Repository navigation
[V3]: bump non core transitive deps (#2845)
#1190
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| branches: | |
| - v3 | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| id-token: write | |
| packages: write | |
| concurrency: ${{ github.workflow }}-${{ github.ref }} | |
| jobs: | |
| release: | |
| name: Release | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout Repo | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| fetch-depth: 0 | |
| - uses: ./.github/actions/setup-node-pnpm-turbo | |
| with: | |
| use-prebuilt-artifacts: "false" | |
| - name: Configure npm registry for Trusted Publishing | |
| uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 | |
| with: | |
| node-version: 20.x | |
| registry-url: "https://registry.npmjs.org" | |
| - name: Update npm for Trusted Publishing | |
| # Trusted Publishing (OIDC) needs npm >= 11.5.1; npm 12+ requires | |
| # node >= 22 and this job runs node 20, so pin the last known-good | |
| # 11.x exactly. Unpin (back to npm@latest) when the job moves to | |
| # node >= 22. | |
| run: npm install -g npm@11.18.0 | |
| - name: Run Lint & Build | |
| run: pnpm exec turbo run lint && pnpm exec turbo run build | |
| - name: Check for actionable changesets | |
| id: check_changesets | |
| run: | | |
| # Read the ignore list from .changeset/config.json | |
| IGNORED=$(node -e " | |
| const config = require('./.changeset/config.json'); | |
| (config.ignore || []).forEach(p => console.log(p)); | |
| ") | |
| HAS_ACTIONABLE=false | |
| HAS_ANY=false | |
| for f in .changeset/*.md; do | |
| [ "$f" = ".changeset/README.md" ] && continue | |
| [ ! -f "$f" ] && continue | |
| HAS_ANY=true | |
| # Extract package names from the changeset frontmatter | |
| PACKAGES=$(sed -n '/^---$/,/^---$/{ /^---$/d; s/^"\(.*\)":.*/\1/p }' "$f") | |
| for pkg in $PACKAGES; do | |
| if ! echo "$IGNORED" | grep -qxF "$pkg"; then | |
| HAS_ACTIONABLE=true | |
| break 2 | |
| fi | |
| done | |
| done | |
| # Skip only when ALL pending changesets target ignored packages. | |
| # When there are no changesets at all, the action must still run | |
| # so it can publish freshly-versioned packages. | |
| if [ "$HAS_ANY" = "true" ] && [ "$HAS_ACTIONABLE" = "false" ]; then | |
| echo "All pending changesets target ignored packages — skipping changesets action." | |
| echo "should_run=false" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "should_run=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Create Release Pull Request or Publish to npm | |
| id: changesets | |
| uses: changesets/action@63a615b9cd06ba9a3e6d13796c7fbcb080a60a0b # v1.8.0 | |
| if: steps.check_changesets.outputs.should_run == 'true' | |
| with: | |
| publish: pnpm run release | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Publish already-versioned packages | |
| if: steps.check_changesets.outputs.should_run != 'true' | |
| run: pnpm run release | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Check if browse publish is needed | |
| if: github.ref == 'refs/heads/v3' | |
| id: browse_cli | |
| run: | | |
| # Restore working tree — changesets/action may have switched branches | |
| git checkout ${{ github.sha }} | |
| if git diff --quiet ${{ github.sha }}^ ${{ github.sha }} -- packages/cli/package.json; then | |
| echo "browse version did not change on this push." | |
| echo "should_publish=false" >> "$GITHUB_OUTPUT" | |
| exit 0 | |
| fi | |
| OLD_VERSION=$(git show ${{ github.sha }}^:packages/cli/package.json | node -pe "JSON.parse(require('fs').readFileSync(0, 'utf8')).version") | |
| NEW_VERSION=$(git show ${{ github.sha }}:packages/cli/package.json | node -pe "JSON.parse(require('fs').readFileSync(0, 'utf8')).version") | |
| echo "version=${NEW_VERSION}" >> "$GITHUB_OUTPUT" | |
| if [ "$OLD_VERSION" = "$NEW_VERSION" ]; then | |
| echo "browse version did not change on this push." | |
| echo "should_publish=false" >> "$GITHUB_OUTPUT" | |
| exit 0 | |
| fi | |
| echo "should_publish=true" >> "$GITHUB_OUTPUT" | |
| if npm view "browse@${NEW_VERSION}" version >/dev/null 2>&1; then | |
