diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml new file mode 100644 index 0000000..29b3635 --- /dev/null +++ b/.github/workflows/build.yml @@ -0,0 +1,85 @@ +name: Release +env: + DEBUG: napi:* + APP_NAME: aic-sdk +permissions: + contents: read +'on': + push: + tags: + - '[0-9]+.[0-9]+.[0-9]+*' +concurrency: + group: release-${{ github.ref }} + cancel-in-progress: false +jobs: + checks: + uses: ./.github/workflows/check.yml + permissions: + contents: read + secrets: + AIC_SDK_LICENSE: ${{ secrets.AIC_SDK_LICENSE }} + publish: + name: Publish + runs-on: ubuntu-latest + needs: checks + permissions: + contents: write + id-token: write + steps: + - uses: actions/checkout@v7 + - name: setup pnpm + uses: pnpm/action-setup@v6 + - name: Setup node + uses: actions/setup-node@v7 + with: + node-version: 22 + cache: pnpm + - name: Install dependencies + run: pnpm install + - name: Download all artifacts + uses: actions/download-artifact@v8 + with: + path: artifacts + - name: create npm dirs + run: pnpm napi create-npm-dirs + - name: Move artifacts + run: pnpm artifacts + - name: List packages + run: ls -R ./npm + shell: bash + - name: Install an npm with trusted publishing support + run: npm install -g npm@latest + - name: Publish + run: | + VERSION="${GITHUB_REF_NAME#v}" + PACKAGE_VERSION="$(node -p "require('./package.json').version")" + if [ "$VERSION" != "$PACKAGE_VERSION" ]; then + echo "::error::Tag $GITHUB_REF_NAME does not match package.json version $PACKAGE_VERSION" + exit 1 + fi + PACKAGE_NAME="$(node -p "require('./package.json').name")" + if npm view "$PACKAGE_NAME@$VERSION" version >/dev/null 2>&1; then + echo "$PACKAGE_NAME@$VERSION is already published, skipping" + exit 0 + fi + case "$VERSION" in + *-*) npm publish --tag next --access public ;; + *) npm publish --access public ;; + esac + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + - name: Create the GitHub release + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + VERSION="${GITHUB_REF_NAME#v}" + node scripts/changelog-section.mjs "$VERSION" > release-notes.md + case "$VERSION" in + *-*) PRERELEASE=--prerelease ;; + *) PRERELEASE= ;; + esac + if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then + gh release edit "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE + else + gh release create "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE + fi diff --git a/.github/workflows/CI.yml b/.github/workflows/check.yml similarity index 83% rename from .github/workflows/CI.yml rename to .github/workflows/check.yml index d307a37..353b796 100644 --- a/.github/workflows/CI.yml +++ b/.github/workflows/check.yml @@ -1,21 +1,22 @@ -name: CI +name: Checks env: DEBUG: napi:* APP_NAME: aic-sdk MACOSX_DEPLOYMENT_TARGET: '10.13' CARGO_INCREMENTAL: '1' permissions: - contents: write - id-token: write + contents: read 'on': push: branches: - main - tags: - - '[0-9]+.[0-9]+.[0-9]+*' pull_request: null + workflow_call: + secrets: + AIC_SDK_LICENSE: + required: false concurrency: - group: ${{ github.workflow }}-${{ github.ref }} + group: checks-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: lint: @@ -348,70 +349,3 @@ jobs: - name: Check the enhanced file was written if: steps.license.outputs.available == 'true' run: test -s example-input_enhanced.wav - publish: - name: Publish - if: startsWith(github.ref, 'refs/tags/') - runs-on: ubuntu-latest - needs: - - lint - - test-macOS-windows-binding - - test-linux-binding - - run-examples - steps: - - uses: actions/checkout@v7 - - name: setup pnpm - uses: pnpm/action-setup@v6 - - name: Setup node - uses: actions/setup-node@v7 - with: - node-version: 22 - cache: pnpm - - name: Install dependencies - run: pnpm install - - name: Download all artifacts - uses: actions/download-artifact@v8 - with: - path: artifacts - - name: create npm dirs - run: pnpm napi create-npm-dirs - - name: Move artifacts - run: pnpm artifacts - - name: List packages - run: ls -R ./npm - shell: bash - - name: Install an npm with trusted publishing support - run: npm install -g npm@latest - - name: Publish - run: | - VERSION="${GITHUB_REF_NAME#v}" - PACKAGE_VERSION="$(node -p "require('./package.json').version")" - if [ "$VERSION" != "$PACKAGE_VERSION" ]; then - echo "::error::Tag $GITHUB_REF_NAME does not match package.json version $PACKAGE_VERSION" - exit 1 - fi - PACKAGE_NAME="$(node -p "require('./package.json').name")" - if npm view "$PACKAGE_NAME@$VERSION" version >/dev/null 2>&1; then - echo "$PACKAGE_NAME@$VERSION is already published, skipping" - exit 0 - fi - case "$VERSION" in - *-*) npm publish --tag next --access public ;; - *) npm publish --access public ;; - esac - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - - name: Create the GitHub release - env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - VERSION="${GITHUB_REF_NAME#v}" - node scripts/changelog-section.mjs "$VERSION" > release-notes.md - case "$VERSION" in - *-*) PRERELEASE=--prerelease ;; - *) PRERELEASE= ;; - esac - if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then - gh release edit "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE - else - gh release create "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE - fi diff --git a/DEVELOPMENT.md b/DEVELOPMENT.md index eaac992..162ebe3 100644 --- a/DEVELOPMENT.md +++ b/DEVELOPMENT.md @@ -43,5 +43,10 @@ tag. Publishing uses npm trusted publishing over OIDC, so there is no npm token in the repository. Each of the seven published packages (`@ai-coustics/aic-sdk` and its six platform packages) needs a trusted publisher on npmjs.com naming this repository and the -workflow file `CI.yml`. npm rejects a publish whose workflow file does not match, with a -404 on the `PUT` rather than a permission error. +workflow file `build.yml`, with direct `npm publish` allowed. A mismatched trusted +publisher can cause authentication errors such as `ENEEDAUTH`. + +`check.yml` runs builds, lint, tests, and examples with read-only repository permissions. +It runs on main-branch pushes and pull requests, and is called by `build.yml` for release +tags. Only the publish job in `build.yml` receives `contents: write` for GitHub releases +and `id-token: write` for npm trusted publishing.