Adjust release triggers to use cache-writable token (#12030)

This commit is contained in:
Michal Kinas
2026-07-03 07:56:50 +02:00
committed by GitHub
parent 7f57b3936b
commit 4cd8648a05
3 changed files with 15 additions and 22 deletions
+7 -2
View File
@@ -12,9 +12,14 @@ runs:
- name: base vars - name: base vars
shell: bash shell: bash
run: | run: |
if [ -n "${GITHUB_BASE_REF:-}" ]; then
BASE_HASH=$(git merge-base "origin/${GITHUB_BASE_REF}" HEAD 2>/dev/null || git rev-parse HEAD)
else
BASE_HASH=$(git rev-parse HEAD)
fi
{ {
echo "GIT_HASH=$(git rev-parse HEAD)"; echo "GIT_HASH=$(git rev-parse HEAD)";
echo "BASE_HASH=$(git merge-base origin/${GITHUB_BASE_REF} HEAD)"; echo "BASE_HASH=${BASE_HASH}";
echo "HEAD_HASH=HEAD"; echo "HEAD_HASH=HEAD";
echo "HEAD_COMMIT_HASH=${GH_COMMIT}"; echo "HEAD_COMMIT_HASH=${GH_COMMIT}";
echo "NX_CALCULATION_FLAGS=--all"; echo "NX_CALCULATION_FLAGS=--all";
@@ -55,7 +60,7 @@ runs:
} >> $GITHUB_ENV } >> $GITHUB_ENV
- name: RELEASE on master/develop patch branch - name: RELEASE on master/develop patch branch
if: ${{ env.BREAK_ACTION == false && github.event.pull_request.merged }} if: ${{ env.BREAK_ACTION == false && (github.event.pull_request.merged || github.event_name == 'push') }}
shell: bash shell: bash
env: env:
REF_NAME: ${{ github.ref_name }} REF_NAME: ${{ github.ref_name }}
+2 -2
View File
@@ -23,8 +23,8 @@ runs:
env: env:
DRY_RUN_FLAG: ${{ inputs.dry-run-flag }} DRY_RUN_FLAG: ${{ inputs.dry-run-flag }}
run: | run: |
if [[ '$DRY_RUN_FLAG' == 'true' ]]; then if [[ "$DRY_RUN_FLAG" == 'true' ]]; then
echo "dryrun=--dryrun" >> $GITHUB_OUTPUT; echo "dryrun=--dry-run" >> $GITHUB_OUTPUT;
echo "enabling dryrun" echo "enabling dryrun"
else else
echo "dryrun=" >> $GITHUB_OUTPUT; echo "dryrun=" >> $GITHUB_OUTPUT;
+6 -18
View File
@@ -1,13 +1,6 @@
name: "release" name: "release"
on: on:
workflow_call:
inputs:
dry-run-flag:
description: 'enable dry-run on artifact push'
required: false
type: boolean
default: true
workflow_dispatch: workflow_dispatch:
inputs: inputs:
dry-run-flag: dry-run-flag:
@@ -15,13 +8,10 @@ on:
required: false required: false
type: boolean type: boolean
default: true default: true
pull_request: push:
types: [closed]
branches: branches:
- develop - develop
- develop-patch* - develop-patch*
push:
branches:
- master - master
- master-patch-* - master-patch-*
@@ -34,8 +24,6 @@ concurrency:
cancel-in-progress: false cancel-in-progress: false
env: env:
BASE_REF: ${{ github.base_ref }}
HEAD_REF: ${{ github.head_ref }}
GH_COMMIT: ${{ github.sha }} GH_COMMIT: ${{ github.sha }}
GH_BUILD_NUMBER: ${{ github.run_id }} GH_BUILD_NUMBER: ${{ github.run_id }}
LOG_LEVEL: "ERROR" LOG_LEVEL: "ERROR"
@@ -44,7 +32,7 @@ env:
jobs: jobs:
setup: setup:
timeout-minutes: 20 timeout-minutes: 20
if: github.event.pull_request.merged == true || github.ref_name == 'master' || github.ref_name == 'master-patch-*' || github.event_name == 'workflow_dispatch' if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
name: "Setup" name: "Setup"
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions: permissions:
@@ -68,7 +56,7 @@ jobs:
outputs: outputs:
release_version: ${{ steps.set-version.outputs.release_version }} release_version: ${{ steps.set-version.outputs.release_version }}
timeout-minutes: 30 timeout-minutes: 30
if: github.event.pull_request.merged == true || github.ref_name == 'master' || github.ref_name == 'master-patch-*' || github.event_name == 'workflow_dispatch' if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest runs-on: ubuntu-latest
permissions: permissions:
id-token: write # Required for OIDC id-token: write # Required for OIDC
@@ -108,7 +96,7 @@ jobs:
node-version-file: '.nvmrc' node-version-file: '.nvmrc'
registry-url: 'https://npm.pkg.github.com' registry-url: 'https://npm.pkg.github.com'
scope: '@alfresco' scope: '@alfresco'
- run: pnpm run publish --tag ${{ steps.setup.outputs.npm-tag }} --provenance=false - run: pnpm run publish --tag ${{ steps.setup.outputs.npm-tag }} --provenance=false ${{ steps.set-dryrun.outputs.dryrun }}
env: env:
NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0 - uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
@@ -117,7 +105,7 @@ jobs:
node-version-file: '.nvmrc' node-version-file: '.nvmrc'
registry-url: 'https://${{ vars.NPM_REGISTRY_ADDRESS }}' registry-url: 'https://${{ vars.NPM_REGISTRY_ADDRESS }}'
scope: '@alfresco' scope: '@alfresco'
- run: pnpm run publish --tag ${{ steps.setup.outputs.npm-tag }} - run: pnpm run publish --tag ${{ steps.setup.outputs.npm-tag }} ${{ steps.set-dryrun.outputs.dryrun }}
create-git-tag: create-git-tag:
runs-on: ubuntu-latest runs-on: ubuntu-latest
@@ -138,7 +126,7 @@ jobs:
npm-check-bundle: npm-check-bundle:
needs: [release-npm] needs: [release-npm]
timeout-minutes: 15 timeout-minutes: 15
if: github.event.pull_request.merged == true || github.ref_name == 'master' || github.ref_name == 'master-patch-*' || github.event_name == 'workflow_dispatch' if: github.event_name == 'push' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest runs-on: ubuntu-latest
steps: steps:
- name: Checkout repository - name: Checkout repository