Skip to content

Switch from npm to pnpm #372

Switch from npm to pnpm

Switch from npm to pnpm #372

Workflow file for this run

name: Release
on:
workflow_dispatch:
pull_request:
push:
branches:
- main
release:
types: [published]
permissions: {}
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
submodules: true
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
package-manager-cache: false
# Install only pnpm, not the repo's full toolchain — Node comes from
# actions/setup-node. See mise.toml for why, and for why PATH order is
# not what makes it safe.
- name: Setup mise
uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
install: false
# Caching is disabled in this workflow only. zizmor's cache-poisoning
# audit flags a restorable cache in a job that publishes artifacts
# built at runtime, which is also why the setup-node steps here set
# package-manager-cache: false. test.yml and lint.yml leave the
# default, which zizmor does not flag -- though with install: false
# mise-action never writes a cache there either.
cache: false
- name: Install pnpm
env:
MISE_AUTO_INSTALL: 'false'
run: |
mise install --locked github:pnpm/pnpm
pnpm_bin=$(mise which pnpm)
[ -x "$pnpm_bin" ] || { echo "mise which pnpm produced no usable path" >&2; exit 1; }
dirname "$pnpm_bin" >> "$GITHUB_PATH"
- run: pnpm install --frozen-lockfile
- run: pnpm test
- run: pnpm run lint
- run: pnpm run build
- run: pnpm run build:docs
publish:
needs: build
if: github.event_name == 'release' && github.event.action == 'published'
runs-on: ubuntu-latest
environment: npm
permissions:
contents: write
id-token: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
submodules: true
persist-credentials: false
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
# Node 24 bundles npm 11.17.0, above the 11.5.1 minimum for npm
# Trusted Publishing. On Node 22 (npm 10.9.8) this job had to run
# `npm install -g npm@latest`, which tripped zizmor's adhoc-packages
# rule for installing outside a lockfile.
node-version: 24
package-manager-cache: false
# Writes the .npmrc that OIDC publishing needs.
registry-url: 'https://registry.npmjs.org'
# The pin above cannot fail on its own; this can. Assert rather than
# trust the bundled version, since a Node downgrade would otherwise only
# surface during a real release.
- name: Verify npm supports trusted publishing
run: |
npm_version=$(npm --version)
echo "npm $npm_version (need >= 11.5.1 for OIDC trusted publishing)"
printf '11.5.1\n%s\n' "$npm_version" | sort -V -C
# Install only pnpm, not the repo's full toolchain — Node comes from
# actions/setup-node. See mise.toml for why, and for why PATH order is
# not what makes it safe.
- name: Setup mise
uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4
with:
install: false
# Caching is disabled in this workflow only. zizmor's cache-poisoning
# audit flags a restorable cache in a job that publishes artifacts
# built at runtime, which is also why the setup-node steps here set
# package-manager-cache: false. test.yml and lint.yml leave the
# default, which zizmor does not flag -- though with install: false
# mise-action never writes a cache there either.
cache: false
- name: Install pnpm
env:
MISE_AUTO_INSTALL: 'false'
run: |
mise install --locked github:pnpm/pnpm
pnpm_bin=$(mise which pnpm)
[ -x "$pnpm_bin" ] || { echo "mise which pnpm produced no usable path" >&2; exit 1; }
dirname "$pnpm_bin" >> "$GITHUB_PATH"
- run: pnpm install --frozen-lockfile
- run: pnpm run build
# Publishing deliberately stays on the npm CLI. This is not a pnpm
# capability gap: pnpm 11 implements OIDC trusted publishing and
# provenance natively. It is that CI never exercises the release path,
# so switching the publish command belongs in its own change rather
# than a package-manager migration. npm publish is safe in a
# pnpm-installed tree: it packs only `files: ["dist"]` and reads no
# lockfile.
- run: npm publish --provenance
- run: pnpm run build:docs
- name: Deploy docs to gh-pages
uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0
with:
github_token: ${{ secrets.GITHUB_TOKEN }}
publish_dir: ./docs