release-vendor-publish.yml 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114
  1. # Publish the vendored framework sequence to npm. This workflow is manual-only
  2. # (workflow_dispatch) and intentionally does not listen to pull_request or push:
  3. # publication must always be an explicit, reviewed act from a vendor-* tag, and
  4. # it must never appear as a PR check. It repacks the current tree before
  5. # publishing so the bytes uploaded are exactly what this dispatch produced.
  6. name: Release publish (vendor)
  7. on:
  8. workflow_dispatch:
  9. permissions:
  10. contents: read
  11. env:
  12. PRIMARY_NODE_VERSION: '24'
  13. DSH_TELEMETRY_DISABLED: '1'
  14. jobs:
  15. pack:
  16. name: Pack npm tarballs
  17. runs-on: ubuntu-24.04
  18. steps:
  19. # Complete history: the release scripts read tags.
  20. - uses: actions/checkout@v6
  21. with:
  22. fetch-depth: 0
  23. persist-credentials: false
  24. - uses: pnpm/action-setup@v4
  25. with:
  26. dest: ${{ runner.temp }}/setup-pnpm
  27. - uses: actions/setup-node@v6
  28. with:
  29. node-version: ${{ env.PRIMARY_NODE_VERSION }}
  30. - name: Configure pnpm store path
  31. id: pnpm-store
  32. run: |
  33. store_root="$HOME/.local/share/pnpm/store"
  34. echo "PNPM_CONFIG_STORE_DIR=$store_root" >> "$GITHUB_ENV"
  35. store_path=$(PNPM_CONFIG_STORE_DIR="$store_root" pnpm store path --silent)
  36. echo "path=$store_path" >> "$GITHUB_OUTPUT"
  37. - uses: actions/cache/restore@v4
  38. with:
  39. path: ${{ steps.pnpm-store.outputs.path }}
  40. key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
  41. restore-keys: |
  42. ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-
  43. - name: Install (immutable)
  44. run: pnpm install --frozen-lockfile
  45. - name: Verify release version
  46. env:
  47. RELEASE_PUBLISH: 'true'
  48. run: pnpm run release:verify --family vendor
  49. # The vendored packages publish their own sources and build outputs; the
  50. # host build produces what their manifests select.
  51. - name: Build
  52. run: pnpm run build:lib:host
  53. - name: Pack release tarballs
  54. run: pnpm run release:pack --family vendor --out dist/npm-vendor
  55. - name: Verify packed install
  56. run: pnpm run release:verify-packed-install --family vendor --from dist/npm-vendor
  57. - uses: actions/upload-artifact@v4
  58. with:
  59. name: vendor-npm-tarballs
  60. path: dist/npm-vendor/*
  61. if-no-files-found: error
  62. retention-days: 7
  63. publish:
  64. name: Publish to npm
  65. needs: pack
  66. runs-on: ubuntu-24.04
  67. environment: npm-publish
  68. concurrency:
  69. group: Release-publish
  70. cancel-in-progress: false
  71. permissions:
  72. contents: read
  73. steps:
  74. # Checkout and install carry the release scripts only; no build step.
  75. - uses: actions/checkout@v6
  76. with:
  77. persist-credentials: false
  78. - uses: pnpm/action-setup@v4
  79. with:
  80. dest: ${{ runner.temp }}/setup-pnpm
  81. - uses: actions/setup-node@v6
  82. with:
  83. node-version: ${{ env.PRIMARY_NODE_VERSION }}
  84. registry-url: https://registry.npmjs.org
  85. - name: Install (immutable, no package scripts)
  86. run: pnpm install --frozen-lockfile --ignore-scripts
  87. - uses: actions/download-artifact@v4
  88. with:
  89. name: vendor-npm-tarballs
  90. path: dist/npm-vendor
  91. - name: Publish tarballs
  92. env:
  93. NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
  94. run: pnpm run release:publish --family vendor --from dist/npm-vendor