Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
67 changes: 67 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
name: Publish

# Publishes to npm using OIDC trusted publishing: npm verifies this workflow's
# short-lived, workflow-scoped identity, so there is no npm token to store,
# rotate, or leak. Provenance attestations are generated automatically.
#
# Prerequisite, done once on npmjs.com: package settings -> Trusted publishers
# -> GitHub Actions, with repository mark-brannan/wire-wright and workflow
# file `publish.yml`. Until that exists this workflow will fail
# authentication, which is the correct failure mode.

on:
workflow_dispatch:
# Deliberately no `push: tags` trigger. release-please.yml tags through a
# GitHub App installation token (not the default GITHUB_TOKEN), so that
# push DOES fire workflows -- and a `push: tags` listener here would start
# a second, racing publish alongside the explicit `gh workflow run
# publish.yml --ref <tag>` dispatch release-please.yml already does.
# workflow_dispatch is also the only trigger npm's OIDC trusted publisher
# is configured for on npmjs.com (this file, this repo). So a tag alone,
# pushed by hand, does not publish; run `gh workflow run publish.yml --ref
# vX.Y.Z` instead.

permissions:
contents: read # release-please.yml creates the tag and the GitHub Release
id-token: write # required: this is what mints the OIDC token

jobs:
publish:
runs-on: ubuntu-latest
# workflow_dispatch can target a branch, not just a tag. A branch named
# to match package.json's version (e.g. "v0.1.1") would pass the tag
# check below despite not being an actual release tag -- npm trusted
# publishing doesn't restrict which ref a workflow_dispatch can run on.
# Refusing anything but a real tag closes that.
if: github.ref_type == 'tag'
steps:
# Nothing here writes to the repository -- release-please.yml owns the
# tag and the Release -- and the checkout's token should not outlive
# the step. Same rationale as test.yml's checkout.
- uses: actions/checkout@v7
Comment thread
claude[bot] marked this conversation as resolved.
with: { persist-credentials: false }
Comment thread
mark-brannan marked this conversation as resolved.

- uses: actions/setup-node@v7
with:
node-version: 22
registry-url: https://registry.npmjs.org

# Trusted publishing requires npm >= 11.5.1, newer than what ships with
# Node 22.
- run: npm install -g npm@latest
Comment thread
mark-brannan marked this conversation as resolved.

- name: Refuse to publish a tag that disagrees with package.json
run: |
TAG="${GITHUB_REF_NAME}"
PKG=$(node -p "require('./package.json').version")
if [ "${TAG#v}" != "$PKG" ]; then
echo "tag $TAG does not match package.json version $PKG" >&2
exit 1
fi

# The one dependency is `ampacity`, same as test.yml.
- run: npm ci
- run: npm test

# No NODE_AUTH_TOKEN. Authentication is the OIDC identity above.
- run: npm publish
5 changes: 0 additions & 5 deletions .github/workflows/release-please.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,6 @@ name: Release
# mark-brannan/.github/.github/workflows/release-please.yml for the full
# rationale (batching, squash-merge requirement, tag format, version
# policy).
#
# This repo has no publish.yml -- nothing to dispatch on release -- so the
# caller opts out with `publish: false`.

on:
push:
Expand All @@ -23,8 +20,6 @@ permissions:
jobs:
release:
uses: mark-brannan/.github/.github/workflows/release-please.yml@main
with:
publish: false
secrets:
RELEASE_PLEASE_APP_CLIENT_ID: ${{ secrets.RELEASE_PLEASE_APP_CLIENT_ID }}
RELEASE_PLEASE_APP_PRIVATE_KEY: ${{ secrets.RELEASE_PLEASE_APP_PRIVATE_KEY }}
Loading