refactor(ci): one workflow publishes, because npm allows one trusted publisher

npm revoked every classic token in December 2025 and caps a granular one at
90 days, so a token in CI would expire quarterly. OIDC is the only option
left, and it matches a package's single trusted publisher against the
filename of the workflow that starts the run. So the release lives in ci.yml
and nowhere else: release.yml and release-publish.yml are gone, along with
the released_tag the promotion used to re-cut an older commit.

Actions -> ci -> Run workflow, promote=minor|major cuts a milestone, and it
runs the whole suite first like a merge does.

Claude-Session: https://claude.ai/code/session_01ShuAy8q8ZfPi8KHxwc8JpQ
This commit is contained in:
pj committed 2026-08-16 15:30:17 +05:30
1 parent b9c9861b0a
commit f82b459609
5 files changed
+204 -281

No files matched your search

+2 -15
View File
@@ -44,12 +44,6 @@ expect_version() { # <want> <case>
[ "$status" = 0 ] || fail "$2: exit $status, want 0"
}
# The manual pipeline re-cuts the commit this tag points at, so a wrong answer
# here releases the wrong code under the right version.
expect_released_tag() { # <want, empty for none> <case>
grep -qxF -- "released_tag=$1" "$outputs" \
|| fail "$2: $(grep '^released_tag=' "$outputs" || echo 'no released_tag'), want released_tag=$1"
}
# How far back GoReleaser reaches for the notes. Empty leaves it on its own
# default, which is the release immediately before this one.
@@ -65,28 +59,23 @@ expect_refused() { # <case> <message fragment>
}
# A repository with nothing released yet starts the line at 0.0.1 rather than
# reissuing 0.0.0, and has no release to promote or to write notes against.
# reissuing 0.0.0, and has no earlier release to write notes against.
resolve first patch
expect_version 0.0.1 first
expect_released_tag "" first
expect_previous_tag "" first
# The rc tags this repository carries are candidates for 0.0.1, so the first
# stable release is 0.0.1 and not 0.0.2, and a candidate is not a release to
# promote.
# stable release is 0.0.1 and not 0.0.2.
resolve rcs patch v0.0.1-rc1 v0.0.1-rc4
expect_version 0.0.1 rcs
expect_released_tag "" rcs
resolve patch patch v1.2.3
expect_version 1.2.4 patch
expect_released_tag v1.2.3 patch
# A patch already follows the release before it, so GoReleaser is left alone.
expect_previous_tag "" patch
resolve minor minor v1.2.3
expect_version 1.3.0 minor
expect_released_tag v1.2.3 minor
resolve major major v1.2.3
expect_version 2.0.0 major
@@ -95,12 +84,10 @@ expect_version 2.0.0 major
# next patch off the wrong release and hand back 0.9.1.
resolve ordering patch v0.9.0 v0.10.0
expect_version 0.10.1 ordering
expect_released_tag v0.10.0 ordering
# A tag that is not a release is not a base to count from.
resolve noise patch v1.2.3 nightly v2.0.0-rc1 vfoo
expect_version 1.2.4 noise
expect_released_tag v1.2.3 noise
# A bump counts off the highest release, so releasing twice in a row advances
# twice rather than landing on the tag the first one just cut.
+5 -10
View File
@@ -4,10 +4,9 @@
# nothing in the tree holds it: no commit has to land on master to advance a
# version, and a release cannot disagree with a package.json someone edited.
#
# BUMP is major, minor or patch. Writes `version`, `tag`, `released_tag` and
# `previous_tag` to $GITHUB_OUTPUT when it is set. `released_tag` is the release
# this one follows, and is the commit a promotion re-cuts. `previous_tag` is how
# far back the release notes should reach.
# BUMP is major, minor or patch. Writes `version`, `tag` and `previous_tag` to
# $GITHUB_OUTPUT when it is set. `previous_tag` is how far back the release
# notes should reach.
set -euo pipefail
bump="${BUMP:-patch}"
@@ -22,11 +21,8 @@ releases() { # <sed script selecting the tags to consider>
}
stable='s/^v\([0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*\)$/\1/p'
released="$(releases "$stable" | tail -1)"
released_tag=""
if [ -n "$released" ]; then released_tag="v$released"; fi
base="${released:-0.0.0}"
base="$(releases "$stable" | tail -1)"
base="${base:-0.0.0}"
IFS=. read -r major minor patch <<<"$base"
case "$bump" in
@@ -71,7 +67,6 @@ if [ -n "${GITHUB_OUTPUT:-}" ]; then
{
echo "version=$version"
echo "tag=$tag"
echo "released_tag=$released_tag"
echo "previous_tag=$previous_tag"
} >> "$GITHUB_OUTPUT"
fi