Skip to content

chore(release): 2.0.2 #7

chore(release): 2.0.2

chore(release): 2.0.2 #7

Workflow file for this run

name: Publish
# Tag-triggered publish to npm, authenticated by npm's trusted publisher rather
# than a stored token. It runs only on a pushed v* tag, and only once a
# maintainer approves the npm-publish environment. Publishing therefore needs
# the trusted publisher registered on npmjs.com against this repository, this
# workflow filename and that environment; no NPM_TOKEN is involved.
on:
push:
tags: ['v*']
jobs:
publish:
runs-on: ubuntu-latest
# Required-reviewer environment: a pushed tag queues the publish until a
# maintainer approves the run, and npm's trusted publisher config pins to
# this environment name so no other workflow can mint a publish token.
environment: npm-publish
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 22
registry-url: https://registry.npmjs.org
cache: yarn
- name: Upgrade npm
# Trusted publishing (OIDC) needs npm >= 11.5.1; the Node 22 image
# ships npm 10.x.
run: npm install -g npm@latest
- name: Verify tag matches package version
run: |
version="$(node -p "require('./package.json').version")"
if [ "v$version" != "$GITHUB_REF_NAME" ]; then
echo "Tag $GITHUB_REF_NAME does not match package.json version $version" >&2
exit 1
fi
- name: Install
run: yarn install --frozen-lockfile
- name: Build
run: yarn run build
- name: Test
run: yarn run test
- name: Publish
# No NODE_AUTH_TOKEN: npm mints a short-lived credential from the OIDC
# token this job requests, against the trusted publisher npmjs.com pins
# to this repo, workflow and environment. Supplying a token instead
# takes the classic auth path, which demands an interactive OTP and so
# can never complete unattended.
run: npm publish --access public --provenance