Switch from npm to pnpm #372
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| push: | |
| branches: | |
| - main | |
| release: | |
| types: [published] | |
| permissions: {} | |
| jobs: | |
| build: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| submodules: true | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: 22 | |
| package-manager-cache: false | |
| # Install only pnpm, not the repo's full toolchain — Node comes from | |
| # actions/setup-node. See mise.toml for why, and for why PATH order is | |
| # not what makes it safe. | |
| - name: Setup mise | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| with: | |
| install: false | |
| # Caching is disabled in this workflow only. zizmor's cache-poisoning | |
| # audit flags a restorable cache in a job that publishes artifacts | |
| # built at runtime, which is also why the setup-node steps here set | |
| # package-manager-cache: false. test.yml and lint.yml leave the | |
| # default, which zizmor does not flag -- though with install: false | |
| # mise-action never writes a cache there either. | |
| cache: false | |
| - name: Install pnpm | |
| env: | |
| MISE_AUTO_INSTALL: 'false' | |
| run: | | |
| mise install --locked github:pnpm/pnpm | |
| pnpm_bin=$(mise which pnpm) | |
| [ -x "$pnpm_bin" ] || { echo "mise which pnpm produced no usable path" >&2; exit 1; } | |
| dirname "$pnpm_bin" >> "$GITHUB_PATH" | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm test | |
| - run: pnpm run lint | |
| - run: pnpm run build | |
| - run: pnpm run build:docs | |
| publish: | |
| needs: build | |
| if: github.event_name == 'release' && github.event.action == 'published' | |
| runs-on: ubuntu-latest | |
| environment: npm | |
| permissions: | |
| contents: write | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| submodules: true | |
| persist-credentials: false | |
| - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| # Node 24 bundles npm 11.17.0, above the 11.5.1 minimum for npm | |
| # Trusted Publishing. On Node 22 (npm 10.9.8) this job had to run | |
| # `npm install -g npm@latest`, which tripped zizmor's adhoc-packages | |
| # rule for installing outside a lockfile. | |
| node-version: 24 | |
| package-manager-cache: false | |
| # Writes the .npmrc that OIDC publishing needs. | |
| registry-url: 'https://registry.npmjs.org' | |
| # The pin above cannot fail on its own; this can. Assert rather than | |
| # trust the bundled version, since a Node downgrade would otherwise only | |
| # surface during a real release. | |
| - name: Verify npm supports trusted publishing | |
| run: | | |
| npm_version=$(npm --version) | |
| echo "npm $npm_version (need >= 11.5.1 for OIDC trusted publishing)" | |
| printf '11.5.1\n%s\n' "$npm_version" | sort -V -C | |
| # Install only pnpm, not the repo's full toolchain — Node comes from | |
| # actions/setup-node. See mise.toml for why, and for why PATH order is | |
| # not what makes it safe. | |
| - name: Setup mise | |
| uses: jdx/mise-action@7e36c90d9ab29c415a2384db3006f3ec8a8cc654 # v4.2.4 | |
| with: | |
| install: false | |
| # Caching is disabled in this workflow only. zizmor's cache-poisoning | |
| # audit flags a restorable cache in a job that publishes artifacts | |
| # built at runtime, which is also why the setup-node steps here set | |
| # package-manager-cache: false. test.yml and lint.yml leave the | |
| # default, which zizmor does not flag -- though with install: false | |
| # mise-action never writes a cache there either. | |
| cache: false | |
| - name: Install pnpm | |
| env: | |
| MISE_AUTO_INSTALL: 'false' | |
| run: | | |
| mise install --locked github:pnpm/pnpm | |
| pnpm_bin=$(mise which pnpm) | |
| [ -x "$pnpm_bin" ] || { echo "mise which pnpm produced no usable path" >&2; exit 1; } | |
| dirname "$pnpm_bin" >> "$GITHUB_PATH" | |
| - run: pnpm install --frozen-lockfile | |
| - run: pnpm run build | |
| # Publishing deliberately stays on the npm CLI. This is not a pnpm | |
| # capability gap: pnpm 11 implements OIDC trusted publishing and | |
| # provenance natively. It is that CI never exercises the release path, | |
| # so switching the publish command belongs in its own change rather | |
| # than a package-manager migration. npm publish is safe in a | |
| # pnpm-installed tree: it packs only `files: ["dist"]` and reads no | |
| # lockfile. | |
| - run: npm publish --provenance | |
| - run: pnpm run build:docs | |
| - name: Deploy docs to gh-pages | |
| uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0 | |
| with: | |
| github_token: ${{ secrets.GITHUB_TOKEN }} | |
| publish_dir: ./docs |