Merge pull request #197 from TightknitAI/release-please--branches--ma… #160
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release Please | |
| on: | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| id-token: write | |
| jobs: | |
| release-please: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - uses: googleapis/release-please-action@v5 | |
| id: release | |
| with: | |
| config-file: release-please-config.json | |
| manifest-file: .release-please-manifest.json | |
| # Everything below runs only when release-please merges its PR and | |
| # creates a release. Publish-side gating is intentionally minimal: | |
| # lint + typecheck + build. The full test suite (incl. Playwright) | |
| # already ran in CI against the same commit before release-please | |
| # merged it to main, and re-installing Chromium on the npm-token- | |
| # bearing job widens the supply-chain surface for no security gain. | |
| - uses: actions/checkout@v6 | |
| if: ${{ steps.release.outputs.releases_created == 'true' }} | |
| - uses: ./.github/actions/setup | |
| if: ${{ steps.release.outputs.releases_created == 'true' }} | |
| - run: pnpm run lint | |
| if: ${{ steps.release.outputs.releases_created == 'true' }} | |
| - run: pnpm run typecheck | |
| if: ${{ steps.release.outputs.releases_created == 'true' }} | |
| - run: pnpm run build:clean | |
| if: ${{ steps.release.outputs.releases_created == 'true' }} | |
| # Trusted Publisher (OIDC) needs npm CLI >= 11.5.1; Node 22 ships | |
| # with npm 10.x. Run the modern CLI via `npx` from its separate | |
| # cache instead of `npm install -g npm@latest`, which races against | |
| # the running npm mid-install ("Cannot find module 'promise-retry'"). | |
| # npm 11+ also requires an explicit --tag for prereleases. | |
| - name: Publish to npm | |
| if: ${{ steps.release.outputs.releases_created == 'true' }} | |
| run: | | |
| version=$(node -p "require('./package.json').version") | |
| if [[ "$version" == *-* ]]; then | |
| tag="${version#*-}" | |
| tag="${tag%%.*}" | |
| npx -y npm@latest publish --provenance --access public --tag "$tag" | |
| else | |
| npx -y npm@latest publish --provenance --access public | |
| fi |