diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml new file mode 100644 index 0000000..c354ae8 --- /dev/null +++ b/.github/workflows/publish.yml @@ -0,0 +1,47 @@ +name: Publish to npm + +on: + release: + types: + - published + # Manual backfill (e.g. publishing an existing tag after wiring OIDC). + workflow_dispatch: + +permissions: + contents: read + id-token: write + +concurrency: + group: npm-${{ github.event.release.tag_name || github.run_id }} + cancel-in-progress: false + +jobs: + publish: + name: publish + runs-on: ubuntu-latest + timeout-minutes: 15 + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 + + - name: Setup Node.js + uses: actions/setup-node@249970729cb0ef3589644e2896645e5dc5ba9c38 # v6 + with: + node-version: 24 + registry-url: https://registry.npmjs.org/ + package-manager-cache: false + + - name: Install dependencies + run: npm ci + + - name: Verify build and tests + run: npm test + + - name: Verify package contents + run: npm pack --dry-run + + # OIDC trusted publishing (no tokens): requires the trusted publisher + # configured on npmjs.com for this repo + publish.yml workflow. + - name: Publish with provenance + run: npm publish --access public --provenance