publish:publint and publish:attw only ran in the tag-triggered publish job, so a packaging break stayed green until release. Add publint to build (offline, fast, packs the built dist). attw stays in publish, where the full resolution matrix is worth the cost.
70 lines
2.4 KiB
YAML
70 lines
2.4 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
branches: [main]
|
|
workflow_dispatch: {}
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .node-version
|
|
cache: "npm"
|
|
- run: npm ci
|
|
- run: npm run build
|
|
- run: npm run check
|
|
- run: npm run test:ci
|
|
# Fast, offline packaging gate. `attw` stays in `publish` (it needs
|
|
# a pack + full resolution matrix); `publint` packs too but is cheap
|
|
# enough to run on every push so a packaging break fails here, not
|
|
# at release time.
|
|
- run: npm run publish:publint
|
|
|
|
# Advisory scans (dead code, dependency freshness). Non-blocking: surfaced in
|
|
# the Actions tab for visibility, but must never gate a merge — so
|
|
# continue-on-error and intentionally NOT in `publish`'s `needs`.
|
|
maintain:
|
|
runs-on: ubuntu-latest
|
|
continue-on-error: true
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .node-version
|
|
cache: "npm"
|
|
- run: npm ci
|
|
- run: npm run maintain
|
|
|
|
publish:
|
|
if: startsWith(gitea.ref, 'refs/tags/')
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# Double-gate: publish only runs on a tag *and* aborts here if NPM_TOKEN
|
|
# is unset, so a tag push never silently no-ops (or half-publishes). Set
|
|
# NPM_TOKEN in the Gitea repo: Settings → Actions → Secrets.
|
|
- name: Assert NPM_TOKEN is configured
|
|
run: |
|
|
if [ -z "${{ secrets.NPM_TOKEN }}" ]; then
|
|
echo "::error::NPM_TOKEN secret is not set — refusing to publish."
|
|
exit 1
|
|
fi
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .node-version
|
|
registry-url: "https://registry.npmjs.org/"
|
|
- run: npm ci
|
|
- run: npm run build
|
|
- run: npm run publish:publint
|
|
- run: npm run publish:attw
|
|
- run: npm publish --access public
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|