fix: preserve Windows lock retry policy #35
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish to npm | |
| on: | |
| push: | |
| tags: | |
| - "v*" | |
| concurrency: | |
| group: publish-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| id-token: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v6 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v6 | |
| with: | |
| node-version: 24.17.0 | |
| registry-url: https://registry.npmjs.org | |
| package-manager-cache: false | |
| - name: Verify tag matches package.json version | |
| run: | | |
| TAG_VERSION="${GITHUB_REF#refs/tags/v}" | |
| PKG_VERSION=$(node -p "require('./package.json').version") | |
| if [ "${TAG_VERSION}" != "${PKG_VERSION}" ]; then | |
| echo "Tag v${TAG_VERSION} does not match package.json version ${PKG_VERSION}" | |
| exit 1 | |
| fi | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Run package release checks | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| AUTHORITY_SOURCE="github-actions:${GITHUB_WORKFLOW}:${GITHUB_EVENT_NAME}:${GITHUB_REPOSITORY}:${GITHUB_REF}:${GITHUB_SHA}" | |
| POLICY_DIGEST="$(node -e 'const {sha256}=require("./hooks/_runtime/content-identity.cjs"); process.stdout.write(sha256(JSON.stringify({workflow:process.env.GITHUB_WORKFLOW,event:process.env.GITHUB_EVENT_NAME,repository:process.env.GITHUB_REPOSITORY,ref:process.env.GITHUB_REF,commit:process.env.GITHUB_SHA,purpose:"release"})))')" | |
| BUDGET_DIGEST="$( | |
| node scripts/run-validation.js --route package-release --purpose release --actor release-pipeline --authority-source "${AUTHORITY_SOURCE}" --policy-digest "${POLICY_DIGEST}" --plan --json | | |
| node -e 'const fs = require("fs"); const envelope = JSON.parse(fs.readFileSync(0, "utf8")); const plan = envelope?.data?.plan; const digest = plan?.budgetCard?.digest; if (envelope?.ok !== true || plan?.routeResolved !== "full" || plan?.verificationPurpose !== "release" || plan?.candidateStable !== true || !/^[a-f0-9]{64}$/.test(String(digest || ""))) process.exit(1); process.stdout.write(digest)' | |
| )" | |
| node scripts/run-validation.js --route package-release --purpose release --actor release-pipeline --authority-source "${AUTHORITY_SOURCE}" --policy-digest "${POLICY_DIGEST}" --approve-plan "${BUDGET_DIGEST}" | |
| - name: Create the exact qualified release artifact | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| RELEASE_DIR="${RUNNER_TEMP}/devcodex-release-artifact" | |
| mkdir -p "${RELEASE_DIR}" | |
| CREATE_RESULT="${RUNNER_TEMP}/devcodex-release-create-result.json" | |
| node scripts/exact-release-artifact.js create --output-dir "${RELEASE_DIR}" > "${CREATE_RESULT}" | |
| RELEASE_ARTIFACT_PATH="$(node -e 'const fs=require("fs"); const value=JSON.parse(fs.readFileSync(process.argv[1],"utf8")); if(value.ok!==true||!value.artifactPath) process.exit(1); process.stdout.write(value.artifactPath)' "${CREATE_RESULT}")" | |
| echo "RELEASE_DIR=${RELEASE_DIR}" >> "${GITHUB_ENV}" | |
| echo "RELEASE_ARTIFACT_PATH=${RELEASE_ARTIFACT_PATH}" >> "${GITHUB_ENV}" | |
| - name: Verify the exact release artifact | |
| run: node scripts/exact-release-artifact.js verify --output-dir "${RELEASE_DIR}" | |
| - name: Publish the exact qualified tarball | |
| run: npm publish "${RELEASE_ARTIFACT_PATH}" --ignore-scripts --provenance --access public | |
| env: | |
| NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} | |
| - name: Verify registry identity and provenance | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| for attempt in $(seq 1 12); do | |
| if node scripts/exact-release-artifact.js postcheck --output-dir "${RELEASE_DIR}"; then | |
| exit 0 | |
| fi | |
| if [ "${attempt}" -eq 12 ]; then | |
| echo "Published artifact did not converge to the qualified identity" | |
| exit 1 | |
| fi | |
| sleep 10 | |
| done | |
| - name: Create the GitHub Release from the verified tag and artifact | |
| shell: bash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| set -euo pipefail | |
| gh release create "${GITHUB_REF_NAME}" "${RELEASE_ARTIFACT_PATH}" \ | |
| --verify-tag \ | |
| --title "DevCodex ${GITHUB_REF_NAME}" \ | |
| --notes-file "changelogs/releases/${GITHUB_REF_NAME}.md" |