Merge pull request #158 from taras/release/bump-0.5.1 #11
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish packages | |
| # GENERATED by scripts/gen-publish-workflow.md — do not edit by hand. | |
| # Run `deno task gen:publish-workflow` and commit the result. | |
| # See specs/release-process-spec.md. | |
| on: | |
| push: | |
| tags: ["v*"] | |
| permissions: | |
| contents: read | |
| actions: read # the version job polls the release.yml run | |
| id-token: write # npm OIDC in publish-one.yml, JSR OIDC in the jsr job | |
| jobs: | |
| version: | |
| runs-on: ubuntu-latest | |
| outputs: | |
| value: ${{ steps.resolve.outputs.value }} | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - id: resolve | |
| run: | | |
| TAG="${{ github.ref_name }}" | |
| echo "value=${TAG#v}" >> "$GITHUB_OUTPUT" | |
| # Refuse a tag the manifests do not declare (spec §2). | |
| - name: Validate the manifests declare this version | |
| run: | | |
| VERSION="${{ steps.resolve.outputs.value }}" | |
| for f in packages/durable-streams/deno.json packages/runtime/deno.json packages/core/deno.json packages/acp/deno.json packages/testing/deno.json packages/test-agent/deno.json packages/cli/deno.json packages/code-review-agent/deno.json; do | |
| declared="$(jq -r .version "$f")" | |
| if [ "$declared" != "$VERSION" ]; then | |
| echo "::error::$f declares $declared, not $VERSION — the tag does not match the manifests" | |
| exit 1 | |
| fi | |
| done | |
| # Packages publish only after the binaries exist (spec §1): poll the | |
| # release.yml run for this commit and fail if it fails. | |
| - name: Wait for the binary release to succeed | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| for i in $(seq 1 60); do | |
| RUNS="repos/${{ github.repository }}/actions/workflows/release.yml/runs?head_sha=${{ github.sha }}&per_page=1" | |
| STATUS="$(gh api "$RUNS" --jq '.workflow_runs[0].status // "queued"')" | |
| CONCLUSION="$(gh api "$RUNS" --jq '.workflow_runs[0].conclusion // "none"')" | |
| if [ "$STATUS" = "completed" ]; then | |
| if [ "$CONCLUSION" = "success" ]; then | |
| echo "release.yml succeeded — binaries are published" | |
| exit 0 | |
| fi | |
| echo "::error::release.yml concluded '$CONCLUSION' — refusing to publish packages without binaries" | |
| exit 1 | |
| fi | |
| sleep 30 | |
| done | |
| echo "::error::timed out waiting for release.yml" | |
| exit 1 | |
| durable-streams: | |
| needs: [version] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/durable-streams | |
| version: ${{ needs.version.outputs.value }} | |
| runtime: | |
| needs: [version] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/runtime | |
| version: ${{ needs.version.outputs.value }} | |
| core: | |
| needs: [version, durable-streams, runtime] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/core | |
| version: ${{ needs.version.outputs.value }} | |
| acp: | |
| needs: [version, core, runtime] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/acp | |
| version: ${{ needs.version.outputs.value }} | |
| testing: | |
| needs: [version, core, durable-streams] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/testing | |
| version: ${{ needs.version.outputs.value }} | |
| test-agent: | |
| needs: [version, acp, core, durable-streams, runtime, testing] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/test-agent | |
| version: ${{ needs.version.outputs.value }} | |
| cli: | |
| needs: [version, acp, core, durable-streams, runtime, test-agent, testing] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/cli | |
| version: ${{ needs.version.outputs.value }} | |
| code-review-agent: | |
| needs: [version] | |
| uses: ./.github/workflows/publish-one.yml | |
| with: | |
| package: packages/code-review-agent | |
| version: ${{ needs.version.outputs.value }} | |
| jsr: | |
| needs: [version] | |
| runs-on: ubuntu-latest | |
| # Same gate as the npm jobs: only actors permitted on this environment can | |
| # publish (spec §5). | |
| environment: npm-publish | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - uses: denoland/setup-deno@e95548e56dfa95d4e1a28d6f422fafe75c4c26fb # v2.0.3 | |
| with: | |
| deno-version: v2.9.1 | |
| # deno publish filters already-published members itself, so a rerun after | |
| # a partial publish completes the members that are missing (spec §7). | |
| - name: Publish the workspace to JSR | |
| run: deno publish |