-
Notifications
You must be signed in to change notification settings - Fork 13
132 lines (112 loc) 路 4.32 KB
/
Copy pathrelease.yml
File metadata and controls
132 lines (112 loc) 路 4.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
name: Release
on:
push:
tags:
- 'v*'
permissions:
contents: read
concurrency:
group: npm-release
cancel-in-progress: false
jobs:
verify:
uses: ./.github/workflows/ci.yml
package:
needs: verify
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5.0.0
with:
fetch-depth: 0
- name: Setup
uses: ./.github/actions/setup
- name: Validate release tag
run: |
git merge-base --is-ancestor HEAD origin/main
node scripts/check-release.mjs "$GITHUB_REF_NAME"
- name: Build package
run: yarn build
- name: Pack and inspect
run: |
mkdir artifacts
npm pack --ignore-scripts --pack-destination artifacts
node scripts/check-package.mjs artifacts/*.tgz
- name: Preserve verified package
uses: actions/upload-artifact@v4
with:
name: npm-package
path: artifacts/*.tgz
if-no-files-found: error
retention-days: 7
publish:
needs: package
runs-on: ubuntu-latest
environment: release
permissions:
contents: read
id-token: write
steps:
- name: Use Node.js 24
uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6
with:
node-version: 24
registry-url: https://registry.npmjs.org
package-manager-cache: false
- name: Download verified package
uses: actions/download-artifact@v4
with:
name: npm-package
path: artifacts
- name: Publish with npm trusted publishing
shell: bash
run: |
set -euo pipefail
package_name=react-native-ease
version="${GITHUB_REF_NAME#v}"
tarball="./artifacts/$package_name-$version.tgz"
dist_tag=latest
if [[ "$version" == *-* ]]; then dist_tag=next; fi
local_integrity="sha512-$(openssl dgst -sha512 -binary "$tarball" | openssl base64 -A)"
registry_file="$RUNNER_TEMP/registry.json"
registry_error="$RUNNER_TEMP/registry-error.txt"
if npm view "$package_name@$version" version dist.integrity --json > "$registry_file" 2> "$registry_error"; then
node -e '
const fs = require("node:fs");
const [file, version, integrity] = process.argv.slice(1);
const published = JSON.parse(fs.readFileSync(file, "utf8"));
if (published.version !== version || published["dist.integrity"] !== integrity) {
throw new Error("The existing registry version does not match this release tarball.");
}
' "$registry_file" "$version" "$local_integrity"
echo "$package_name@$version already exists with matching integrity; skipping publish."
exit 0
fi
if ! grep -qE '(^|[^A-Z])E404([^0-9]|$)' "$registry_error"; then
cat "$registry_error" >&2
echo "Registry lookup failed with an error other than E404; refusing to publish." >&2
exit 1
fi
npm publish "$tarball" --provenance --access public --tag "$dist_tag"
for attempt in {1..60}; do
if npm view "$package_name@$version" version dist.integrity --json > "$registry_file" &&
npm view "$package_name" "dist-tags.$dist_tag" --json > "$RUNNER_TEMP/dist-tag.json" &&
node -e '
const fs = require("node:fs");
const [releaseFile, tagFile, version, integrity] = process.argv.slice(1);
const published = JSON.parse(fs.readFileSync(releaseFile, "utf8"));
const tagged = JSON.parse(fs.readFileSync(tagFile, "utf8"));
process.exit(
published.version === version &&
published["dist.integrity"] === integrity &&
tagged === version
? 0
: 1,
);
' "$registry_file" "$RUNNER_TEMP/dist-tag.json" "$version" "$local_integrity"; then
exit 0
fi
sleep 10
done
echo "npm accepted publication, but registry verification is still pending. Check the exact version before retrying with the saved artifact." >&2
exit 1