-
Notifications
You must be signed in to change notification settings - Fork 0
138 lines (116 loc) · 4.33 KB
/
Copy pathrelease.yml
File metadata and controls
138 lines (116 loc) · 4.33 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
name: Release
on:
push:
branches: [main]
workflow_dispatch:
concurrency:
group: release
cancel-in-progress: false
jobs:
release:
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: write
issues: write
pull-requests: write
id-token: write
steps:
- uses: actions/checkout@v5
with:
fetch-depth: 0
- uses: actions/setup-node@v6
with:
node-version: "20"
registry-url: "https://registry.npmjs.org"
cache: "npm"
# Trusted publishing (OIDC) needs npm >= 11.5.1; Node 20 ships npm 10.
- name: Update npm for trusted publishing
run: npm install -g npm@11
- run: npm ci
- run: npm run build
- name: Get current version
id: current_version
run: echo "VERSION=$(node -p "require('./package.json').version")" >> $GITHUB_OUTPUT
- name: Check if version exists on npm
id: version_check
env:
VERSION: ${{ steps.current_version.outputs.VERSION }}
run: |
if npm view nex-code@$VERSION >/dev/null 2>&1; then
echo "VERSION_EXISTS=true" >> $GITHUB_OUTPUT
else
echo "VERSION_EXISTS=false" >> $GITHUB_OUTPUT
fi
# Auth via npm Trusted Publishing (OIDC): the job's id-token permission
# is exchanged for a short-lived publish credential — no NPM_TOKEN
# secret, nothing to expire, no 2FA/OTP prompt.
- name: Publish to npm
if: steps.version_check.outputs.VERSION_EXISTS == 'false'
run: npm publish --provenance --access public --ignore-scripts
- name: Generate release notes
if: always() && steps.version_check.outputs.VERSION_EXISTS == 'false'
id: release_notes
env:
VERSION: ${{ steps.current_version.outputs.VERSION }}
run: |
PREV_TAG=$(git describe --tags --abbrev=0 HEAD^ 2>/dev/null || echo "")
if [ -n "$PREV_TAG" ]; then
NOTES=$(git log ${PREV_TAG}..HEAD --pretty=format:"- %s" --no-merges)
else
NOTES=$(git log --pretty=format:"- %s" --no-merges -20)
fi
echo "NOTES<<EOF" >> $GITHUB_OUTPUT
echo "$NOTES" >> $GITHUB_OUTPUT
echo "EOF" >> $GITHUB_OUTPUT
- name: Create GitHub Release
if: always() && steps.version_check.outputs.VERSION_EXISTS == 'false'
uses: ncipollo/release-action@v1
with:
tag: v${{ steps.current_version.outputs.VERSION }}
name: Release v${{ steps.current_version.outputs.VERSION }}
body: |
## Changes in v${{ steps.current_version.outputs.VERSION }}
${{ steps.release_notes.outputs.NOTES }}
draft: false
prerelease: false
- name: Notify on publish failure
if: failure()
run: |
echo "::error::npm publish failed for version ${{ steps.current_version.outputs.VERSION }}"
echo "Check the Trusted Publisher config on npmjs.com (package nex-code -> Settings): repo hybridpicker/nex-code, workflow release.yml"
publish-vscode:
name: Build and attach VS Code Extension
runs-on: ubuntu-latest
needs: release
timeout-minutes: 15
if: needs.release.result == 'success'
permissions:
contents: write
steps:
- uses: actions/checkout@v5
- uses: actions/setup-node@v6
with:
node-version: "20"
cache: "npm"
- name: Install root deps
run: npm ci
- name: Install VS Code extension deps
run: cd vscode && npm ci
- name: Build VS Code extension
run: cd vscode && npm run build
- name: Package VS Code extension (.vsix)
run: cd vscode && npx @vscode/vsce package --no-dependencies --allow-missing-repository
- name: Get version
id: version
run: echo "VERSION=$(node -p "require('./package.json').version")" >> $GITHUB_OUTPUT
- name: Attach .vsix to GitHub Release
uses: softprops/action-gh-release@v2
with:
tag_name: v${{ steps.version.outputs.VERSION }}
files: vscode/*.vsix
- name: Publish to VS Code Marketplace
if: env.VSCE_PAT != ''
run: cd vscode && npx @vscode/vsce publish --no-dependencies --allow-missing-repository --packagePath *.vsix
env:
VSCE_PAT: ${{ secrets.VSCE_PAT }}