Publish snapshot / snapshot (push) Successful in 1m5s
Pushing a release pushes the branch and then the tags seconds apart. publish-snapshot.yml keys its concurrency group on the branch and release.yml keys its own on the tag, so the two never gate each other — on a single runner they race for it and the branch push always wins. On 1.0.1 the snapshot job wedged extracting a layer of the runner image, the release job never started, release.mjs gave up after its 20-minute wait, and two of three tags were left unpushed. The report still printed a bold "Done" above an empty shipped list, so it read as a success. - publish-snapshot.yml skips commits whose message starts with "release:". A snapshot of a release commit is the same tree the tag is about to publish properly, so skipping costs nothing and removes the race. - waitForRelease() offers to keep waiting instead of giving up. No timeout value survives a wedged runner, so the real choice is between asking and making the operator finish the release by hand. --yes and a non-interactive run still give up; the latter matters because confirm() answers with its default without a terminal, which would extend the deadline forever. - The final header says "Blocked" when it is, and labels the packages that did ship before the blockage. - --wait-timeout defaults to 2400s rather than 1200s. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01DCzYTAm9QUhvLNr2EpdagJ
168 lines
6.8 KiB
YAML
168 lines
6.8 KiB
YAML
# Every commit that lands on `main` publishes a prerelease of every publishable
|
|
# package to the Gitea npm registry under the `main` dist-tag:
|
|
#
|
|
# pnpm add @bitsquare/nopy@main
|
|
#
|
|
# The verification gate runs here rather than in ci.yml so a snapshot can never
|
|
# be published from a red `main`. Versions are derived, never committed —
|
|
# releases to npmjs are cut by hand via a tag (see release.yml).
|
|
|
|
name: Publish snapshot
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
|
|
concurrency:
|
|
group: snapshot-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
snapshot:
|
|
# Not on a release commit. `scripts/release.mjs` pushes the branch and then
|
|
# the tags seconds apart, and this workflow's concurrency group is keyed on
|
|
# the branch while release.yml's is keyed on the tag — so the two never gate
|
|
# each other, they race for the runner, and the branch push always gets
|
|
# there first. Measured: a snapshot job that wedged pulling the runner image
|
|
# held the runner long enough for release.mjs to give up waiting on npmjs,
|
|
# leaving two of three tags unpushed.
|
|
#
|
|
# Skipping costs nothing. A snapshot of a release commit is the same tree
|
|
# the tag is about to publish properly, under a version nobody installs.
|
|
if: ${{ !startsWith(github.event.head_commit.message, 'release:') }}
|
|
runs-on: ubuntu-latest
|
|
|
|
env:
|
|
# e.g. https://gitea.example.com/api/packages/BitSquare/npm/
|
|
REGISTRY: ${{ github.server_url }}/api/packages/${{ github.repository_owner }}/npm/
|
|
# GITEA_TOKEN is injected automatically but the package registry rejects
|
|
# it — it is a repo-scoped task token. MYGITEA_NPM_TOKEN must be a PAT with
|
|
# `write:package`; the fallback only survives here for other instances.
|
|
REGISTRY_TOKEN: ${{ secrets.MYGITEA_NPM_TOKEN || secrets.GITEA_TOKEN }}
|
|
NPMRC: ${{ github.workspace }}/.npmrc-gitea
|
|
|
|
steps:
|
|
- name: Check out
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Drop the repo's Gitea scope mapping
|
|
# See the same step in release.yml. This job only ever targets Gitea, so
|
|
# the committed file happens to agree with it — but it agrees by
|
|
# accident, and a project-level `@bitsquare:registry` silently outranks
|
|
# the userconfig written below. Removing it keeps the registry a
|
|
# property of the step rather than of the checkout.
|
|
run: rm -f .npmrc
|
|
|
|
- name: Set up pnpm
|
|
# Version comes from `packageManager` in the root package.json.
|
|
uses: pnpm/action-setup@v4
|
|
|
|
- name: Set up Node
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: .nvmrc
|
|
|
|
- name: Locate the pnpm store
|
|
id: pnpm-store
|
|
run: echo "path=$(pnpm store path --silent)" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Restore the pnpm store
|
|
continue-on-error: true
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: ${{ steps.pnpm-store.outputs.path }}
