name: CI on: push: branches: [main] pull_request: branches: [main] workflow_dispatch: {} jobs: build: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: "npm" - run: npm ci - run: npm run build - run: npm run check - run: npm run test:ci # Fast, offline packaging gate. `attw` stays in `publish` (it needs # a pack + full resolution matrix); `publint` packs too but is cheap # enough to run on every push so a packaging break fails here, not # at release time. - run: npm run publish:publint # Persist the exact dist/ that `check`, `test:ci` and `publint` were # run against, so `publish` ships those bytes instead of rebuilding # (which could in principle differ and would pay the build twice). - uses: actions/upload-artifact@v4 with: name: dist path: dist/ # Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in # the Actions tab for visibility, but must never gate a merge — so # continue-on-error and intentionally NOT in `publish`'s `needs`. maintain: runs-on: ubuntu-latest continue-on-error: true steps: - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version cache: "npm" - run: npm ci - run: npm run maintain publish: if: startsWith(gitea.ref, 'refs/tags/') needs: build runs-on: ubuntu-latest steps: # Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN # is unset, so a tag push never silently no-ops (or half-publishes). Set # NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets. - name: Assert NPM_TOKEN is configured run: | if [ -z "${{ secrets.NPM_TOKEN }}" ]; then echo "::error::NPM_TOKEN secret is not set — refusing to publish." exit 1 fi - uses: actions/checkout@v4 - uses: actions/setup-node@v4 with: node-version-file: .node-version registry-url: "https://registry.npmjs.org/" - run: npm ci # Consume the dist/ that `build` produced and gated, instead of # rebuilding here — `publish` must ship the tested artifact. - uses: actions/download-artifact@v4 with: name: dist path: dist/ - run: npm run publish:publint - run: npm run publish:attw - run: npm publish --access public env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}