👷 Publish the dist built by the build job
The publish job re-ran npm ci + build from scratch, discarding the output that check, test:ci and publint had already gated, and paying the build twice on a tag push. Upload dist/ as an artifact from build and download it in publish instead. npm ci stays for the publint/attw binaries; only the redundant rebuild is gone.
This commit is contained in:
1 parent
303544796e
commit
fe9d59f8d4
2 files changed
+15
-3
No files matched your search
+13
-1
@@ -25,6 +25,13 @@ jobs:
|
|||||||
# enough to run on every push so a packaging break fails here, not
|
# enough to run on every push so a packaging break fails here, not
|
||||||
# at release time.
|
# at release time.
|
||||||
- run: npm run publish:publint
|
- run: npm run publish:publint
|
||||||
|
# Persist the exact dist/ that `check`, `test:ci` and `publint` were
|
||||||
|
# run against, so `publish` ships those bytes instead of rebuilding
|
||||||
|
# (which could in principle differ and would pay the build twice).
|
||||||
|
- uses: actions/upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: dist
|
||||||
|
path: dist/
|
||||||
|
|
||||||
# Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in
|
# Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in
|
||||||
# the Actions tab for visibility, but must never gate a merge — so
|
# the Actions tab for visibility, but must never gate a merge — so
|
||||||
@@ -61,7 +68,12 @@ jobs:
|
|||||||
node-version-file: .node-version
|
node-version-file: .node-version
|
||||||
registry-url: "https://registry.npmjs.org/"
|
registry-url: "https://registry.npmjs.org/"
|
||||||
- run: npm ci
|
- run: npm ci
|
||||||
- run: npm run build
|
# Consume the dist/ that `build` produced and gated, instead of
|
||||||
|
# rebuilding here — `publish` must ship the tested artifact.
|
||||||
|
- uses: actions/download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: dist
|
||||||
|
path: dist/
|
||||||
- run: npm run publish:publint
|
- run: npm run publish:publint
|
||||||
- run: npm run publish:attw
|
- run: npm run publish:attw
|
||||||
- run: npm publish --access public
|
- run: npm publish --access public
|
||||||
|
|||||||
+2
-2
@@ -31,10 +31,10 @@ Setup:
|
|||||||
✔ Run packaging checks in CI `build` @done
|
✔ Run packaging checks in CI `build` @done
|
||||||
- `publish:publint` / `publish:attw` only run in the tag-triggered `publish` job, so a PR that breaks packaging stays green until release
|
- `publish:publint` / `publish:attw` only run in the tag-triggered `publish` job, so a PR that breaks packaging stays green until release
|
||||||
✔ At minimum add `publish:publint` to the `build` job (offline, fast); `attw` needs a pack @done
|
✔ At minimum add `publish:publint` to the `build` job (offline, fast); `attw` needs a pack @done
|
||||||
☐ Publish the exact artifact CI tested
|
✔ Publish the exact artifact CI tested @done
|
||||||
- `publish: needs: build`, then re-runs `npm ci` + `build` from scratch, discarding the tested output
|
- `publish: needs: build`, then re-runs `npm ci` + `build` from scratch, discarding the tested output
|
||||||
- tag push pays a double build and the two builds could differ
|
- tag push pays a double build and the two builds could differ
|
||||||
☐ Persist `dist/` as an artifact in `build` and consume it in `publish`
|
✔ Persist `dist/` as an artifact in `build` and consume it in `publish` @done
|
||||||
☐ Confirm pre-push gate strength
|
☐ Confirm pre-push gate strength
|
||||||
- pre-push runs `npm test` (`check:tsc` + tests), not full `check`; oxlint/oxfmt/cspell drift on unstaged content is only caught per-staged-file at commit or whole-project in CI
|
- pre-push runs `npm test` (`check:tsc` + tests), not full `check`; oxlint/oxfmt/cspell drift on unstaged content is only caught per-staged-file at commit or whole-project in CI
|
||||||
☐ Confirm this is intended per the feedback-tier table, or point pre-push at `verify`
|
☐ Confirm this is intended per the feedback-tier table, or point pre-push at `verify`
|
||||||
|
|||||||
Reference in new issue
Block a user