ci: Configure OIDC Trusted Publishing for npm releases by removing `N… #184
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| env: | |
| package_name: "pilotui" | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - dev | |
| permissions: | |
| contents: write | |
| issues: write | |
| pull-requests: write | |
| packages: write | |
| id-token: write # Required for Trusted Publishing/OIDC | |
| jobs: | |
| release: | |
| name: Release | |
| runs-on: ubuntu-latest | |
| # environment: production # Optional: keep if you want UI tracking, but ensure it's not branch-restricted | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: "20" | |
| registry-url: "https://registry.npmjs.org/" | |
| - name: Install dependencies | |
| run: yarn install | |
| - name: Build | |
| run: yarn build | |
| - name: Release | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # NPM_TOKEN removed - OIDC Trusted Publishing will be used instead | |
| run: | | |
| if [ "${{ github.ref }}" == "refs/heads/dev" ]; then | |
| yarn semantic-release --branch dev --tag-format "dev-\${version}" | |
| else | |
| yarn semantic-release | |
| fi |