-
Notifications
You must be signed in to change notification settings - Fork 58
90 lines (79 loc) · 3.02 KB
/
Copy pathnpm-publish.yml
File metadata and controls
90 lines (79 loc) · 3.02 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
name: Publish npm package via OIDC
on:
release:
types: [published]
jobs:
publish:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write # Required for npm OIDC provenance
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Wait for .tgz release asset uploaded by Jenkins
run: |
echo "Waiting for .tgz asset to appear in release..."
for i in {1..30}; do
assets=$(gh release view "${{ github.event.release.tag_name }}" --json assets --jq '.assets[].name' || true)
echo "Assets found: $assets"
if echo "$assets" | grep -E '\.tgz$' >/dev/null; then
echo "Found .tgz asset."
break
fi
echo "Attempt $i/30: not found yet, waiting 10s..."
sleep 10
done
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Download release asset (.tgz)
uses: robinraju/release-downloader@v1.11
with:
repository: ${{ github.repository }}
tag: ${{ github.event.release.tag_name }}
fileName: "*.tgz"
out-file-path: ./dist
token: ${{ secrets.GITHUB_TOKEN }}
- name: Determine package file name from tag
id: pkg
run: |
VERSION="${GITHUB_REF_NAME#v}" # strip leading "v" if present
FILE="./dist/wireapp-avs-${VERSION}.tgz"
echo "Checking for package file: $FILE"
if [ ! -f "$FILE" ]; then
echo "ERROR: Expected file $FILE not found!"
echo "Available files:"
ls -lh ./dist
exit 1
fi
echo "Using package file: $FILE"
echo "tgz_file=$FILE" >> $GITHUB_OUTPUT
echo "version=$VERSION" >> $GITHUB_OUTPUT
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: 20
registry-url: "https://registry.npmjs.org/"
- name: Update npm to the required OIDC version
run: npm install -g npm@latest
- name: Determine npm tag for publish
id: tag
run: |
VERSION=${{ steps.pkg.outputs.version }}
NAME="@wireapp/avs"
echo "Checking current latest version on npm..."
LATEST=$(npm view "$NAME" version || echo "0.0.0")
echo "Latest published version: $LATEST"
# compare versions
if [ "$(printf '%s\n%s' "$VERSION" "$LATEST" | sort -V | tail -n1)" = "$VERSION" ]; then
TAG="latest"
else
BASE_TAG=$(echo "$VERSION" | awk -F. '{print $1"."$2}')
TAG="release-$BASE_TAG"
fi
echo "Using npm tag: $TAG"
echo "npm_tag=$TAG" >> $GITHUB_OUTPUT
- name: Publish with provenance (OIDC)
run: |
echo "Publishing ${{ steps.pkg.outputs.tgz_file }} to npm with tag ${{ steps.tag.outputs.npm_tag }}..."
npm publish "${{ steps.pkg.outputs.tgz_file }}" --tag "${{ steps.tag.outputs.npm_tag }}" --provenance --access public