claude-code-best/.github/workflows/publish-npm.yml
林凯90331 1e10473fb7 ci(publish-npm): pin bun version, add vite build, and ignore scripts on publish
Pin bun to 1.3.11 for reproducible builds. Add explicit vite build step before publishing. Add --ignore-scripts to npm publish for security.

Signed-off-by: 林凯90331 <90331@sangfor.com>

Co-authored-by: CoStrict <zgsm@sangfor.com.cn>
2026-05-14 21:37:15 +08:00

158 lines
5.6 KiB
YAML

name: Publish to npm
on:
workflow_dispatch:
inputs:
version:
description: '版本号 (例如: 4.0.16)'
required: true
type: string
dry_run:
description: 'Dry run (仅验证,不实际发布)'
required: false
type: boolean
default: false
permissions:
contents: write
packages: write
id-token: write
jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2, 2026-04-25
with:
fetch-depth: 0
- name: Resolve version ref
id: version
run: |
RAW="${{ github.event.inputs.version || github.ref_name }}"
RAW_NO_V="${RAW#v}"
TAG="${RAW_NO_V}"
echo "raw=${RAW_NO_V}" >> "$GITHUB_OUTPUT"
echo "tag=${TAG}" >> "$GITHUB_OUTPUT"
- name: Sync package version
if: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.dry_run != 'true' }}
run: |
VERSION="${{ steps.version.outputs.raw }}"
# Update package.json
jq --arg v "$VERSION" '.version = $v' package.json > package.json.tmp && mv package.json.tmp package.json
# Update scripts/defines.ts
sed -i "s/\"MACRO.VERSION\": JSON.stringify(\"[^\"]*\")/\"MACRO.VERSION\": JSON.stringify(\"$VERSION\")/" scripts/defines.ts
# Verify
echo "package.json version: $(jq -r '.version' package.json)"
grep "MACRO.VERSION" scripts/defines.ts
# Commit and push version bump
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git status
git diff
git add -A
git commit -m "chore(release): bump version to ${VERSION}" || true
git push origin HEAD || true
- name: Create or recreate tag
if: ${{ github.event_name == 'workflow_dispatch' }}
run: |
TAG="${{ steps.version.outputs.tag }}"
HEAD_COMMIT=$(git rev-parse HEAD)
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
if git rev-parse "${TAG}" >/dev/null 2>&1; then
TAG_COMMIT=$(git rev-parse "${TAG}^{commit}")
if [ "${TAG_COMMIT}" != "${HEAD_COMMIT}" ]; then
echo "Tag ${TAG} exists but points to old commit ${TAG_COMMIT}, recreating on ${HEAD_COMMIT}"
git push --delete origin "${TAG}" || true
git tag -d "${TAG}" || true
git tag "${TAG}"
git push origin "${TAG}"
else
echo "Tag ${TAG} already points to current HEAD"
fi
else
git tag "${TAG}"
git push origin "${TAG}"
fi
- run: git checkout "${{ steps.version.outputs.tag }}"
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6, 2026-04-25
with:
node-version: "24"
registry-url: "https://registry.npmjs.org"
- name: Setup Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2, 2026-04-25
with:
bun-version: "1.3.11"
- name: Setup SSH for review agent generation
uses: webfactory/ssh-agent@v0.9.0
with:
ssh-private-key: ${{ secrets.MY_SSH_PRIVATE_KEY }}
- name: Generate review builtin files
run: bun run scripts/generate-review-builtin.ts
continue-on-error: true
- name: Install dependencies
run: bun install --frozen-lockfile
# - name: Type check
# run: bun run typecheck
# - name: Run tests
# run: bun test
- name: Build for publish (Vite)
run: bun run build:vite
- name: Publish to npm
if: ${{ github.event.inputs.dry_run != 'true' }}
run: npm publish --provenance --access public --ignore-scripts
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: Publish to npm (dry-run)
if: ${{ github.event.inputs.dry_run == 'true' }}
run: npm publish --dry-run --provenance --access public --ignore-scripts
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: Generate changelog
if: ${{ github.event.inputs.dry_run != 'true' }}
id: changelog
run: |
VERSION="${{ steps.version.outputs.tag }}"
PREV_TAG=$(git tag --sort=-version:refname | grep -v "^${VERSION}$" | head -1)
if [ -n "$PREV_TAG" ]; then
COMMITS=$(git log "${PREV_TAG}..${VERSION}" --pretty=format:"- %s (%h)" --no-merges)
else
COMMITS=$(git log --pretty=format:"- %s (%h)" --no-merges -20)
fi
{
echo "commits<<EOF"
echo "$COMMITS"
echo "EOF"
} >> "$GITHUB_OUTPUT"
- name: Create GitHub Release
if: ${{ github.event.inputs.dry_run != 'true' }}
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2, 2026-04-25
with:
tag_name: ${{ steps.version.outputs.tag }}
name: ${{ steps.version.outputs.tag }}
body: |
## What's Changed
${{ steps.changelog.outputs.commits }}
**Full Changelog**: https://github.com/${{ github.repository }}/compare/${{ steps.version.outputs.tag }}^...${{ steps.version.outputs.tag }}
draft: false
prerelease: ${{ contains(steps.version.outputs.raw, 'rc') || contains(steps.version.outputs.raw, 'beta') || contains(steps.version.outputs.raw, 'alpha') }}