Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 28 additions & 4 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,17 @@ name: Publish
on:
push:
tags: ["v*"]
# Resume a publish that died after the npm step (a transient Sigstore or
# GitHub failure leaves the version on npm with no signed binaries, no
# release and no tap update, and a re-run of the tag's job would fail at
# `npm publish` before reaching them). Every step below is idempotent on
# what already exists, so dispatching the tag finishes what the push started.
workflow_dispatch:
inputs:
tag:
description: "Release tag to publish or resume (vX.Y.Z)"
required: true
type: string

permissions:
contents: write
Expand All @@ -16,8 +27,12 @@ jobs:
publish:
runs-on: ubuntu-latest
timeout-minutes: 20
env:
RELEASE_TAG: ${{ inputs.tag || github.ref_name }}
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.tag || github.ref_name }}

- uses: oven-sh/setup-bun@v2

Expand All @@ -27,14 +42,18 @@ jobs:
registry-url: "https://registry.npmjs.org"

- name: Set version from tag
run: npm version "${GITHUB_REF_NAME#v}" --no-git-tag-version --allow-same-version
run: npm version "${RELEASE_TAG#v}" --no-git-tag-version --allow-same-version

- run: bun install --frozen-lockfile
- run: bun run build

- name: Publish to npm (with provenance)
run: |
VERSION="${GITHUB_REF_NAME#v}"
VERSION="${RELEASE_TAG#v}"
if [ "$(npm view "@agent-score/pay@${VERSION}" version 2>/dev/null)" = "$VERSION" ]; then
echo "@agent-score/pay@${VERSION} is already on npm; skipping publish (resumed run)"
exit 0
fi
if [[ "$VERSION" == *-* ]]; then
DIST_TAG="${VERSION#*-}"
DIST_TAG="${DIST_TAG%%.*}"
Expand All @@ -60,7 +79,12 @@ jobs:

- name: Create GitHub Release
run: |
gh release create "$GITHUB_REF_NAME" --generate-notes \
if gh release view "$RELEASE_TAG" >/dev/null 2>&1; then
echo "release $RELEASE_TAG exists; uploading any missing assets"
gh release upload "$RELEASE_TAG" --clobber dist/bin/agentscore-pay-*
exit 0
fi
gh release create "$RELEASE_TAG" --generate-notes \
dist/bin/agentscore-pay-darwin-arm64 \
dist/bin/agentscore-pay-darwin-arm64.bundle \
dist/bin/agentscore-pay-darwin-x64 \
Expand All @@ -77,7 +101,7 @@ jobs:
- name: Update Homebrew tap
env:
GH_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}
VERSION: ${{ github.ref_name }}
VERSION: ${{ inputs.tag || github.ref_name }}
if: env.GH_TOKEN != ''
run: |
set -euo pipefail
Expand Down