refactor(ci): one workflow publishes, because npm allows one trusted publisher

npm revoked every classic token in December 2025 and caps a granular one at
90 days, so a token in CI would expire quarterly. OIDC is the only option
left, and it matches a package's single trusted publisher against the
filename of the workflow that starts the run. So the release lives in ci.yml
and nowhere else: release.yml and release-publish.yml are gone, along with
the released_tag the promotion used to re-cut an older commit.

Actions -> ci -> Run workflow, promote=minor|major cuts a milestone, and it
runs the whole suite first like a merge does.

Claude-Session: https://claude.ai/code/session_01ShuAy8q8ZfPi8KHxwc8JpQ
This commit is contained in:
pj committed 2026-08-16 15:30:17 +05:30
1 parent b9c9861b0a
commit f82b459609
5 files changed
+204 -281

No files matched your search

+197 -16
View File
@@ -4,7 +4,21 @@ on:
pull_request:
push:
branches: [master]
# `none` is an ordinary ci run. minor and major consolidate every patch
# released since the last milestone into one, and run the whole suite first:
# a release that skipped the device legs would be the only release nobody
# checked. The default is what stops a dispatch meant to re-run the tests
# from cutting a release by accident.
workflow_dispatch:
inputs:
promote:
description: Consolidate the released patches into a milestone
type: choice
options:
- none
- minor
- major
default: none
permissions:
contents: read
@@ -433,28 +447,195 @@ jobs:
path: runs/
retention-days: 14
# Every merge to master cuts a patch release: 0.1.4 becomes 0.1.5, published
# to npm and to GitHub Releases. It waits on the device legs as well as the
# checks, so nothing reaches a registry that the emulators and the simulator
# have not agreed on. `release.yml` promotes a run of these to a minor or a
# major by hand, and shares the steps below rather than holding a second copy.
release:
name: Release
# Every merge to master cuts a patch: 0.1.4 becomes 0.1.5. A dispatch with
# `promote` set cuts the milestone that consolidates them instead. Both wait on
# the device legs as well as the checks, so nothing reaches a registry that the
# emulators and the simulator have not agreed on, and both release the commit
# this run tested rather than whatever master drifted to while it ran.
#
# These jobs live here rather than in a workflow of their own because npm
# matches a package's one trusted publisher against the filename of the
# workflow that starts the run. See docs/development/ci.md.
release-tag:
name: Tag
needs:
- checks
- folio
- replay-ui
if: github.ref == 'refs/heads/master' && github.event_name == 'push'
uses: ./.github/workflows/release-publish.yml
if: >-
(github.event_name == 'push' && github.ref == 'refs/heads/master') ||
(github.event_name == 'workflow_dispatch' && inputs.promote != 'none')
runs-on: ubuntu-latest
permissions:
contents: write
with:
bump: patch
# The commit that triggered the run is the one to release: master may have
# moved on in the hour the device legs take.
sha: ${{ github.sha }}
secrets:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
outputs:
version: ${{ steps.next.outputs.version }}
tag: ${{ steps.next.outputs.tag }}
previous_tag: ${{ steps.next.outputs.previous_tag }}
steps:
- uses: actions/checkout@v7
with:
# The version is counted off the tags, so the tags have to be here.
fetch-depth: 0
# `inputs` is empty on a push, which leaves the resolver on its default of
# a patch: that is the bump a merge cuts.
- name: Resolve the version
id: next
run: .github/scripts/next-version.sh
env:
BUMP: ${{ inputs.promote }}
# Nothing is published until this lands, so a version that cannot be
# tagged never reaches a registry. npm is the half of a release that
# cannot be taken back and a tag is the half that can.
- name: Tag the commit
run: |
git -c user.name='github-actions[bot]' \
-c user.email='41898282+github-actions[bot]@users.noreply.github.com' \
tag -a "$TAG" -m "$TAG"
git push origin "refs/tags/$TAG"
env:
TAG: ${{ steps.next.outputs.tag }}
release-npm:
name: Release (npm)
needs: release-tag
runs-on: ubuntu-latest
permissions:
contents: read
