Switch from npm to pnpm #370
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| release: | |
| types: [published] | |
| permissions: {} | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| submodules: true | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 22 | |
| package-manager-cache: false | |
| # Install only pnpm, not the repo's full toolchain — Node comes from | |
| # actions/setup-node, which pins the version this job needs. | |
| # Appending only pnpm's directory to PATH keeps mise's own Node | |
| # (mise.toml pins "latest") from ever shadowing setup-node's. | |
| - name: Setup mise | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| with: | |
| install: false | |
| # Caching is disabled in this workflow only. zizmor's cache-poisoning | |
| # audit flags a restorable cache in a job that publishes artifacts | |
| # built at runtime, which is also why the setup-node steps here set | |
| # package-manager-cache: false. Caching stays on in test.yml and | |
| # lint.yml, where it is a real speed win and is not flagged. | |
| cache: false | |
| - name: Install pnpm | |
| env: | |
| MISE_AUTO_INSTALL: 'false' | |
| run: | | |
| mise install github:pnpm/pnpm | |
| dirname "$(mise which pnpm)" >> "$GITHUB_PATH" | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm test | |
| - run: pnpm run lint | |
| - run: pnpm run build | |
| - run: pnpm run build:docs | |
| publish: | |
| needs: build | |
| if: github.event_name == 'release' && github.event.action == 'published' | |
| runs-on: ubuntu-latest | |
| environment: npm | |
| permissions: | |
| contents: write | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| submodules: true | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| # Node 24 bundles npm 11.17.0, above the 11.5.1 minimum for npm | |
| # Trusted Publishing. On Node 22 (npm 10.9.8) this job had to run | |
| # `npm install -g npm@latest`, which tripped zizmor's adhoc-packages | |
| # rule for installing outside a lockfile. | |
| node-version: 24 | |
| package-manager-cache: false | |
| # Writes the .npmrc that OIDC publishing needs. | |
| registry-url: 'https://registry.npmjs.org' | |
| # The pin above cannot fail on its own; this can. Assert rather than | |
| # trust the bundled version, since a Node downgrade would otherwise only | |
| # surface during a real release. | |
| - name: Verify npm supports trusted publishing | |
| run: | | |
| npm_version=$(npm --version) | |
| echo "npm $npm_version (need >= 11.5.1 for OIDC trusted publishing)" | |
| printf '11.5.1\n%s\n' "$npm_version" | sort -V -C | |
| # Install only pnpm, not the repo's full toolchain — Node comes from | |
| # actions/setup-node, which pins the version this job needs. | |
| # Appending only pnpm's directory to PATH keeps mise's own Node | |
| # (mise.toml pins "latest") from ever shadowing setup-node's. | |
| - name: Setup mise | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| with: | |
| install: false | |
| # Caching is disabled in this workflow only. zizmor's cache-poisoning | |
| # audit flags a restorable cache in a job that publishes artifacts | |
| # built at runtime, which is also why the setup-node steps here set | |
| # package-manager-cache: false. Caching stays on in test.yml and | |
| # lint.yml, where it is a real speed win and is not flagged. | |
| cache: false | |
| - name: Install pnpm | |
| env: | |
| MISE_AUTO_INSTALL: 'false' | |
| run: | | |
| mise install github:pnpm/pnpm | |
| dirname "$(mise which pnpm)" >> "$GITHUB_PATH" | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm run build | |
| # Publishing stays on the npm CLI, so do not "fix" this to `pnpm | |
| # publish`. pnpm has no native OIDC support — it shells out to npm for | |
| # trusted publishing and provenance, and that path has known failures | |
| # (pnpm/pnpm#9812). npm publish is safe in a pnpm-installed tree: it | |
| # packs only `files: ["dist"]` and reads no lockfile. | |
| - run: npm publish --provenance | |
| - run: pnpm run build:docs | |
| - name: Deploy docs to gh-pages | |
| uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0 | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| publish_dir: ./docs |