name: CI on: push: branches: [main] pull_request: branches: [main] workflow_dispatch: {} jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: "npm" - run: npm ci - run: npm run build - run: npm run check - run: npm run test:ci # Fast, offline packaging gate. `attw` stays in `publish` (it needs # a pack + full resolution matrix); `publint` packs too but is cheap # enough to run on every push so a packaging break fails here, not # at release time. - run: npm run publish:publint # Persist the exact dist/ that `check`, `test:ci` and `publint` were # run against, so `publish` ships those bytes instead of rebuilding # (which could in principle differ and would pay the build twice). - uses: actions/upload-artifact@v4 with: name: dist path: dist/ # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in # the Actions tab for visibility, but must never gate a merge — so # continue-on-error and intentionally NOT in `publish`'s `needs`. maintain: runs-on: ubuntu-latest continue-on-error: true steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: "npm" - run: npm ci - run: npm run maintain publish: if: startsWith(gitea.ref, 'refs/tags/') needs: build runs-on: ubuntu-latest # The release page is created with the run's automatic Gitea token # (`github.token`), not `NPM_TOKEN`, so it needs `contents: write`. permissions: contents: write steps: # Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN # is unset, so a tag push never silently no-ops (or half-publishes). Set # NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets. - name: Assert NPM_TOKEN is configured run: | if [ -z "${{ secrets.NPM_TOKEN }}" ]; then echo "::error::NPM_TOKEN secret is not set — refusing to publish." exit 1 fi - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version registry-url: "https://registry.npmjs.org/" - run: npm ci # Consume the dist/ that `build` produced and gated, instead of # rebuilding here — `publish` must ship the tested artifact. - uses: actions/download-artifact@v4 with: name: dist path: dist/ - run: npm run publish:publint - run: npm run publish:attw # The Gitea release page is created *before* `npm publish` on # purpose: a broken page then fails CI without burning an npm # version. The page is cheap to retry, a published version is not. # The body is the matching Keep-a-Changelog section; an unknown tag # makes the extractor exit non-zero, so the page can never go up # empty. - name: Extract release notes from CHANGELOG.md env: TAG_REF: ${{ gitea.ref }} run: ./scripts/release-notes.sh "${TAG_REF#refs/tags/}" > release-notes.md - uses: https://gitea.com/actions/gitea-release-action@v1 with: body_path: release-notes.md - run: npm publish --access public env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}