chore(release): 2.0.2 #7
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish | |
| # Tag-triggered publish to npm, authenticated by npm's trusted publisher rather | |
| # than a stored token. It runs only on a pushed v* tag, and only once a | |
| # maintainer approves the npm-publish environment. Publishing therefore needs | |
| # the trusted publisher registered on npmjs.com against this repository, this | |
| # workflow filename and that environment; no NPM_TOKEN is involved. | |
| on: | |
| push: | |
| tags: ['v*'] | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-latest | |
| # Required-reviewer environment: a pushed tag queues the publish until a | |
| # maintainer approves the run, and npm's trusted publisher config pins to | |
| # this environment name so no other workflow can mint a publish token. | |
| environment: npm-publish | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| registry-url: https://registry.npmjs.org | |
| cache: yarn | |
| - name: Upgrade npm | |
| # Trusted publishing (OIDC) needs npm >= 11.5.1; the Node 22 image | |
| # ships npm 10.x. | |
| run: npm install -g npm@latest | |
| - name: Verify tag matches package version | |
| run: | | |
| version="$(node -p "require('./package.json').version")" | |
| if [ "v$version" != "$GITHUB_REF_NAME" ]; then | |
| echo "Tag $GITHUB_REF_NAME does not match package.json version $version" >&2 | |
| exit 1 | |
| fi | |
| - name: Install | |
| run: yarn install --frozen-lockfile | |
| - name: Build | |
| run: yarn run build | |
| - name: Test | |
| run: yarn run test | |
| - name: Publish | |
| # No NODE_AUTH_TOKEN: npm mints a short-lived credential from the OIDC | |
| # token this job requests, against the trusted publisher npmjs.com pins | |
| # to this repo, workflow and environment. Supplying a token instead | |
| # takes the classic auth path, which demands an interactive OTP and so | |
| # can never complete unattended. | |
| run: npm publish --access public --provenance |