Repository navigation
Publish to npm #23
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish to npm | |
| # Trusted publishing (OIDC): no npm token is stored anywhere. npm accepts the publish | |
| # because this repo + this workflow file are registered as the package's trusted publisher | |
| # (`npm trust github opencode-context-tree --file publish.yml --repo navbytes/opencode-plugins`). | |
| # Registering a new package: `npm publish` its v0.x by hand once with a real token, then | |
| # `npm trust github <name> --file publish.yml --repo navbytes/opencode-plugins`. | |
| on: | |
| release: | |
| types: [published] | |
| workflow_dispatch: # dispatched on the new tag by release.yml, or run directly | |
| inputs: | |
| package: | |
| description: "Package to publish (only used when run directly, not via release)" | |
| type: choice | |
| default: context-tree | |
| options: [context-tree, git-stats] | |
| permissions: | |
| id-token: write # mint the OIDC token npm verifies | |
| contents: read | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-latest | |
| environment: npm | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # `prepack` runs `bun run build`, so Bun must be on PATH when npm packs. | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: latest | |
| # npm CLI >= 11.5.1 / Node >= 22.14 are required for OIDC trusted publishing. | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: '24' | |
| registry-url: 'https://registry.npmjs.org' | |
| package-manager-cache: false | |
| - run: bun install --frozen-lockfile | |
| - run: bun run typecheck | |
| - run: bun test | |
| # The tag is <package>-v<version>: derive both, stamp the version into that package's | |
| # package.json in this checkout only. A prerelease (0.3.0-beta.1) goes under the `beta` | |
| # dist-tag so `latest` keeps pointing at the last stable. Old-style bare `v*` tags (the | |
| # transition case) have no `-v` in the middle and resolve to context-tree. | |
| - name: Determine package and version | |
| id: meta | |
| run: | | |
| set -euo pipefail | |
| case "$GITHUB_REF_NAME" in | |
| *-v*) | |
| package="${GITHUB_REF_NAME%-v*}" | |
| version="${GITHUB_REF_NAME#*-v}" | |
| ;; | |
| v*) | |
| package="context-tree" | |
| version="${GITHUB_REF_NAME#v}" | |
| ;; | |
| *) | |
| package="${{ inputs.package }}" | |
| version="" | |
| ;; | |
| esac | |
| package="${package:-context-tree}" | |
| echo "$version" | grep -Eq '^[0-9]+\.[0-9]+\.[0-9]+([-.][0-9A-Za-z.-]+)?$' || { echo "ref '$GITHUB_REF_NAME' is not a version tag (package=$package, version=$version)" >&2; exit 1; } | |
| case "$version" in *-*) dist_tag=beta ;; *) dist_tag=latest ;; esac | |
| cd "packages/$package" && npm version "$version" --no-git-tag-version --allow-same-version | |
| echo "package=$package" >> "$GITHUB_OUTPUT" | |
| echo "version=$version" >> "$GITHUB_OUTPUT" | |
| echo "dist_tag=$dist_tag" >> "$GITHUB_OUTPUT" | |
| # OIDC trusted publishing needs the package to already exist on npm: the very first | |
| # version of a new package is published once by hand, every later one lands here. | |
| - run: cd "packages/${{ steps.meta.outputs.package }}" && npm publish --provenance --access public --tag "${{ steps.meta.outputs.dist_tag }}" |