Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
85 changes: 85 additions & 0 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,85 @@
name: Release
env:
DEBUG: napi:*
APP_NAME: aic-sdk
permissions:
contents: read
'on':
push:
tags:
- '[0-9]+.[0-9]+.[0-9]+*'
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
checks:
uses: ./.github/workflows/check.yml
permissions:
contents: read
secrets:
AIC_SDK_LICENSE: ${{ secrets.AIC_SDK_LICENSE }}
publish:
name: Publish
runs-on: ubuntu-latest
needs: checks
permissions:
contents: write
id-token: write
steps:
- uses: actions/checkout@v7
- name: setup pnpm
uses: pnpm/action-setup@v6
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- name: Install dependencies
run: pnpm install
- name: Download all artifacts
uses: actions/download-artifact@v8
with:
path: artifacts
- name: create npm dirs
run: pnpm napi create-npm-dirs
- name: Move artifacts
run: pnpm artifacts
- name: List packages
run: ls -R ./npm
shell: bash
- name: Install an npm with trusted publishing support
run: npm install -g npm@latest
- name: Publish
run: |
VERSION="${GITHUB_REF_NAME#v}"
PACKAGE_VERSION="$(node -p "require('./package.json').version")"
if [ "$VERSION" != "$PACKAGE_VERSION" ]; then
echo "::error::Tag $GITHUB_REF_NAME does not match package.json version $PACKAGE_VERSION"
exit 1
fi
PACKAGE_NAME="$(node -p "require('./package.json').name")"
if npm view "$PACKAGE_NAME@$VERSION" version >/dev/null 2>&1; then
echo "$PACKAGE_NAME@$VERSION is already published, skipping"
exit 0
fi
case "$VERSION" in
*-*) npm publish --tag next --access public ;;
*) npm publish --access public ;;
esac
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Create the GitHub release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
VERSION="${GITHUB_REF_NAME#v}"
node scripts/changelog-section.mjs "$VERSION" > release-notes.md
case "$VERSION" in
*-*) PRERELEASE=--prerelease ;;
*) PRERELEASE= ;;
esac
if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then
gh release edit "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE
else
gh release create "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE
fi
80 changes: 7 additions & 73 deletions .github/workflows/CI.yml → .github/workflows/check.yml
Original file line number Diff line number Diff line change
@@ -1,21 +1,22 @@
name: CI
name: Checks
env:
DEBUG: napi:*
APP_NAME: aic-sdk
MACOSX_DEPLOYMENT_TARGET: '10.13'
CARGO_INCREMENTAL: '1'
permissions:
contents: write
id-token: write
contents: read
'on':
push:
branches:
- main
tags:
- '[0-9]+.[0-9]+.[0-9]+*'
pull_request: null
workflow_call:
secrets:
AIC_SDK_LICENSE:
required: false
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
group: checks-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
lint:
Expand Down Expand Up @@ -348,70 +349,3 @@ jobs:
- name: Check the enhanced file was written
if: steps.license.outputs.available == 'true'
run: test -s example-input_enhanced.wav
publish:
name: Publish
if: startsWith(github.ref, 'refs/tags/')
runs-on: ubuntu-latest
needs:
- lint
- test-macOS-windows-binding
- test-linux-binding
- run-examples
steps:
- uses: actions/checkout@v7
- name: setup pnpm
uses: pnpm/action-setup@v6
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: 22
cache: pnpm
- name: Install dependencies
run: pnpm install
- name: Download all artifacts
uses: actions/download-artifact@v8
with:
path: artifacts
- name: create npm dirs
run: pnpm napi create-npm-dirs
- name: Move artifacts
run: pnpm artifacts
- name: List packages
run: ls -R ./npm
shell: bash
- name: Install an npm with trusted publishing support
run: npm install -g npm@latest
- name: Publish
run: |
VERSION="${GITHUB_REF_NAME#v}"
PACKAGE_VERSION="$(node -p "require('./package.json').version")"
if [ "$VERSION" != "$PACKAGE_VERSION" ]; then
echo "::error::Tag $GITHUB_REF_NAME does not match package.json version $PACKAGE_VERSION"
exit 1
fi
PACKAGE_NAME="$(node -p "require('./package.json').name")"
if npm view "$PACKAGE_NAME@$VERSION" version >/dev/null 2>&1; then
echo "$PACKAGE_NAME@$VERSION is already published, skipping"
exit 0
fi
case "$VERSION" in
*-*) npm publish --tag next --access public ;;
*) npm publish --access public ;;
esac
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Create the GitHub release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
VERSION="${GITHUB_REF_NAME#v}"
node scripts/changelog-section.mjs "$VERSION" > release-notes.md
case "$VERSION" in
*-*) PRERELEASE=--prerelease ;;
*) PRERELEASE= ;;
esac
if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then
gh release edit "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE
else
gh release create "$GITHUB_REF_NAME" --title "$VERSION" --notes-file release-notes.md $PRERELEASE
fi
9 changes: 7 additions & 2 deletions DEVELOPMENT.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,5 +43,10 @@ tag.
Publishing uses npm trusted publishing over OIDC, so there is no npm token in the
repository. Each of the seven published packages (`@ai-coustics/aic-sdk` and its six
platform packages) needs a trusted publisher on npmjs.com naming this repository and the
workflow file `CI.yml`. npm rejects a publish whose workflow file does not match, with a
404 on the `PUT` rather than a permission error.
workflow file `build.yml`, with direct `npm publish` allowed. A mismatched trusted
publisher can cause authentication errors such as `ENEEDAUTH`.

`check.yml` runs builds, lint, tests, and examples with read-only repository permissions.
It runs on main-branch pushes and pull requests, and is called by `build.yml` for release
tags. Only the publish job in `build.yml` receives `contents: write` for GitHub releases
and `id-token: write` for npm trusted publishing.