diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index ac17520..d742ce6 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -9,9 +9,13 @@ on: jobs: build-test: runs-on: ubuntu-latest + permissions: + contents: read + checks: write + pull-requests: write steps: - uses: actions/checkout@v3 - - uses: ArtiomTr/jest-coverage-report-action@v2 + - uses: ArtiomTr/jest-coverage-report-action@7f750dd50f5585533321eb7ebc482b936b49a5d4 # v2 id: coverage-utils-js with: output: comment, report-markdown diff --git a/.github/workflows/npm-publish.yml b/.github/workflows/npm-publish.yml deleted file mode 100644 index 3f8b11c..0000000 --- a/.github/workflows/npm-publish.yml +++ /dev/null @@ -1,40 +0,0 @@ -# This workflow publishes packages when a GitHub Release is created for a version tag. -# For more information see: https://help.github.com/actions/language-and-framework-guides/publishing-nodejs-packages - -name: Publish package to NPM repository -on: - release: - types: [created] - -jobs: - publish-npm: - if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - with: - ref: ${{ github.event.release.tag_name }} - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://registry.npmjs.org' - - run: npm ci - - run: npm publish - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - publish-git: - if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4 - with: - ref: ${{ github.event.release.tag_name }} - - uses: actions/setup-node@v4 - with: - node-version: '22.x' - registry-url: 'https://npm.pkg.github.com' - scope: '@contentstack' - - run: npm ci - - run: npm publish --access public - env: - NODE_AUTH_TOKEN: ${{ secrets.GIT_TOKEN }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..cd933f4 --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,51 @@ +name: Publish package to npmjs registry +on: + release: + types: [published] + +jobs: + publish-npm: + if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} + runs-on: ubuntu-latest + permissions: + contents: read + id-token: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://registry.npmjs.org/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish --access public --tag ${{ github.event.release.prerelease && 'beta' || 'latest' }} + + publish-github: + if: ${{ startsWith(github.event.release.tag_name, 'v') && !github.event.release.draft }} + runs-on: ubuntu-latest + permissions: + contents: read + packages: write + steps: + - uses: actions/checkout@v7 + with: + ref: ${{ github.event.release.tag_name }} + persist-credentials: false + - uses: actions/setup-node@v7 + with: + node-version: 24 + registry-url: https://npm.pkg.github.com/ + cache: 'npm' + - run: npm ci + - name: Update npm + run: npm install -g npm@latest + - name: Release + run: npm publish + env: + NODE_AUTH_TOKEN: ${{ github.token }} diff --git a/.talismanrc b/.talismanrc index 40570f0..f4811d0 100644 --- a/.talismanrc +++ b/.talismanrc @@ -4,3 +4,5 @@ fileignoreconfig: - filecontent - filename: package-lock.json checksum: 8e62821551e64c0fbd23ce2951b44e41561196f0d38b6a2da7de1f6921b48865 + - filename: .github/workflows/ci.yml + checksum: 14991153c5531029f3ac14dbce6fab70aa4b654d445a3514083d446bfadc8813