diff --git a/.github/workflows/ci.yml b/.gitea/workflows/ci.yml similarity index 66% rename from .github/workflows/ci.yml rename to .gitea/workflows/ci.yml index 1c9bdd0..189cdd8 100644 --- a/.github/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -20,15 +20,10 @@ jobs: - run: npm run build - run: npm run check - run: npm run test:ci - - name: Upload coverage - uses: actions/upload-artifact@v4 - with: - name: coverage - path: coverage - # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced on - # the PR for visibility, but must never gate a merge — so continue-on-error and - # intentionally NOT in `publish`'s `needs`. + # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in + # the Actions tab for visibility, but must never gate a merge — so + # continue-on-error and intentionally NOT in `publish`'s `needs`. maintain: runs-on: ubuntu-latest continue-on-error: true @@ -42,10 +37,19 @@ jobs: - run: npm run maintain publish: - if: startsWith(github.ref, 'refs/tags/') + if: startsWith(gitea.ref, 'refs/tags/') needs: build runs-on: ubuntu-latest steps: + # Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN + # is unset, so a tag push never silently no-ops (or half-publishes). Set + # NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets. + - name: Assert NPM_TOKEN is configured + run: | + if [ -z "${{ secrets.NPM_TOKEN }}" ]; then + echo "::error::NPM_TOKEN secret is not set — refusing to publish." + exit 1 + fi - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: