Skip to content

Update actions/checkout action to v7 (#165) #32

Update actions/checkout action to v7 (#165)

Update actions/checkout action to v7 (#165) #32

Workflow file for this run

---
name: "Build & Deploy"
on:
push:
branches:
- main
release:
types:
- released
# Least-privilege at the top level; the publish jobs elevate id-token for npm provenance (OIDC)
permissions:
contents: read
concurrency:
group: ${{ github.ref_name }}-${{ github.workflow }}
cancel-in-progress: true
jobs:
deploy_beta:
name: Deploy to NPM (beta)
if: github.event_name == 'push'
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write # npm provenance (OIDC)
environment:
name: release
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version: "24.x"
registry-url: "https://registry.npmjs.org"
scope: nvuillam
- run: npm ci
- run: |
git config --global user.name nvuillam
git config --global user.email nicolas.vuillamy@gmail.com
- name: Bump beta prerelease version
run: |
BETAID=$(date '+%Y%m%d%H%M')
npm version prerelease --preid="beta${BETAID}"
shell: bash
- name: Publish beta package
run: npm publish --tag beta --provenance
deploy_release:
name: Deploy to NPM (release)
if: github.event_name == 'release'
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write # npm provenance (OIDC)
environment:
name: release
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
with:
persist-credentials: false
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6
with:
node-version: "24.x"
registry-url: "https://registry.npmjs.org"
scope: nvuillam
- run: npm ci
- run: |
git config --global user.name nvuillam
git config --global user.email nicolas.vuillamy@gmail.com
- name: Publish release package
run: npm publish --provenance