| echo "browse ${NEW_VERSION} is already published." | |
| echo "already_published=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "already_published=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Publish browse to npm | |
| if: steps.browse_cli.outputs.should_publish == 'true' && steps.browse_cli.outputs.already_published != 'true' | |
| run: | | |
| cd packages/cli | |
| PACK_DIR=$(mktemp -d) | |
| trap 'rm -rf "$PACK_DIR"' EXIT | |
| TARBALL=$(pnpm pack --json --pack-destination "$PACK_DIR" | node -pe "JSON.parse(require('fs').readFileSync(0, 'utf8')).filename") | |
| npm publish "$TARBALL" --provenance --access public --tag latest | |
| - name: Tag browse release | |
| if: github.ref == 'refs/heads/v3' && steps.browse_cli.outputs.should_publish == 'true' && steps.browse_cli.outputs.already_published != 'true' | |
| run: | | |
| TAG="browse@${{ steps.browse_cli.outputs.version }}" | |
| if git rev-parse -q --verify "refs/tags/${TAG}" >/dev/null; then | |
| echo "Tag ${TAG} already exists." | |
| exit 0 | |
| fi | |
| git config user.name "github-actions[bot]" | |
| git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | |
| git tag "$TAG" | |
| git push origin "$TAG" | |
| - name: Set up QEMU | |
| if: steps.browse_cli.outputs.should_publish == 'true' && steps.browse_cli.outputs.already_published != 'true' | |
| uses: docker/setup-qemu-action@06116385d9baf250c9f4dcb4858b16962ea869c3 # v4.1.0 | |
| - name: Set up Docker Buildx | |
| if: steps.browse_cli.outputs.should_publish == 'true' && steps.browse_cli.outputs.already_published != 'true' | |
| uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0 | |
| - name: Log in to GitHub Container Registry | |
| if: steps.browse_cli.outputs.should_publish == 'true' && steps.browse_cli.outputs.already_published != 'true' | |
| uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee # v4.2.0 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push browse image to GHCR | |
| if: steps.browse_cli.outputs.should_publish == 'true' && steps.browse_cli.outputs.already_published != 'true' | |
| uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf # v7.2.0 | |
| with: | |
| context: packages/cli | |
| file: packages/cli/Dockerfile | |
| platforms: linux/amd64,linux/arm64 | |
| push: true | |
| provenance: false | |
| build-args: | | |
| BROWSE_VERSION=${{ steps.browse_cli.outputs.version }} | |
| tags: | | |
| ghcr.io/browserbase/browse:${{ steps.browse_cli.outputs.version }} | |
| ghcr.io/browserbase/browse:latest | |
| - name: Publish browse canary | |
| if: github.ref == 'refs/heads/v3' && steps.browse_cli.outputs.should_publish != 'true' | |
| run: | | |
| # Skip if no browse files changed in this push | |
| if git diff --quiet ${{ github.sha }}^ ${{ github.sha }} -- packages/cli/; then | |
| echo "No browse changes in this push, skipping canary." | |
| exit 0 | |
| fi | |
| cd packages/cli | |
| BASE_VERSION=$(node -p "require('./package.json').version") | |
| SHORT_SHA=$(echo "${{ github.sha }}" | cut -c1-7) | |
| CANARY_VERSION="${BASE_VERSION}-alpha-${SHORT_SHA}" | |
| if npm view "browse@${CANARY_VERSION}" version >/dev/null 2>&1; then | |
| echo "browse canary ${CANARY_VERSION} is already published." | |
| exit 0 | |
| fi | |
| # Temporarily set canary version for pnpm pack | |
| node -e " | |
| const pkg = require('./package.json'); | |
| pkg.version = '${CANARY_VERSION}'; | |
| require('fs').writeFileSync('package.json', JSON.stringify(pkg, null, 2) + '\n'); | |
| " | |
| PACK_DIR=$(mktemp -d) | |
| trap 'git checkout -- package.json; rm -rf "$PACK_DIR"' EXIT | |
| TARBALL=$(pnpm pack --json --pack-destination "$PACK_DIR" | node -pe "JSON.parse(require('fs').readFileSync(0, 'utf8')).filename") | |
| npm publish "$TARBALL" --provenance --access public --tag alpha | |
| echo "Published browse@${CANARY_VERSION}" | |
| - name: Publish Canary | |
| if: github.ref == 'refs/heads/v3' | |
| run: | | |
| git checkout ${{ github.sha }} | |
| pnpm run release-canary | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |