👷 Gate the publish steps on their tokens

The publish job aborted at the top-of-job NPM_TOKEN assert, so every tag run
since 0.1.1 failed before checkout and nothing was ever published. Lift both
optional secrets into job-level env (the secrets context is not allowed in a
step if) and gate each publish step: the Gitea release on GITEA_TOKEN, npm
publish on NPM_TOKEN. An absent secret now skips only its step, so a tag without
the maintainer's secrets stays green after the packaging checks.
This commit is contained in:
tmu committed 2026-09-15 09:06:35 +00:00
1 parent 75f2185b32
commit 8915eb8faa
1 file changed
+28 -24
+28 -24
View File
@@ -65,8 +65,8 @@ jobs:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
# Fail fast when the job container is not the baked image: a stale # Fail fast when the job container is not the baked image: a stale
# tag on the runner (`forcePull=false` in its pull log) silently # tag on the runner (`forcePull=false` in its pull log) silently
# reintroduces the per-job download. Mirrors the publish job's # reintroduces the per-job download. Cheap, and it names the
# NPM_TOKEN assert — cheap, and it names the invariant. # invariant.
- name: Assert the baked tool cache is present - name: Assert the baked tool cache is present
run: | run: |
test -f "/opt/hostedtoolcache/node/$(tr -d '[:space:]' < .node-version)/x64.complete" test -f "/opt/hostedtoolcache/node/$(tr -d '[:space:]' < .node-version)/x64.complete"
@@ -141,20 +141,18 @@ jobs:
# `.npmrc` rewrite here; only the Node download is skipped. # `.npmrc` rewrite here; only the Node download is skipped.
container: container:
image: gitea.e1nsnull.de/tmu/act-ci:26.8.2 image: gitea.e1nsnull.de/tmu/act-ci:26.8.2
# The release page is created with the run's automatic Gitea token # Lift the optional publish secrets into job-level `env` so the steps
# (`github.token`), not `NPM_TOKEN`, so it needs `contents: write`. # below can gate on them: `secrets` is not an allowed context in a step
permissions: # `if` (see GitHub's context-availability table), `env` is. An unset
contents: write # secret arrives as the empty string, which is exactly the skip signal.
# A tag pushed without the maintainer's secrets (a fork, a manual
# dispatch) now runs the packaging checks and skips only the publish
# steps whose token is missing, instead of failing the job at an assert.
# Set both in the Gitea repo: Settings → Actions → Secrets.
env:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
steps: steps:
# Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN
# is unset, so a tag push never silently no-ops (or half-publishes). Set
# NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets.
- name: Assert NPM_TOKEN is configured
run: |
if [ -z "${{ secrets.NPM_TOKEN }}" ]; then
echo "::error::NPM_TOKEN secret is not set — refusing to publish."
exit 1
fi
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- uses: actions/setup-node@v4 - uses: actions/setup-node@v4
with: with:
@@ -173,19 +171,25 @@ jobs:
path: dist/ path: dist/
- run: npm run publish:publint - run: npm run publish:publint
- run: npm run publish:attw - run: npm run publish:attw
# The Gitea release page is created *before* `npm publish` on # When both tokens are present the Gitea release page is created
# purpose: a broken page then fails CI without burning an npm # *before* `npm publish` on purpose: a broken page then fails CI
# version. The page is cheap to retry, a published version is not. # without burning an npm version. The page is cheap to retry, a
# The body is the matching Keep-a-Changelog section; an unknown tag # published version is not. The body is the matching
# makes the extractor exit non-zero, so the page can never go up # Keep-a-Changelog section; an unknown tag makes the extractor exit
# empty. # non-zero, so the page can never go up empty.
- name: Extract release notes from CHANGELOG.md - name: Extract release notes from CHANGELOG.md
if: env.GITEA_TOKEN != ''
env: env:
TAG_REF: ${{ gitea.ref }} TAG_REF: ${{ gitea.ref }}
run: ./scripts/release-notes.sh "${TAG_REF#refs/tags/}" > release-notes.md run: ./scripts/release-notes.sh "${TAG_REF#refs/tags/}" > release-notes.md
- uses: https://gitea.com/actions/gitea-release-action@v1 - name: Create the Gitea release
if: env.GITEA_TOKEN != ''
uses: https://gitea.com/actions/gitea-release-action@v1
with: with:
token: ${{ env.GITEA_TOKEN }}
body_path: release-notes.md body_path: release-notes.md
- run: npm publish --access public - name: Publish to npm
if: env.NPM_TOKEN != ''
run: npm publish --access public
env: env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} NODE_AUTH_TOKEN: ${{ env.NPM_TOKEN }}