Skip to content

Release

Release #1

Workflow file for this run

name: Release
# Stages a version on the npm registry. Staging never prompts for 2FA, so it
# runs unattended; a maintainer then runs `npm stage approve <stage-id>` to make
# the version public.
on:
push:
tags: ['v*']
workflow_dispatch:
inputs:
dist_tag:
description: 'Override the npm dist-tag (default: derived from the version)'
required: false
default: ''
permissions:
contents: read
id-token: write
jobs:
stage:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: '22.x'
cache: npm
registry-url: https://registry.npmjs.org
# `npm stage` and `--provenance` need npm 11.15.0 or newer.
- run: npm install -g npm@^12.0.0
- run: npm ci
- run: npm run build
- run: npm run typecheck
- run: npm test
- id: meta
run: |
version=$(node -p "require('./package.json').version")
if [ "$GITHUB_REF_TYPE" = tag ] && [ "$GITHUB_REF_NAME" != "v$version" ]; then
echo "git tag $GITHUB_REF_NAME does not match package version $version" >&2
exit 1
fi
tag="${{ github.event.inputs.dist_tag }}"
if [ -z "$tag" ]; then
tag=$(node -p "(require('./package.json').version.match(/-([a-z]+)/) || [,'latest'])[1]")
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
echo "tag=$tag" >> "$GITHUB_OUTPUT"
- run: npm stage publish --tag '${{ steps.meta.outputs.tag }}' --provenance
env:
# Delete this secret and the env block once a trust relationship is
# configured with `npm trust github qca --allow-stage-publish`; npm
# then authenticates through OIDC.
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- run: |
echo "Staged qca@${{ steps.meta.outputs.version }} under tag ${{ steps.meta.outputs.tag }}." >> "$GITHUB_STEP_SUMMARY"
echo 'Approve it locally: `npm stage list qca` then `npm stage approve <stage-id>`.' >> "$GITHUB_STEP_SUMMARY"