-
Notifications
You must be signed in to change notification settings - Fork 0
189 lines (181 loc) · 8.32 KB
/
Copy pathrelease-please.yml
File metadata and controls
189 lines (181 loc) · 8.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
name: release-please
on:
push:
branches: [main]
# Recovery lever for a release that was tagged on GitHub but never reached
# npm (e.g. the release run died between tagging and emitting its outputs).
# Trusted publishing authorizes it because it runs from this same workflow file.
workflow_dispatch:
inputs:
release_tag:
description: "Existing release tag to publish to npm (e.g. sandbox-v0.4.0)"
required: true
type: string
# Only one release run at a time; never cancel an in-progress publish.
concurrency:
group: release-please-${{ github.ref }}
cancel-in-progress: false
permissions: {}
jobs:
release-please:
if: ${{ github.event_name == 'push' }}
runs-on: ubuntu-latest
permissions:
actions: write # restart checks after GITHUB_TOKEN updates release PR branches
contents: write # create release tags, GitHub releases, and the release PR
pull-requests: write # open/update the release PR
outputs:
# Per-package outputs. The path contains a '/', so it MUST be read with
# JS-style bracket+quote indexing, not dot access.
sandbox_released: ${{ steps.release.outputs['packages/sandbox--release_created'] }}
agent_released: ${{ steps.release.outputs['packages/agent--release_created'] }}
provider_released: ${{ steps.release.outputs['packages/provider--release_created'] }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
env:
# Keep this write-scoped token inside the action step: the action
# installs the tools itself, and no later step runs `mise install`.
# Pre-setting it stops mise-action from exporting its `github_token`
# input to later steps (and so to dependency lifecycle scripts) via
# GITHUB_ENV. The publish jobs below use the same pattern.
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
# Avoid release-in-progress 404s; mirrors pnpm's minimumReleaseAge posture.
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
# Runs release-please as a library with our AI changelog-notes hook
# registered (changelog-type: "ai" in the config). release-please itself
# writes the CHANGELOG, the release PR, and the GitHub Release — nothing
# downstream overwrites its output. The harness emits the same per-path
# outputs the stock action did, so the publish jobs below are unchanged.
- name: Run release-please (AI changelog notes)
id: release
run: pnpm --filter @coder/release-please-ai exec tsx src/cli.ts
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
# Publish jobs authenticate to npm via OIDC trusted publishing (no NPM_TOKEN).
# Requires a trusted publisher configured per package on npmjs.com pointing at
# this repo + workflow file. Provenance is attested via the OIDC id-token.
# The publish conditions use !cancelled() so an emitted release still publishes
# even if the release-please job later failed on housekeeping: its outputs are
# written the moment releases are tagged, and a tagged release only publishes
# from this run (re-runs see it as already tagged and skip it).
publish-sandbox:
needs: release-please
if: ${{ !cancelled() && needs.release-please.outputs.sandbox_released == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
- run: pnpm --filter @coder/ai-sdk-sandbox build
- name: Publish @coder/ai-sdk-sandbox
run: pnpm --filter @coder/ai-sdk-sandbox publish --provenance --access public --no-git-checks
publish-agent:
needs: release-please
if: ${{ !cancelled() && needs.release-please.outputs.agent_released == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
- run: pnpm --filter @coder/ai-sdk-agent build
- name: Publish @coder/ai-sdk-agent
run: pnpm --filter @coder/ai-sdk-agent publish --provenance --access public --no-git-checks
publish-provider:
needs: release-please
if: ${{ !cancelled() && needs.release-please.outputs.provider_released == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- run: pnpm install --frozen-lockfile
- run: pnpm --filter @coder/ai-sdk-provider build
- name: Publish @coder/ai-sdk-provider
run: pnpm --filter @coder/ai-sdk-provider publish --provenance --access public --no-git-checks
# Manual recovery (workflow_dispatch): publish an already-tagged release whose
# npm publish never ran. Builds the tag's checkout and refuses to run if the
# tag doesn't match the package.json version or the version is already on npm.
publish-recovery:
if: ${{ github.event_name == 'workflow_dispatch' }}
runs-on: ubuntu-latest
permissions:
contents: read # checkout only
id-token: write # OIDC: trusted-publishing auth + provenance
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.release_tag }}
persist-credentials: false
- name: Install node and pnpm via mise
uses: jdx/mise-action@7a4e45a543138629540c9a1616d08632b893e492 # v5.0.1
env:
MISE_GITHUB_TOKEN: ${{ github.token }}
with:
minimum_release_age: 24h
- name: Resolve package from tag
id: pkg
env:
RELEASE_TAG: ${{ inputs.release_tag }}
run: |
case "$RELEASE_TAG" in
sandbox-v*) name="@coder/ai-sdk-sandbox" path="packages/sandbox" ;;
agent-v*) name="@coder/ai-sdk-agent" path="packages/agent" ;;
provider-v*) name="@coder/ai-sdk-provider" path="packages/provider" ;;
*) echo "unrecognized release tag: $RELEASE_TAG" >&2; exit 1 ;;
esac
version="${RELEASE_TAG#*-v}"
manifest_version="$(jq -r .version "$path/package.json")"
if [ "$manifest_version" != "$version" ]; then
echo "tag version $version does not match $path/package.json version $manifest_version" >&2
exit 1
fi
if npm view "$name@$version" version >/dev/null 2>&1; then
echo "$name@$version is already published" >&2
exit 1
fi
echo "name=$name" >> "$GITHUB_OUTPUT"
- run: pnpm install --frozen-lockfile
- run: pnpm --filter "$PACKAGE_NAME" build
env:
PACKAGE_NAME: ${{ steps.pkg.outputs.name }}
- name: Publish ${{ inputs.release_tag }}
run: pnpm --filter "$PACKAGE_NAME" publish --provenance --access public --no-git-checks
env:
PACKAGE_NAME: ${{ steps.pkg.outputs.name }}