♻️ Port CI workflow from GitHub Actions to Gitea Actions
The runner now lives on Gitea; move the workflow to .gitea/workflows/ and delete the stale .github copy (Gitea ignores .github/, so it's drift bait). Use the native gitea.ref context for the tag gate; keep actions pinned to their GitHub sources (the runner has internet + caches them). Drop the upload-artifact coverage step in favour of the self-hosted webserver plan tracked in the backlog. Add an empty-secret gate as publish's first step so a tag push without NPM_TOKEN fails loudly instead of silently no-oppping.
This commit is contained in:
1 parent
9a08262076
commit
0c6d1483de
1 file changed
+13
-9
@@ -0,0 +1,64 @@
|
||||
name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
branches: [main]
|
||||
workflow_dispatch: {}
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version-file: .node-version
|
||||
cache: "npm"
|
||||
- run: npm ci
|
||||
- run: npm run build
|
||||
- run: npm run check
|
||||
- run: npm run test:ci
|
||||
|
||||
# Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in
|
||||
# the Actions tab for visibility, but must never gate a merge — so
|
||||
# continue-on-error and intentionally NOT in `publish`'s `needs`.
|
||||
maintain:
|
||||
runs-on: ubuntu-latest
|
||||
continue-on-error: true
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version-file: .node-version
|
||||
cache: "npm"
|
||||
- run: npm ci
|
||||
- run: npm run maintain
|
||||
|
||||
publish:
|
||||
if: startsWith(gitea.ref, 'refs/tags/')
|
||||
needs: build
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
# Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN
|
||||
# is unset, so a tag push never silently no-ops (or half-publishes). Set
|
||||
# NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets.
|
||||
- name: Assert NPM_TOKEN is configured
|
||||
run: |
|
||||
if [ -z "${{ secrets.NPM_TOKEN }}" ]; then
|
||||
echo "::error::NPM_TOKEN secret is not set — refusing to publish."
|
||||
exit 1
|
||||
fi
|
||||
- uses: actions/checkout@v4
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version-file: .node-version
|
||||
registry-url: "https://registry.npmjs.org/"
|
||||
- run: npm ci
|
||||
- run: npm run build
|
||||
- run: npm run publish:publint
|
||||
- run: npm run publish:attw
|
||||
- run: npm publish --access public
|
||||
env:
|
||||
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||
Reference in new issue
Block a user