Repository navigation
Release and Publish to GitHub Packages #1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release and Publish to GitHub Packages | |
| permissions: | |
| contents: read | |
| packages: write | |
| on: | |
| release: | |
| types: [published] | |
| workflow_dispatch: | |
| jobs: | |
| publish: | |
| name: Publish to GitHub Packages | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| # Don't persist the token in .git/config (artipacked). fetch-depth: 0 | |
| # already pulls all branches/tags, so no later authed git ops are needed. | |
| persist-credentials: false | |
| - name: Validate tag format | |
| if: github.event_name != 'workflow_dispatch' | |
| env: | |
| TAG: ${{ github.event.release.tag_name }} | |
| run: | | |
| VERSION="${TAG#v}" | |
| if ! [[ $VERSION =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then | |
| echo "Error: Invalid version format '$VERSION'. Expected format: x.y.z" | |
| exit 1 | |
| fi | |
| echo "Releasing version: $VERSION (from tag: $TAG)" | |
| - name: Verify tag is on the default branch | |
| if: github.event_name != 'workflow_dispatch' | |
| env: | |
| DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} | |
| run: | | |
| # origin/$DEFAULT_BRANCH is already present from the fetch-depth: 0 | |
| # checkout; merge-base is a local op, so no authenticated re-fetch is | |
| # required. Use the repo's default branch so this keeps working if it | |
| # is ever renamed (e.g. master -> main). | |
| if ! git merge-base --is-ancestor "$GITHUB_SHA" "origin/$DEFAULT_BRANCH"; then | |
| echo "Error: Tag commit $GITHUB_SHA is not reachable from origin/$DEFAULT_BRANCH." | |
| echo "Only tags on the default branch ($DEFAULT_BRANCH) can be published." | |
| exit 1 | |
| fi | |
| - name: Setup Node | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: 20 | |
| registry-url: "https://npm.pkg.github.com" | |
| scope: "@optimizely" | |
| - name: Validate package.json version matches tag | |
| if: github.event_name != 'workflow_dispatch' | |
| env: | |
| TAG: ${{ github.event.release.tag_name }} | |
| run: | | |
| TAG_VERSION="${TAG#v}" | |
| PKG_VERSION=$(node -p "require('./package.json').version") | |
| if [ "$TAG_VERSION" != "$PKG_VERSION" ]; then | |
| echo "Error: Tag version '$TAG_VERSION' does not match package.json version '$PKG_VERSION'." | |
| echo "Bump the version in package.json before tagging." | |
| exit 1 | |
| fi | |
| - name: Publish to GitHub Packages | |
| # No build/install: lib/ (the package entry) and dist/ are committed, | |
| # so npm publish packs the already-present artifacts as-is. | |
| env: | |
| NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: npm publish ${{ github.event_name == 'workflow_dispatch' && '--dry-run' || '' }} |