ci: fail on high/critical vulnerabilities (#73) #33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release workflow | |
| on: | |
| push: | |
| branches: | |
| - main | |
| jobs: | |
| check-changes: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 2 # We only need the current and the previous commit | |
| - name: Check if the package.version has changed | |
| id: check_changes | |
| run: | | |
| if git diff --unified=0 HEAD^ package.json | grep '"version":'; then | |
| echo "changes=detected" >> $GITHUB_OUTPUT | |
| else | |
| echo "changes=none" >> $GITHUB_OUTPUT | |
| fi | |
| outputs: | |
| changes: ${{ steps.check_changes.outputs.changes }} | |
| release: | |
| runs-on: ubuntu-latest | |
| needs: [ check-changes ] | |
| if: needs.check-changes.outputs.changes == 'detected' | |
| defaults: | |
| run: | |
| shell: nix develop --command bash {0} | |
| permissions: | |
| contents: write | |
| id-token: write # npm trusted publishing (OIDC) | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| - uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23 | |
| - uses: DeterminateSystems/magic-nix-cache-action@84c0677f58dcedf3b91f8223ce36a9ea5b3c84b7 # v15 | |
| - uses: DeterminateSystems/flake-checker-action@786422608c7bded2bbc9741ad9f91356842bf520 # v14 | |
| - name: Install dependencies | |
| run: | | |
| yarn install --immutable | |
| - name: Build | |
| run: | | |
| yarn tsc | |
| yarn build | |
| # npm publish (not yarn) because trusted publishing needs npm >= 11.5.1 | |
| - name: Release to NPM | |
| run: npm publish --access public | |
| - name: Release to GitHub releases | |
| run: errout=$(mktemp); gh release create $(cat package.json | jq -r .version) -R $GITHUB_REPOSITORY -t $(cat package.json | jq -r .version) --target $GITHUB_REF 2> $errout && true; exitcode=$?; if [ $exitcode -ne 0 ] && ! grep -q "Release.tag_name already exists" $errout; then cat $errout; exit $exitcode; fi | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| GITHUB_REPOSITORY: ${{ github.repository }} | |
| GITHUB_REF: ${{ github.ref }} |