Skip to content

ci: fail on high/critical vulnerabilities (#73) #33

ci: fail on high/critical vulnerabilities (#73)

ci: fail on high/critical vulnerabilities (#73) #33

Workflow file for this run

name: Release workflow
on:
push:
branches:
- main
jobs:
check-changes:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 2 # We only need the current and the previous commit
- name: Check if the package.version has changed
id: check_changes
run: |
if git diff --unified=0 HEAD^ package.json | grep '"version":'; then
echo "changes=detected" >> $GITHUB_OUTPUT
else
echo "changes=none" >> $GITHUB_OUTPUT
fi
outputs:
changes: ${{ steps.check_changes.outputs.changes }}
release:
runs-on: ubuntu-latest
needs: [ check-changes ]
if: needs.check-changes.outputs.changes == 'detected'
defaults:
run:
shell: nix develop --command bash {0}
permissions:
contents: write
id-token: write # npm trusted publishing (OIDC)
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: DeterminateSystems/nix-installer-action@3138316df39ed29be04236d7ffc686fa525866aa # v23
- uses: DeterminateSystems/magic-nix-cache-action@84c0677f58dcedf3b91f8223ce36a9ea5b3c84b7 # v15
- uses: DeterminateSystems/flake-checker-action@786422608c7bded2bbc9741ad9f91356842bf520 # v14
- name: Install dependencies
run: |
yarn install --immutable
- name: Build
run: |
yarn tsc
yarn build
# npm publish (not yarn) because trusted publishing needs npm >= 11.5.1
- name: Release to NPM
run: npm publish --access public
- name: Release to GitHub releases
run: errout=$(mktemp); gh release create $(cat package.json | jq -r .version) -R $GITHUB_REPOSITORY -t $(cat package.json | jq -r .version) --target $GITHUB_REF 2> $errout && true; exitcode=$?; if [ $exitcode -ne 0 ] && ! grep -q "Release.tag_name already exists" $errout; then cat $errout; exit $exitcode; fi
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
GITHUB_REF: ${{ github.ref }}