Skip to content

fix(hooks): install command and correct gate-deny exit codes #6

fix(hooks): install command and correct gate-deny exit codes

fix(hooks): install command and correct gate-deny exit codes #6

Workflow file for this run

name: release
# Publishes @chtnnh/know-code via npm Trusted Publishing (OIDC).
# On npmjs.com → @chtnnh/know-code → Trusted Publisher:
# Repository: chtnnh/know-code
# Workflow filename: release.yml (filename only, not a path)
# Environment: npm-release (must match job.environment)
# No NPM_TOKEN / NODE_AUTH_TOKEN — those block OIDC.
on:
push:
tags:
- "v*"
permissions:
contents: write
id-token: write # required for npm OIDC
jobs:
publish:
runs-on: ubuntu-latest
environment: npm-release
steps:
- uses: actions/checkout@v4
# Node 24 → npm ≥ 11.5.1 (required for trusted publishing).
# Do NOT set registry-url: setup-node would inject a dummy NODE_AUTH_TOKEN
# that prevents the OIDC exchange (ENEEDAUTH).
- uses: actions/setup-node@v4
with:
node-version: "24"
package-manager-cache: false
- run: npm --version
- run: npm install
- run: npm run build
- run: npm test
- name: Publish CLI to npm (OIDC)
working-directory: packages/cli
run: |
unset NODE_AUTH_TOKEN
npm publish --access public
- name: Create GitHub Release
env:
GH_TOKEN: ${{ github.token }}
run: |
TAG="${GITHUB_REF_NAME}"
NOTES="Release ${TAG}. See CHANGELOG.md."
if [[ -f CHANGELOG.md ]]; then
NOTES="$(sed -n "/^## ${TAG#v}/,/^## /p" CHANGELOG.md | sed '$d' || true)"
[[ -n "$NOTES" ]] || NOTES="Release ${TAG}. See CHANGELOG.md."
fi
gh release create "$TAG" --title "$TAG" --notes "$NOTES"