Publish Skills #7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish Skills | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| tag: | |
| description: "リリースタグ(省略時は skill-v<YYYYMMDD-HHMM> UTC で自動生成)" | |
| required: false | |
| default: "" | |
| concurrency: | |
| group: publish-skills | |
| cancel-in-progress: false | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Ensure gh CLI >= 2.90 (skill subcommand available) | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| gh --version | head -n 1 | |
| if gh help | grep -q '^ skill:'; then | |
| echo "gh skill subcommand already available" | |
| exit 0 | |
| fi | |
| echo "Installing latest gh CLI from cli/cli releases" | |
| LATEST=$(gh api repos/cli/cli/releases/latest --jq .tag_name | sed 's/^v//') | |
| TARBALL="gh_${LATEST}_linux_amd64.tar.gz" | |
| curl -sSL -o "/tmp/${TARBALL}" "https://github.com/cli/cli/releases/download/v${LATEST}/${TARBALL}" | |
| tar -xzf "/tmp/${TARBALL}" -C /tmp | |
| sudo install -m 0755 "/tmp/gh_${LATEST}_linux_amd64/bin/gh" /usr/local/bin/gh | |
| hash -r | |
| gh --version | head -n 1 | |
| if ! gh help | grep -q '^ skill:'; then | |
| echo "::error::gh skill subcommand still not available after upgrade" | |
| exit 1 | |
| fi | |
| - name: Resolve release tag | |
| id: tag | |
| env: | |
| INPUT_TAG: ${{ inputs.tag }} | |
| run: | | |
| if [ -n "$INPUT_TAG" ]; then | |
| TAG="$INPUT_TAG" | |
| else | |
| TS=$(date -u +%Y%m%d-%H%M%S) | |
| TAG="skill-v${TS}" | |
| fi | |
| # prefix + 許可文字のみ: 改行・制御文字混入による GITHUB_OUTPUT インジェクションを防ぐ | |
| case "$TAG" in | |
| skill-v[0-9A-Za-z._-]*) ;; | |
| *) | |
| echo "::error::tag must match ^skill-v[0-9A-Za-z._-]+$ (got: $TAG)" | |
| exit 1 | |
| ;; | |
| esac | |
| case "$TAG" in | |
| *[!0-9A-Za-z.v_-]*) | |
| echo "::error::tag contains disallowed characters (got: $TAG)" | |
| exit 1 | |
| ;; | |
| esac | |
| printf 'tag=%s\n' "$TAG" >> "$GITHUB_OUTPUT" | |
| echo "Resolved tag: $TAG" | |
| - name: Dry-run validation | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| working-directory: .claude | |
| run: gh skill publish --dry-run | |
| - name: Publish skills | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| RELEASE_TAG: ${{ steps.tag.outputs.tag }} | |
| working-directory: .claude | |
| run: gh skill publish --tag "$RELEASE_TAG" |