| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114 |
- # Publish the vendored framework sequence to npm. This workflow is manual-only
- # (workflow_dispatch) and intentionally does not listen to pull_request or push:
- # publication must always be an explicit, reviewed act from a vendor-* tag, and
- # it must never appear as a PR check. It repacks the current tree before
- # publishing so the bytes uploaded are exactly what this dispatch produced.
- name: Release publish (vendor)
- on:
- workflow_dispatch:
- permissions:
- contents: read
- env:
- PRIMARY_NODE_VERSION: '24'
- DSH_TELEMETRY_DISABLED: '1'
- jobs:
- pack:
- name: Pack npm tarballs
- runs-on: ubuntu-24.04
- steps:
- # Complete history: the release scripts read tags.
- - uses: actions/checkout@v6
- with:
- fetch-depth: 0
- persist-credentials: false
- - uses: pnpm/action-setup@v4
- with:
- dest: ${{ runner.temp }}/setup-pnpm
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ env.PRIMARY_NODE_VERSION }}
- - name: Configure pnpm store path
- id: pnpm-store
- run: |
- store_root="$HOME/.local/share/pnpm/store"
- echo "PNPM_CONFIG_STORE_DIR=$store_root" >> "$GITHUB_ENV"
- store_path=$(PNPM_CONFIG_STORE_DIR="$store_root" pnpm store path --silent)
- echo "path=$store_path" >> "$GITHUB_OUTPUT"
- - uses: actions/cache/restore@v4
- with:
- path: ${{ steps.pnpm-store.outputs.path }}
- key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}
- restore-keys: |
- ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-
- - name: Install (immutable)
- run: pnpm install --frozen-lockfile
- - name: Verify release version
- env:
- RELEASE_PUBLISH: 'true'
- run: pnpm run release:verify --family vendor
- # The vendored packages publish their own sources and build outputs; the
- # host build produces what their manifests select.
- - name: Build
- run: pnpm run build:lib:host
- - name: Pack release tarballs
- run: pnpm run release:pack --family vendor --out dist/npm-vendor
- - name: Verify packed install
- run: pnpm run release:verify-packed-install --family vendor --from dist/npm-vendor
- - uses: actions/upload-artifact@v4
- with:
- name: vendor-npm-tarballs
- path: dist/npm-vendor/*
- if-no-files-found: error
- retention-days: 7
- publish:
- name: Publish to npm
- needs: pack
- runs-on: ubuntu-24.04
- environment: npm-publish
- concurrency:
- group: Release-publish
- cancel-in-progress: false
- permissions:
- contents: read
- steps:
- # Checkout and install carry the release scripts only; no build step.
- - uses: actions/checkout@v6
- with:
- persist-credentials: false
- - uses: pnpm/action-setup@v4
- with:
- dest: ${{ runner.temp }}/setup-pnpm
- - uses: actions/setup-node@v6
- with:
- node-version: ${{ env.PRIMARY_NODE_VERSION }}
- registry-url: https://registry.npmjs.org
- - name: Install (immutable, no package scripts)
- run: pnpm install --frozen-lockfile --ignore-scripts
- - uses: actions/download-artifact@v4
- with:
- name: vendor-npm-tarballs
- path: dist/npm-vendor
- - name: Publish tarballs
- env:
- NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- run: pnpm run release:publish --family vendor --from dist/npm-vendor
|