release: v4.0.0-alpha.28 #29
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release | |
| # Publishes to npm when a version tag is pushed (v4.0.0, v4.1.0-alpha.1, …), | |
| # then creates the matching GitHub Release with auto-generated notes. | |
| # Requires the NPM_TOKEN repository secret (npm "Automation" token: repo | |
| # Settings → Secrets and variables → Actions → New repository secret). | |
| # The tag must match package.json's version — the guard below enforces it. | |
| on: | |
| push: | |
| tags: ['v*'] | |
| permissions: | |
| contents: read | |
| id-token: write # npm provenance attestation | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: pnpm/action-setup@v6 # version comes from package.json packageManager | |
| - uses: actions/setup-node@v7 | |
| with: | |
| node-version: 22 | |
| registry-url: https://registry.npmjs.org | |
| - name: Test gate | |
| run: pnpm test | |
| - name: Tag ↔ package.json version guard | |
| env: | |
| REF_NAME: ${{ github.ref_name }} | |
| run: | | |
| PKG_VERSION=$(node -p "require('./package.json').version") | |
| if [ "v$PKG_VERSION" != "$REF_NAME" ]; then | |
| echo "tag $REF_NAME does not match package.json version v$PKG_VERSION" >&2 | |
| exit 1 | |
| fi | |
| - name: Publish to npm registry (with provenance) | |
| env: | |
| NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} | |
| run: | | |
| # prereleases (…-alpha.N) go to the 'next' dist-tag; releases to 'latest' | |
| case "$(node -p "require('./package.json').version")" in | |
| *-*) pnpm publish --provenance --access public --tag next --no-git-checks ;; | |
| *) pnpm publish --provenance --access public --no-git-checks ;; | |
| esac | |
| # Runs only after a successful npm publish, so a Release object never exists | |
| # for a version that didn't actually ship. | |
| github-release: | |
| needs: publish | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Create GitHub Release (auto-generated notes) | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| # mirror the npm dist-tag split: prereleases get the badge and are | |
| # excluded from releases/latest; stable versions become Latest | |
| case "$GITHUB_REF_NAME" in | |
| *-*) gh release create "$GITHUB_REF_NAME" --verify-tag --generate-notes --prerelease ;; | |
| *) gh release create "$GITHUB_REF_NAME" --verify-tag --generate-notes --latest ;; | |
| esac |