Conversation
|
Added a Documented in the README, including the npm trusted publisher Environment field that can be pinned to the same name. |
|
Two questions came to mind:
|
There was a problem hiding this comment.
This should be its own workflow called reusable-release.yml.
The current release workflow is just for releasing new shared/reusable workflow versions.
The sync-semver-tags option is used with the nearform release action so when, for example, v7.0.1 is released, it then moves the v7 and v7.0 tags to the v7.0.1 release.
Nobody is using that release.yml. I added it for an experiment than I left it there. |
I'm using it for this repo! 😆 See #224 |
… built from user-controlled sources' Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Signed-off-by: Manuel Spigolon <behemoth89@gmail.com>
OPS fixed |
| - name: Publish to npm | ||
| run: npm publish --provenance --access public | ||
|
|
||
| - name: Push release commit | ||
| run: git push origin HEAD |
There was a problem hiding this comment.
I think the first point is still open: npm publish still runs before git push origin HEAD. In repositories where main is protected against direct pushes via GITHUB_TOKEN, the push would fail after the version is already on npm, leaving no commit or tag in the repo and making any retry fail.
Could we move the "Push release commit" step before "Publish to npm"? If the push fails, nothing gets published. It would also be worth adding a note to the README about allowing GitHub Actions to bypass branch protection (e.g. via a ruleset).
| - name: Publish to npm | |
| run: npm publish --provenance --access public | |
| - name: Push release commit | |
| run: git push origin HEAD | |
| - name: Push release commit | |
| run: git push origin HEAD | |
| - name: Publish to npm | |
| run: npm publish --provenance --access public |
What
Replaces
.github/workflows/release.ymlwith a reusable (workflow_call) release workflow that fastify repositories can call to publish a new version.The workflow:
semverinput (patch|minor|major)Bumped vX.Y.Z--ignore-scriptsnpm run --if-present release:build--provenance(OIDC, noNPM_TOKENneeded)All actions are pinned by commit SHA, using the same
actions/checkoutandactions/setup-nodeversions already declared inplugins-ci.yml.Notes
persist-credentials: trueis required here (and commented as such) because the job pushes the release commit and tag.release.yml(theoptic-release-automation-actionpipeline used to release this repository itself) is removed by this PR. Releases offastify/workflowsneed to be handled separately.README.mddocuments the inputs, the required permissions and a ready-to-copy caller snippet.