Publish the React Native package through npm trusted publishing #19
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: publish | |
| # The version in package.json is the release trigger: a merge to main that names a version npm | |
| # does not have yet publishes it, and a merge that does not is a no-op. That keeps the released | |
| # bytes tied to a commit on main without anyone hand-tagging, and makes the release reviewable as | |
| # an ordinary pull request. This repository is generated from the SplatKit monorepo, so the bump | |
| # lands here through the mirror workflow there. | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| jobs: | |
| publish: | |
| runs-on: ubuntu-24.04 | |
| permissions: | |
| contents: write | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: "24.21.0" | |
| registry-url: "https://registry.npmjs.org" | |
| cache: npm | |
| # Trusted publishing authenticates with the job's OIDC token instead of a secret, and | |
| # npm accepts it for dist-tag changes from 11.21.0; Node 24.21.0 bundles 11.19.0. | |
| - run: npm install --global npm@11.21.0 | |
| - run: npm ci | |
| - id: state | |
| name: Decide whether this version is new | |
| run: | | |
| version=$(node -p "require('./package.json').version") | |
| name=$(node -p "require('./package.json').name") | |
| echo "version=$version" >> "$GITHUB_OUTPUT" | |
| echo "name=$name" >> "$GITHUB_OUTPUT" | |
| if npm view "$name@$version" version >/dev/null 2>&1; then | |
| echo "new=false" >> "$GITHUB_OUTPUT" | |
| echo "$name@$version is already published; nothing to release." | |
| else | |
| echo "new=true" >> "$GITHUB_OUTPUT" | |
| fi | |
| # Prereleases go to the next dist-tag so a later stable release owns `latest` by default. | |
| - name: Publish to npm | |
| if: steps.state.outputs.new == 'true' | |
| run: | | |
| case "$VERSION" in *-*) tag=next ;; *) tag=latest ;; esac | |
| npm publish --provenance --tag "$tag" | |
| env: | |
| VERSION: ${{ steps.state.outputs.version }} | |
| # Until a stable release exists there is nothing for `latest` to mean, and leaving it on an | |
| # older prerelease makes plain `npm install` hand out a build no README describes. This runs | |
| # on every push so a tag left behind by an earlier release is corrected without a new version. | |
| - name: Point latest at the newest release while all of them are prereleases | |
| run: | | |
| current=$(npm view "$NAME" dist-tags.latest 2>/dev/null || true) | |
| if [ "$current" = "$VERSION" ]; then exit 0; fi | |
| case "$current" in | |
| "" | *-*) | |
| npm dist-tag add "$NAME@$VERSION" latest | |
| echo "latest: ${current:-none} -> $VERSION" | |
| ;; | |
| *) echo "latest is the stable $current; leaving it alone." ;; | |
| esac | |
| env: | |
| NAME: ${{ steps.state.outputs.name }} | |
| VERSION: ${{ steps.state.outputs.version }} | |
| - name: Tag the release commit | |
| if: steps.state.outputs.new == 'true' | |
| run: | | |
| git tag "v$VERSION" | |
| git push origin "v$VERSION" | |
| # Not --prerelease, for the reason release.yml gives for the Android artifact: every | |
| # pre-1.0 release is a prerelease, and marking them all prerelease leaves the releases page | |
| # with no Latest at all. | |
| gh release create "v$VERSION" --title "v$VERSION" --generate-notes | |
| env: | |
| VERSION: ${{ steps.state.outputs.version }} | |
| GH_TOKEN: ${{ github.token }} |