Skip to content

Publish to npm

Publish to npm #14

Workflow file for this run

name: Publish to npm
# Trusted publishing (OIDC): no npm token is stored anywhere. npm accepts the publish
# because this repo + this workflow file are registered as the package's trusted publisher
# (`npm trust github opencode-context-tree --file publish.yml --repo navbytes/opencode-tree`).
on:
release:
types: [published]
workflow_dispatch: # dispatched on the new tag by release.yml
permissions:
id-token: write # mint the OIDC token npm verifies
contents: read
jobs:
publish:
runs-on: ubuntu-latest
environment: npm
steps:
- uses: actions/checkout@v4
# `prepack` runs `bun run build`, so Bun must be on PATH when npm packs.
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# npm CLI >= 11.5.1 / Node >= 22.14 are required for OIDC trusted publishing.
- uses: actions/setup-node@v6
with:
node-version: '24'
registry-url: 'https://registry.npmjs.org'
package-manager-cache: false
- run: bun install --frozen-lockfile
- run: bun run typecheck
- run: bun test
# The tag is the version: stamp it into package.json in this checkout only.
- name: Version from the release tag
run: |
tag="${GITHUB_REF_NAME#v}"
echo "$tag" | grep -Eq '^[0-9]+\.[0-9]+\.[0-9]+([-.][0-9A-Za-z.-]+)?$' || { echo "ref '$GITHUB_REF_NAME' is not a version tag" >&2; exit 1; }
npm version "$tag" --no-git-tag-version --allow-same-version
# OIDC trusted publishing needs the package to already exist on npm: the very first
# version of a new package is published once by hand, every later one lands here.
- run: npm publish --provenance --access public