加固多工具本地用量扫描 #140
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: pnpm/action-setup@v5 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - name: Lint (typecheck all packages) | |
| run: pnpm -r lint | |
| - name: Build | |
| run: pnpm turbo build | |
| - name: Test (all packages) | |
| run: pnpm -r test | |
| deploy: | |
| needs: build | |
| if: github.ref == 'refs/heads/main' && github.event_name == 'push' | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: pnpm/action-setup@v5 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - name: Inject Cloudflare deployment config | |
| run: | | |
| if [ -z "$CLOUDFLARE_D1_DATABASE_ID" ]; then | |
| echo "::error::Missing GitHub secret CLOUDFLARE_D1_DATABASE_ID" | |
| exit 1 | |
| fi | |
| node - <<'NODE' | |
| const fs = require('node:fs'); | |
| const path = 'packages/worker/wrangler.jsonc'; | |
| let config = fs.readFileSync(path, 'utf8'); | |
| if (process.env.CLOUDFLARE_WORKER_NAME) { | |
| config = config.replace(/"name":\s*"[^"]+"/, `"name": "${process.env.CLOUDFLARE_WORKER_NAME}"`); | |
| } | |
| const databaseId = JSON.stringify(process.env.CLOUDFLARE_D1_DATABASE_ID); | |
| if (/"database_id":\s*"[^"]+"/.test(config)) { | |
| config = config.replace(/"database_id":\s*"[^"]+"/, `"database_id": ${databaseId}`); | |
| } else { | |
| config = config.replace(/("database_name":\s*"[^"]+")/, `$1,\n "database_id": ${databaseId}`); | |
| } | |
| fs.writeFileSync(path, config); | |
| NODE | |
| env: | |
| CLOUDFLARE_WORKER_NAME: ${{ secrets.CLOUDFLARE_WORKER_NAME }} | |
| CLOUDFLARE_D1_DATABASE_ID: ${{ secrets.CLOUDFLARE_D1_DATABASE_ID }} | |
| - name: Build Dashboard & Deploy Worker | |
| run: | | |
| pnpm --filter @aiusage/dashboard build | |
| cp -r packages/dashboard/dist packages/worker/public | |
| cd packages/worker | |
| npx wrangler d1 migrations apply aiusage-db --remote | |
| npx wrangler deploy | |
| env: | |
| CLOUDFLARE_API_TOKEN: ${{ secrets.CLOUDFLARE_API_TOKEN }} | |
| CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CLOUDFLARE_ACCOUNT_ID }} | |
| publish: | |
| needs: build | |
| if: github.ref == 'refs/heads/main' && github.event_name == 'push' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - uses: pnpm/action-setup@v5 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: 24 | |
| registry-url: https://registry.npmjs.org | |
| package-manager-cache: false | |
| - run: pnpm install --frozen-lockfile | |
| - name: Build publishable packages | |
| run: pnpm turbo build --filter @aiusage/pricing --filter @aiusage/cli | |
| - name: Publish packages (if versions are new) | |
| run: | | |
| publish_if_new() { | |
| local pkg_dir="$1" | |
| local allow_first_publish="${2:-true}" | |
| local pkg_name | |
| local local_version | |
| local npm_version | |
| pkg_name=$(node -p "require('./${pkg_dir}/package.json').name") | |
| local_version=$(node -p "require('./${pkg_dir}/package.json').version") | |
| if npm view "${pkg_name}@${local_version}" version >/dev/null 2>&1; then | |
| echo "${pkg_name} v${local_version} already published, skipping" | |
| else | |
| npm_version=$(npm view "${pkg_name}" version 2>/dev/null || echo "none") | |
| if [ "${npm_version}" = "none" ] && [ "${allow_first_publish}" != "true" ]; then | |
| echo "${pkg_name} has not been published before; skipping first publish until npm package permissions are created" | |
| return 0 | |
| fi | |
| echo "Publishing ${pkg_name}@${local_version} (npm latest is ${npm_version})" | |
| (cd "${pkg_dir}" && npm publish --access public) | |
| fi | |
| } | |
| publish_if_new packages/cli true | |
| publish_if_new packages/pricing false |