Skip to content

Publish to npm

Publish to npm #23

Workflow file for this run

name: Publish to npm
# Trusted publishing (OIDC): no npm token is stored anywhere. npm accepts the publish
# because this repo + this workflow file are registered as the package's trusted publisher
# (`npm trust github opencode-context-tree --file publish.yml --repo navbytes/opencode-plugins`).
# Registering a new package: `npm publish` its v0.x by hand once with a real token, then
# `npm trust github <name> --file publish.yml --repo navbytes/opencode-plugins`.
on:
release:
types: [published]
workflow_dispatch: # dispatched on the new tag by release.yml, or run directly
inputs:
package:
description: "Package to publish (only used when run directly, not via release)"
type: choice
default: context-tree
options: [context-tree, git-stats]
permissions:
id-token: write # mint the OIDC token npm verifies
contents: read
jobs:
publish:
runs-on: ubuntu-latest
environment: npm
steps:
- uses: actions/checkout@v4
# `prepack` runs `bun run build`, so Bun must be on PATH when npm packs.
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# npm CLI >= 11.5.1 / Node >= 22.14 are required for OIDC trusted publishing.
- uses: actions/setup-node@v6
with:
node-version: '24'
registry-url: 'https://registry.npmjs.org'
package-manager-cache: false
- run: bun install --frozen-lockfile
- run: bun run typecheck
- run: bun test
# The tag is <package>-v<version>: derive both, stamp the version into that package's
# package.json in this checkout only. A prerelease (0.3.0-beta.1) goes under the `beta`
# dist-tag so `latest` keeps pointing at the last stable. Old-style bare `v*` tags (the
# transition case) have no `-v` in the middle and resolve to context-tree.
- name: Determine package and version
id: meta
run: |
set -euo pipefail
case "$GITHUB_REF_NAME" in
*-v*)
package="${GITHUB_REF_NAME%-v*}"
version="${GITHUB_REF_NAME#*-v}"
;;
v*)
package="context-tree"
version="${GITHUB_REF_NAME#v}"
;;
*)
package="${{ inputs.package }}"
version=""
;;
esac
package="${package:-context-tree}"
echo "$version" | grep -Eq '^[0-9]+\.[0-9]+\.[0-9]+([-.][0-9A-Za-z.-]+)?$' || { echo "ref '$GITHUB_REF_NAME' is not a version tag (package=$package, version=$version)" >&2; exit 1; }
case "$version" in *-*) dist_tag=beta ;; *) dist_tag=latest ;; esac
cd "packages/$package" && npm version "$version" --no-git-tag-version --allow-same-version
echo "package=$package" >> "$GITHUB_OUTPUT"
echo "version=$version" >> "$GITHUB_OUTPUT"
echo "dist_tag=$dist_tag" >> "$GITHUB_OUTPUT"
# OIDC trusted publishing needs the package to already exist on npm: the very first
# version of a new package is published once by hand, every later one lands here.
- run: cd "packages/${{ steps.meta.outputs.package }}" && npm publish --provenance --access public --tag "${{ steps.meta.outputs.dist_tag }}"