Pin bun to 1.3.11 for reproducible builds. Add explicit vite build step before publishing. Add --ignore-scripts to npm publish for security. Signed-off-by: 林凯90331 <90331@sangfor.com> Co-authored-by: CoStrict <zgsm@sangfor.com.cn>
158 lines
5.6 KiB
YAML
158 lines
5.6 KiB
YAML
name: Publish to npm
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: '版本号 (例如: 4.0.16)'
|
|
required: true
|
|
type: string
|
|
dry_run:
|
|
description: 'Dry run (仅验证,不实际发布)'
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
|
|
permissions:
|
|
contents: write
|
|
packages: write
|
|
id-token: write
|
|
|
|
jobs:
|
|
publish:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2, 2026-04-25
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Resolve version ref
|
|
id: version
|
|
run: |
|
|
RAW="${{ github.event.inputs.version || github.ref_name }}"
|
|
RAW_NO_V="${RAW#v}"
|
|
TAG="${RAW_NO_V}"
|
|
echo "raw=${RAW_NO_V}" >> "$GITHUB_OUTPUT"
|
|
echo "tag=${TAG}" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Sync package version
|
|
if: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.dry_run != 'true' }}
|
|
run: |
|
|
VERSION="${{ steps.version.outputs.raw }}"
|
|
# Update package.json
|
|
jq --arg v "$VERSION" '.version = $v' package.json > package.json.tmp && mv package.json.tmp package.json
|
|
# Update scripts/defines.ts
|
|
sed -i "s/\"MACRO.VERSION\": JSON.stringify(\"[^\"]*\")/\"MACRO.VERSION\": JSON.stringify(\"$VERSION\")/" scripts/defines.ts
|
|
# Verify
|
|
echo "package.json version: $(jq -r '.version' package.json)"
|
|
grep "MACRO.VERSION" scripts/defines.ts
|
|
# Commit and push version bump
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
git status
|
|
git diff
|
|
git add -A
|
|
git commit -m "chore(release): bump version to ${VERSION}" || true
|
|
git push origin HEAD || true
|
|
|
|
- name: Create or recreate tag
|
|
if: ${{ github.event_name == 'workflow_dispatch' }}
|
|
run: |
|
|
TAG="${{ steps.version.outputs.tag }}"
|
|
HEAD_COMMIT=$(git rev-parse HEAD)
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "github-actions[bot]@users.noreply.github.com"
|
|
if git rev-parse "${TAG}" >/dev/null 2>&1; then
|
|
TAG_COMMIT=$(git rev-parse "${TAG}^{commit}")
|
|
if [ "${TAG_COMMIT}" != "${HEAD_COMMIT}" ]; then
|
|
echo "Tag ${TAG} exists but points to old commit ${TAG_COMMIT}, recreating on ${HEAD_COMMIT}"
|
|
git push --delete origin "${TAG}" || true
|
|
git tag -d "${TAG}" || true
|
|
git tag "${TAG}"
|
|
git push origin "${TAG}"
|
|
else
|
|
echo "Tag ${TAG} already points to current HEAD"
|
|
fi
|
|
else
|
|
git tag "${TAG}"
|
|
git push origin "${TAG}"
|
|
fi
|
|
|
|
- run: git checkout "${{ steps.version.outputs.tag }}"
|
|
|
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6, 2026-04-25
|
|
with:
|
|
node-version: "24"
|
|
registry-url: "https://registry.npmjs.org"
|
|
|
|
- name: Setup Bun
|
|
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2, 2026-04-25
|
|
with:
|
|
bun-version: "1.3.11"
|
|
|
|
- name: Setup SSH for review agent generation
|
|
uses: webfactory/ssh-agent@v0.9.0
|
|
with:
|
|
ssh-private-key: ${{ secrets.MY_SSH_PRIVATE_KEY }}
|
|
|
|
- name: Generate review builtin files
|
|
run: bun run scripts/generate-review-builtin.ts
|
|
continue-on-error: true
|
|
|
|
- name: Install dependencies
|
|
run: bun install --frozen-lockfile
|
|
# - name: Type check
|
|
# run: bun run typecheck
|
|
|
|
# - name: Run tests
|
|
# run: bun test
|
|
|
|
- name: Build for publish (Vite)
|
|
run: bun run build:vite
|
|
|
|
- name: Publish to npm
|
|
if: ${{ github.event.inputs.dry_run != 'true' }}
|
|
run: npm publish --provenance --access public --ignore-scripts
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: Publish to npm (dry-run)
|
|
if: ${{ github.event.inputs.dry_run == 'true' }}
|
|
run: npm publish --dry-run --provenance --access public --ignore-scripts
|
|
env:
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
- name: Generate changelog
|
|
if: ${{ github.event.inputs.dry_run != 'true' }}
|
|
id: changelog
|
|
run: |
|
|
VERSION="${{ steps.version.outputs.tag }}"
|
|
PREV_TAG=$(git tag --sort=-version:refname | grep -v "^${VERSION}$" | head -1)
|
|
|
|
if [ -n "$PREV_TAG" ]; then
|
|
COMMITS=$(git log "${PREV_TAG}..${VERSION}" --pretty=format:"- %s (%h)" --no-merges)
|
|
else
|
|
COMMITS=$(git log --pretty=format:"- %s (%h)" --no-merges -20)
|
|
fi
|
|
|
|
{
|
|
echo "commits<<EOF"
|
|
echo "$COMMITS"
|
|
echo "EOF"
|
|
} >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Create GitHub Release
|
|
if: ${{ github.event.inputs.dry_run != 'true' }}
|
|
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2, 2026-04-25
|
|
with:
|
|
tag_name: ${{ steps.version.outputs.tag }}
|
|
name: ${{ steps.version.outputs.tag }}
|
|
body: |
|
|
## What's Changed
|
|
|
|
${{ steps.changelog.outputs.commits }}
|
|
|
|
**Full Changelog**: https://github.com/${{ github.repository }}/compare/${{ steps.version.outputs.tag }}^...${{ steps.version.outputs.tag }}
|
|
draft: false
|
|
prerelease: ${{ contains(steps.version.outputs.raw, 'rc') || contains(steps.version.outputs.raw, 'beta') || contains(steps.version.outputs.raw, 'alpha') }}
|