|
5 | 5 | tags: |
6 | 6 | - "v[0-9]+.[0-9]+.[0-9]+" |
7 | 7 | - "v[0-9]+.[0-9]+.[0-9]+-*" |
| 8 | + # Fallback for when a tag push doesn't enqueue a run (GitHub event-delivery |
| 9 | + # gaps). Triggers are workflow-wide in Actions, so the tag input is |
| 10 | + # re-derived as RELEASE_REF_NAME (see the `ref` step) and every step below |
| 11 | + # uses that instead of GITHUB_REF_NAME; the tag is fetched and checked out |
| 12 | + # at its exact commit. |
| 13 | + workflow_dispatch: |
| 14 | + inputs: |
| 15 | + tag: |
| 16 | + description: "Release tag, e.g. v0.9.0-next.0 (must exist)" |
| 17 | + required: true |
| 18 | + type: string |
8 | 19 |
|
9 | 20 | # Default to no permissions; elevate per-job (least privilege). |
10 | 21 | permissions: {} |
11 | 22 |
|
12 | | -# Never run two publishes for the same ref concurrently. |
| 23 | +# Never run two publishes for the same release concurrently (dispatch runs |
| 24 | +# carry the branch ref, so key the group on the resolved release ref). |
13 | 25 | concurrency: |
14 | | - group: release-${{ github.ref }} |
| 26 | + group: release-${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref }} |
15 | 27 | cancel-in-progress: false |
16 | 28 |
|
17 | 29 | jobs: |
|
22 | 34 | contents: write # create the GitHub Release |
23 | 35 | id-token: write # npm provenance attestation |
24 | 36 | steps: |
| 37 | + - name: Resolve release ref |
| 38 | + id: ref |
| 39 | + run: | |
| 40 | + if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then |
| 41 | + echo "RELEASE_REF_NAME=${{ inputs.tag }}" >> "$GITHUB_OUTPUT" |
| 42 | + else |
| 43 | + echo "RELEASE_REF_NAME=$GITHUB_REF_NAME" >> "$GITHUB_OUTPUT" |
| 44 | + fi |
| 45 | +
|
25 | 46 | - uses: actions/checkout@v7 |
| 47 | + with: |
| 48 | + # Manual runs dispatch from a branch (usually main); check out the |
| 49 | + # tag's exact commit so tag and package.json agree. |
| 50 | + ref: ${{ steps.ref.outputs.RELEASE_REF_NAME }} |
| 51 | + fetch-depth: 0 |
26 | 52 |
|
27 | 53 | - name: Set up Node |
28 | 54 | uses: actions/setup-node@v7 |
|
37 | 63 | - name: Verify tag matches package.json version |
38 | 64 | run: | |
39 | 65 | PKG_VERSION="$(node -p "require('./package.json').version")" |
40 | | - TAG_VERSION="${GITHUB_REF_NAME#v}" |
| 66 | + TAG_NAME="${{ steps.ref.outputs.RELEASE_REF_NAME }}" |
| 67 | + TAG_VERSION="${TAG_NAME#v}" |
41 | 68 | if [[ "$PKG_VERSION" != "$TAG_VERSION" ]]; then |
42 | | - echo "::error::git tag $GITHUB_REF_NAME (=$TAG_VERSION) does not match package.json version $PKG_VERSION" |
| 69 | + echo "::error::tag $TAG_NAME (=$TAG_VERSION) does not match package.json version $PKG_VERSION" |
43 | 70 | exit 1 |
44 | 71 | fi |
45 | 72 |
|
|
73 | 100 | - name: Classify release from tag |
74 | 101 | id: version |
75 | 102 | run: | |
76 | | - VERSION="${GITHUB_REF_NAME#v}" |
| 103 | + TAG_NAME="${{ steps.ref.outputs.RELEASE_REF_NAME }}" |
| 104 | + VERSION="${TAG_NAME#v}" |
77 | 105 | echo "VERSION=$VERSION" >> "$GITHUB_OUTPUT" |
78 | 106 | if [[ "$VERSION" == *-* ]]; then |
79 | 107 | echo "NPM_TAG=next" >> "$GITHUB_OUTPUT" |
|
0 commit comments