Repository navigation
fix(hooks): install command and correct gate-deny exit codes #6
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release | |
| # Publishes @chtnnh/know-code via npm Trusted Publishing (OIDC). | |
| # On npmjs.com → @chtnnh/know-code → Trusted Publisher: | |
| # Repository: chtnnh/know-code | |
| # Workflow filename: release.yml (filename only, not a path) | |
| # Environment: npm-release (must match job.environment) | |
| # No NPM_TOKEN / NODE_AUTH_TOKEN — those block OIDC. | |
| on: | |
| push: | |
| tags: | |
| - "v*" | |
| permissions: | |
| contents: write | |
| id-token: write # required for npm OIDC | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-latest | |
| environment: npm-release | |
| steps: | |
| - uses: actions/checkout@v4 | |
| # Node 24 → npm ≥ 11.5.1 (required for trusted publishing). | |
| # Do NOT set registry-url: setup-node would inject a dummy NODE_AUTH_TOKEN | |
| # that prevents the OIDC exchange (ENEEDAUTH). | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "24" | |
| package-manager-cache: false | |
| - run: npm --version | |
| - run: npm install | |
| - run: npm run build | |
| - run: npm test | |
| - name: Publish CLI to npm (OIDC) | |
| working-directory: packages/cli | |
| run: | | |
| unset NODE_AUTH_TOKEN | |
| npm publish --access public | |
| - name: Create GitHub Release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| TAG="${GITHUB_REF_NAME}" | |
| NOTES="Release ${TAG}. See CHANGELOG.md." | |
| if [[ -f CHANGELOG.md ]]; then | |
| NOTES="$(sed -n "/^## ${TAG#v}/,/^## /p" CHANGELOG.md | sed '$d' || true)" | |
| [[ -n "$NOTES" ]] || NOTES="Release ${TAG}. See CHANGELOG.md." | |
| fi | |
| gh release create "$TAG" --title "$TAG" --notes "$NOTES" |