| id: release | |
| with: | |
| token: ${{ steps.app-token.outputs.token }} | |
| target-branch: main | |
| config-file: release-please-config.json | |
| manifest-file: .release-please-manifest.json | |
| publish: | |
| name: Publish to npm | |
| needs: release-please | |
| if: >- | |
| !cancelled() && | |
| (needs.release-please.outputs.release_created == 'true' || github.event_name == 'workflow_dispatch') | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| environment: npm | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ inputs.tag || needs.release-please.outputs.tag_name }} | |
| persist-credentials: false | |
| # Trusted publishing needs npm >= 11.5.1, which ships with Node 24. | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 24 | |
| registry-url: https://registry.npmjs.org | |
| - name: Check package.json version matches tag | |
| env: | |
| TAG: ${{ inputs.tag || needs.release-please.outputs.tag_name }} | |
| run: | | |
| set -euo pipefail | |
| PKG_VERSION=$(jq -r .version package.json) | |
| if [ "v${PKG_VERSION}" != "$TAG" ]; then | |
| echo "::error::package.json version ${PKG_VERSION} does not match tag ${TAG}." >&2 | |
| exit 1 | |
| fi | |
| JSR_VERSION=$(jq -r .version jsr.json) | |
| if [ "${JSR_VERSION}" != "${PKG_VERSION}" ]; then | |
| echo "::error::jsr.json version ${JSR_VERSION} does not match package.json ${PKG_VERSION}." >&2 | |
| exit 1 | |
| fi | |
| # JSR is linked to this repo so trusted publishing Just Works^TM | |
| - name: Publish @taraxvoid/voidflow to JSR | |
| run: | | |
| set -euo pipefail | |
| npm install --no-save --no-package-lock --ignore-scripts @playwright/test | |
| npx --yes jsr publish | |
| # Publishes with the NPM_TOKEN secret (granular token scoped to both | |
| # packages, stored on the `npm` environment) as a stopgap: npm's trusted | |
| # publishing rejects GitHub's immutable OIDC subject claims, which this | |
| # repo can't opt out of (npm/cli#9969). Provenance still works via | |
| # id-token: write. Once npm fixes that, delete the NPM_TOKEN secret and | |
| # these NODE_AUTH_TOKEN lines to fall back to pure OIDC; the trusted | |
| # publisher entries (this repo, release-please.yml, `npm` environment) | |
| # are already configured on both packages. | |
| - name: Publish @taraxvoid/voidflow to NPM (scoped canonical package) | |
| env: | |
| NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} | |
| run: npm publish | |
| # Unscoped mirror of the same tarball, so `npm add -d voidflow` and | |
| # `npx voidflow` work. | |
| - name: Publish voidflow (unscoped mirror) | |
| env: | |
| NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} | |
| run: | | |
| set -euo pipefail | |
| npm pkg set name=voidflow | |
| npm publish | |