# npm authenticates this publish over OIDC against the trusted publisher
# configured for @sanderling/spec, so the job holds no token and there is
# none to expire. npm revoked every classic token in December 2025 and
# caps a granular one at 90 days, so a token here would break quarterly.
id-token: write
steps:
- uses: actions/checkout@v7
with:
ref: ${{ needs.release-tag.outputs.tag }}
# `npm ci` below runs dependency lifecycle scripts, and no step in
# this job needs the git credential afterwards.
persist-credentials: false
- name: Set up Node 22
uses: actions/setup-node@v7
with:
node-version: "22"
registry-url: "https://registry.npmjs.org"
cache: npm
cache-dependency-path: pkg/spec/package-lock.json
# registry-url above writes an `_authToken=${NODE_AUTH_TOKEN}` line into
# .npmrc whether or not a token exists, and an npm older than 11.5.1 reads
# that empty line as "auth is configured" and never asks for an OIDC
# token, so the publish fails needing auth. Node 22 ships npm 10.
- name: Install an npm that can publish over OIDC
run: npm install -g npm@latest
- name: Install dependencies
working-directory: pkg/spec
run: npm ci
# The repo keeps package.json at 0.0.0-dev. The tags are the record of
# what has been released, and a version committed to master would be a
# second record to hold in step with them.
- name: Stamp the version
working-directory: pkg/spec
run: npm version "$VERSION" --no-git-tag-version --allow-same-version
env:
VERSION: ${{ needs.release-tag.outputs.version }}
# A publish that landed and then failed on its way out leaves npm holding
# the version, and re-running the job must not be red for it. The registry
# is asked rather than the tags: only npm knows what npm has. Only stdout
# decides, because `npm view` on a version that does not exist is empty on
# some npm releases and an error on others, and an unreachable registry
# must end in a publish that fails loudly rather than a skip that reads as
# success.
- name: Ask npm whether this version is already published
id: published
run: |
if [ -n "$(npm view "@sanderling/spec@$VERSION" version 2>/dev/null || true)" ]; then
echo "npm already has @sanderling/spec@$VERSION, nothing to publish"
echo "publish=false" >> "$GITHUB_OUTPUT"
else
echo "publish=true" >> "$GITHUB_OUTPUT"
fi
env:
VERSION: ${{ needs.release-tag.outputs.version }}
- name: Publish @sanderling/spec to npm
if: steps.published.outputs.publish == 'true'
working-directory: pkg/spec
run: npm publish --access public
release-cli:
name: Release (cli)
needs: release-tag
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v7
with:
ref: ${{ needs.release-tag.outputs.tag }}
# GoReleaser reads the tag history for its changelog.
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version-file: go.mod
cache: true
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
distribution: temurin
java-version: "17"
- name: Set up Android SDK
uses: android-actions/setup-android@40fd30fb8d7440372e1316f5d1809ec01dcd3699 # v4.0.1
- name: Cache Gradle
uses: actions/cache@v6
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: |
gradle-${{ runner.os }}-
- name: Build sidecar JAR
run: make sidecar
# GoReleaser reaches back to the release before this one on its own, which
# is right for a patch and wrong for a milestone: the notes on a 0.2.0
# consolidating six patches would cover the last merge only.
# GORELEASER_PREVIOUS_TAG moves that boundary back to the last release at
# this one's level, and an empty value leaves GoReleaser on its own
# default, which is what a patch passes.
- name: Publish the sanderling CLI to GitHub Releases
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
version: "~> v2"
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GORELEASER_PREVIOUS_TAG: ${{ needs.release-tag.outputs.previous_tag }}
release:
name: Release
if: always()
needs:
- release-npm
- release-cli
runs-on: ubuntu-latest
steps:
- name: Check the group passed
if: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled')
run: exit 1
# The docs used to build only when docs/ or the Makefile changed. A path
# filter here would have to sit on the whole workflow, so the site is rebuilt