refactor(ci): one workflow publishes, because npm allows one trusted publisher

npm revoked every classic token in December 2025 and caps a granular one at
90 days, so a token in CI would expire quarterly. OIDC is the only option
left, and it matches a package's single trusted publisher against the
filename of the workflow that starts the run. So the release lives in ci.yml
and nowhere else: release.yml and release-publish.yml are gone, along with
the released_tag the promotion used to re-cut an older commit.

Actions -> ci -> Run workflow, promote=minor|major cuts a milestone, and it
runs the whole suite first like a merge does.

Claude-Session: https://claude.ai/code/session_01ShuAy8q8ZfPi8KHxwc8JpQ
This commit is contained in:
pj committed 2026-08-16 15:30:17 +05:30
1 parent b9c9861b0a
commit f82b459609
5 files changed
+204 -281

No files matched your search

+5 -10
View File
@@ -4,10 +4,9 @@
# nothing in the tree holds it: no commit has to land on master to advance a
# version, and a release cannot disagree with a package.json someone edited.
#
# BUMP is major, minor or patch. Writes `version`, `tag`, `released_tag` and
# `previous_tag` to $GITHUB_OUTPUT when it is set. `released_tag` is the release
# this one follows, and is the commit a promotion re-cuts. `previous_tag` is how
# far back the release notes should reach.
# BUMP is major, minor or patch. Writes `version`, `tag` and `previous_tag` to
# $GITHUB_OUTPUT when it is set. `previous_tag` is how far back the release
# notes should reach.
set -euo pipefail
bump="${BUMP:-patch}"
@@ -22,11 +21,8 @@ releases() { # <sed script selecting the tags to consider>
}
stable='s/^v\([0-9][0-9]*\.[0-9][0-9]*\.[0-9][0-9]*\)$/\1/p'
released="$(releases "$stable" | tail -1)"
released_tag=""
if [ -n "$released" ]; then released_tag="v$released"; fi
base="${released:-0.0.0}"
base="$(releases "$stable" | tail -1)"
base="${base:-0.0.0}"
IFS=. read -r major minor patch <<<"$base"
case "$bump" in
@@ -71,7 +67,6 @@ if [ -n "${GITHUB_OUTPUT:-}" ]; then
{
echo "version=$version"
echo "tag=$tag"
echo "released_tag=$released_tag"
echo "previous_tag=$previous_tag"
} >> "$GITHUB_OUTPUT"
fi