Repository navigation
100 lines (88 loc) · 3.66 KB
/
Copy pathpkg.yml
File metadata and controls
100 lines (88 loc) · 3.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
name: Package Preview
# Builds, packs, and publishes preview packages from the job that built them.
# The job proves it is the run it claims to be by uploading the manifest as
# an artifact of its own run, which only the job's runtime token can do; the
# registry reads the artifact list back through the GitHub API. That works
# the same for pushes, same-repo pull requests, and fork pull requests, and
# needs no permissions or secrets. The upload has to be an action step: the
# runtime token is never exposed to `run:` steps.
on:
push:
branches: [main]
paths:
- "submodules/distilled"
- "packages/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "pnpm-workspace.yaml"
- "tsconfig.json"
- ".github/workflows/pkg.yml"
pull_request:
types: [opened, synchronize, reopened, labeled]
paths:
- "submodules/distilled"
- "packages/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "pnpm-workspace.yaml"
- "tsconfig.json"
- ".github/workflows/pkg.yml"
permissions:
contents: read
env:
PKG_REGISTRY: https://pkg.alchemy.run
concurrency:
# Label events get a group per label so adding an unrelated label (such as
# `deploy-website`) never cancels the run for the latest push.
group: pkg-${{ github.event.pull_request.number || github.ref }}${{ github.event.action == 'labeled' && format('-{0}', github.event.label.name) || '' }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
publish:
name: Publish preview packages
# `labeled` is only for `force-ci`, which repacks every package.
if: github.event.action != 'labeled' || github.event.label.name == 'force-ci'
runs-on: blacksmith-8vcpu-ubuntu-2404
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Pack the pull request head rather than the synthetic merge commit,
# so every tarball is addressed by a commit that exists on the PR.
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
- name: Checkout distilled
run: git submodule update --init --depth=1 --checkout -- submodules/distilled
- name: Setup pnpm, Node.js, Bun and install dependencies
uses: pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b # v2.1.0
with:
cache: true
install: true
require-lockfile: true
- name: Build packages
run: pnpm build:pkg
# Workspace dependencies of the listed packages, such as the
# @distilled.cloud SDKs, are packed automatically under a collapsed
# "Transitive Dependencies" group. Keep the @alchemy.run
# list in sync with `build:pkg`.
- name: Pack packages
id: pack
run: >-
pnpm exec pkg pack
${{ contains(github.event.pull_request.labels.*.name, 'force-ci') && '--all' || '' }}
--rebuild-all-path 'scripts/package-build.ts'
--group 'alchemy=./packages/alchemy'
--group '@alchemy.run[Collapsed]=./packages/{better-auth,cloudflare-runtime,frontend-frameworks,node-utils,floci,pkg}'
- name: Vouch for the manifest
if: steps.pack.outputs.package-count != '0'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ steps.pack.outputs.artifact-name }}
path: .pkg/pkg-manifest.json
include-hidden-files: true
if-no-files-found: error
retention-days: 1
- name: Publish packages
if: steps.pack.outputs.package-count != '0'
run: pnpm exec pkg publish