Repository navigation
Switch from npm to pnpm #369
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| release: | |
| types: [published] | |
| permissions: {} | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| submodules: true | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 22 | |
| package-manager-cache: false | |
| # Install only pnpm, not the repo's full toolchain — Node comes from | |
| # actions/setup-node, which pins the version this job needs. | |
| # Appending only pnpm's directory to PATH keeps mise's own Node | |
| # (mise.toml pins "latest") from ever shadowing setup-node's. | |
| - name: Setup mise | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| with: | |
| install: false | |
| # Caching is disabled in this workflow only. zizmor's cache-poisoning | |
| # audit flags a restorable cache in a job that publishes artifacts | |
| # built at runtime, which is also why the setup-node steps here set | |
| # package-manager-cache: false. Caching stays on in test.yml and | |
| # lint.yml, where it is a real speed win and is not flagged. | |
| cache: false | |
| - name: Install pnpm | |
| env: | |
| MISE_AUTO_INSTALL: 'false' | |
| run: | | |
| mise install github:pnpm/pnpm | |
| dirname "$(mise which pnpm)" >> "$GITHUB_PATH" | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm test | |
| - run: pnpm run lint | |
| - run: pnpm run build | |
| - run: pnpm run build:docs | |
| publish: | |
| needs: build | |
| if: github.event_name == 'release' && github.event.action == 'published' | |
| runs-on: ubuntu-latest | |
| environment: npm | |
| permissions: | |
| contents: write | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| submodules: true | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| # Node 24 bundles npm 11.17.0, above the 11.5.1 minimum for npm | |
| # Trusted Publishing. On Node 22 (npm 10.9.8) this job had to run | |
| # `npm install -g npm@latest`, which tripped zizmor's adhoc-packages | |
| # rule for installing outside a lockfile. | |
| node-version: 24 | |
| package-manager-cache: false | |
| # Writes the .npmrc that OIDC publishing needs. | |
| registry-url: 'https://registry.npmjs.org' | |
| # Install only pnpm, not the repo's full toolchain — Node comes from | |
| # actions/setup-node, which pins the version this job needs. | |
| # Appending only pnpm's directory to PATH keeps mise's own Node | |
| # (mise.toml pins "latest") from ever shadowing setup-node's. | |
| - name: Setup mise | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| with: | |
| install: false | |
| # Caching is disabled in this workflow only. zizmor's cache-poisoning | |
| # audit flags a restorable cache in a job that publishes artifacts | |
| # built at runtime, which is also why the setup-node steps here set | |
| # package-manager-cache: false. Caching stays on in test.yml and | |
| # lint.yml, where it is a real speed win and is not flagged. | |
| cache: false | |
| - name: Install pnpm | |
| env: | |
| MISE_AUTO_INSTALL: 'false' | |
| run: | | |
| mise install github:pnpm/pnpm | |
| dirname "$(mise which pnpm)" >> "$GITHUB_PATH" | |
| # The reason this job pins Node 24 and no longer installs npm globally. | |
| # Assert it rather than trusting the bundled version, since a Node | |
| # downgrade would otherwise only surface during a real release. | |
| - name: Verify npm supports trusted publishing | |
| run: | | |
| npm_version=$(npm --version) | |
| echo "npm $npm_version (need >= 11.5.1 for OIDC trusted publishing)" | |
| printf '11.5.1\n%s\n' "$npm_version" | sort -V -C | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm run build | |
| # Publishing stays on the npm CLI. pnpm has no native OIDC support — it | |
| # shells out to npm for trusted publishing and provenance, and that path | |
| # has known failures (pnpm/pnpm#9812). npm publish is safe in a | |
| # pnpm-installed tree: it packs only `files: ["dist"]` and reads no | |
| # lockfile. | |
| - run: npm publish --provenance | |
| - run: pnpm run build:docs | |
| - name: Deploy docs to gh-pages | |
| uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0 | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| publish_dir: ./docs |