|
|
key: pnpm-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml') }}
|
|
restore-keys: pnpm-${{ runner.os }}-
|
|
|
|
- name: Install
|
|
run: pnpm install --frozen-lockfile
|
|
|
|
- name: Lint
|
|
run: pnpm run lint:ci
|
|
|
|
- name: Typecheck
|
|
run: pnpm run typecheck
|
|
|
|
- name: Test with coverage
|
|
run: pnpm run test:coverage
|
|
|
|
- name: Summarise coverage
|
|
# Reporting only — the gate is the step above.
|
|
if: always()
|
|
continue-on-error: true
|
|
run: pnpm run coverage:summary
|
|
|
|
- name: Build
|
|
# Explicit, so the publish step can skip lifecycle scripts entirely.
|
|
run: pnpm run build
|
|
|
|
- name: Verify the packed manifests
|
|
# Packages link to each other with `workspace:*`, which npm cannot
|
|
# install. Proves on the tarball that pack rewrote it.
|
|
run: node scripts/verify-pack.mjs
|
|
|
|
- name: Authenticate against the Gitea registry
|
|
run: |
|
|
set -euo pipefail
|
|
if [ -z "${REGISTRY_TOKEN}" ]; then
|
|
echo "::error::No registry token. Add a MYGITEA_NPM_TOKEN secret with write:package scope."
|
|
exit 1
|
|
fi
|
|
install -m 600 /dev/null "$NPMRC"
|
|
{
|
|
printf '@bitsquare:registry=%s\n' "$REGISTRY"
|
|
printf '//%s:_authToken=%s\n' "${REGISTRY#*://}" "$REGISTRY_TOKEN"
|
|
} >> "$NPMRC"
|
|
|
|
- name: Publish snapshots
|
|
run: |
|
|
set -euo pipefail
|
|
export npm_config_userconfig="$NPMRC"
|
|
: "${GITHUB_STEP_SUMMARY:=/dev/null}"
|
|
short_sha=$(git rev-parse --short=7 HEAD)
|
|
# Dependencies first, so the registry never briefly holds a package
|
|
# whose dependency has not landed yet.
|
|
dirs=$(node scripts/publish-order.mjs)
|
|
|
|
# Pass 1: stamp every manifest before anything is packed. `pnpm
|
|
# publish` substitutes `workspace:*` with the version the linked
|
|
# package declares at pack time, so nopy-cubes has to be carrying its
|
|
# snapshot version by the time nopy is packed.
|
|
for dir in $dirs; do
|
|
base=$(node -p "require('./${dir}/package.json').version")
|
|
# `g` prefix keeps the identifier a valid semver one even when the
|
|
# abbreviated sha happens to be all digits.
|
|
version="${base}-main.${{ github.run_number }}.g${short_sha}"
|
|
# `buildInfo.commit` is what `nopy --version` annotates itself with.
|
|
# An unknown top-level key is ignored by npm and package.json is
|
|
# always in the tarball, so it ships without any `files` change.
|
|
(cd "$dir" && npm pkg set "version=${version}" "buildInfo.commit=${short_sha}")
|
|
done
|
|
|
|
# Pass 2: publish.
|
|
for dir in $dirs; do
|
|
name=$(node -p "require('./${dir}/package.json').name")
|
|
version=$(node -p "require('./${dir}/package.json').version")
|
|
|
|
echo "::group::${name}@${version}"
|
|
# Scoped, not `--registry`: for a scoped package npm resolves
|
|
# `@scope:registry` first, so a bare flag loses to any project
|
|
# .npmrc that sets the scoped key.
|
|
if npm view "${name}@${version}" version --@bitsquare:registry="$REGISTRY" >/dev/null 2>&1; then
|
|
echo "Already published — skipping (this is a re-run of the same workflow)."
|
|
else
|
|
# pnpm, not npm: npm ships `workspace:*` verbatim and the install
|
|
# then fails with EUNSUPPORTEDPROTOCOL. --no-git-checks because
|
|
# stamping the versions above left the tree dirty.
|
|
(cd "$dir" && pnpm publish --ignore-scripts --no-git-checks --tag main --@bitsquare:registry="$REGISTRY")
|
|
fi
|
|
echo "::endgroup::"
|
|
|
|
echo "- \`pnpm add ${name}@${version}\`" >> "$GITHUB_STEP_SUMMARY"
|
|
done
|
|
|
|
- name: Remove the registry credentials
|
|
if: always()
|
|
run: rm -f "$NPMRC"
|