-
Notifications
You must be signed in to change notification settings - Fork 0
88 lines (74 loc) · 3.54 KB
/
Copy pathrelease.yml
File metadata and controls
88 lines (74 loc) · 3.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
# Publishes @bootnodedev/canton-barebones to npm via Changesets, and the dpm
# component (standalone binaries) to ghcr.io.
#
# Flow: every push to main runs this. The changesets action either
# (a) opens/updates a "Version Packages" PR when unreleased changesets exist, or
# (b) publishes to npm when that PR was merged (i.e. package.json version bumped).
# Nothing is published on a normal merge — only when the Version Packages PR lands.
# The dpm component is published right after a successful npm publish, with the
# same version, so both channels always ship the same source.
name: Release
on:
push:
branches: [main]
# Avoid two release runs racing on the same ref (e.g. rapid merges).
concurrency: release-${{ github.ref }}
jobs:
release:
runs-on: ubuntu-latest
permissions:
contents: write # create tags / GitHub releases and push the Version Packages PR
pull-requests: write # open and update the Version Packages PR
id-token: write # npm trusted publishing (OIDC) and provenance
packages: write # push the dpm component to ghcr.io
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # changesets needs full history to compute versions
- uses: actions/setup-node@v4
with:
node-version: 22
# Publishing uses npm trusted publishing (OIDC) — the trusted publisher is
# configured on npmjs.com for this repo/workflow, so no NPM_TOKEN is needed
# and provenance is attached automatically. It requires npm >= 11.5.1,
# while node 22 ships npm 10.
- run: npm install -g npm@latest
- run: npm ci
# Gate: unit tests must pass before anything is published.
- run: npm test
- name: Create Version PR or publish
id: changesets
uses: changesets/action@v1
with:
publish: npm run release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Everything below runs only when the step above actually published to npm
# (the Version Packages PR was merged); ordinary merges skip it entirely.
- uses: oven-sh/setup-bun@v2
if: steps.changesets.outputs.published == 'true'
with:
bun-version: 1.3.1 # keep in sync with ci.yml
# Pinned dpm shared with ci.yml — see the action for the pin rationale.
- uses: ./.github/actions/setup-dpm
if: steps.changesets.outputs.published == 'true'
- name: Publish dpm component to ghcr.io
if: steps.changesets.outputs.published == 'true'
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
npm run build:component
# dpm reads registry credentials from docker's config.json, so a
# regular docker login is all the auth it needs.
echo "$GITHUB_TOKEN" | docker login ghcr.io -u "$GITHUB_ACTOR" --password-stdin
# The npm publish already bumped package.json, so its version is the
# single source of truth for both channels. dpm requires strict semver
# tags; --extra-tags latest lets users pin `:latest` in daml.yaml.
VERSION=$(node -p "require('./package.json').version")
dpm publish component "oci://ghcr.io/bootnodedev/canton-barebones:${VERSION}" \
-p linux/amd64=dist/dpm-component/linux-amd64 \
-p linux/arm64=dist/dpm-component/linux-arm64 \
-p darwin/amd64=dist/dpm-component/darwin-amd64 \
-p darwin/arm64=dist/dpm-component/darwin-arm64 \
-p windows/amd64=dist/dpm-component/windows-amd64 \
--extra-tags latest