Repository navigation
110 lines (98 loc) · 3.54 KB
/
Copy pathdeploy.yml
File metadata and controls
110 lines (98 loc) · 3.54 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
name: Deploy
on:
push:
branches:
- main
- changeset-release/main
workflow_dispatch:
# Snapit trigger - runs when /snapit comment is made on a PR
issue_comment:
types:
- created
permissions: {}
concurrency: ${{ github.workflow }}-${{ github.ref }}
jobs:
checks:
name: Checks 📝
if: ${{ github.event_name == 'push' && github.ref_name == 'main' }}
permissions:
contents: read
uses: ./.github/workflows/checks.yml
deploy:
name: Deploy 🚀
if: ${{ github.event_name == 'push' && github.ref_name == 'main' }}
needs: [checks]
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
id-token: write # Required for OIDC authentication
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: ./.github/workflows/actions/prepare
- run: pnpm run type-check
- run: pnpm run build
- run: pnpm run deploy
env:
NPM_TOKEN: '' # Empty string forces OIDC
NPM_CONFIG_PROVENANCE: true
preview:
name: Preview 🔮
if: ${{ github.event_name == 'workflow_dispatch' || (github.event_name == 'push' && github.ref_name == 'changeset-release/main') }}
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
id-token: write # Required for OIDC authentication
pull-requests: read # Required for Changesets changelog links
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: ./.github/workflows/actions/prepare
# Changeset entries are consumed on this branch. We need to reset the
# changeset files so that the snapshot command knows the correct packages,
# and does not accidentally publish the new, non-preview version numbers
# prematurely.
- name: Reset changeset entries
run: |
git fetch origin main
git checkout origin/main -- .changeset
- run: pnpm run type-check
- run: pnpm run build
- name: Deploy preview versions to NPM
run: |
pnpm changeset version --snapshot preview
pnpm changeset publish --tag preview --no-git-tag
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: '' # Empty string forces OIDC
NPM_CONFIG_PROVENANCE: true
# Snapit job - runs when /snapit comment is made on a PR
snapit:
name: Snapit
if: ${{ github.event_name == 'issue_comment' && github.event.issue.pull_request && github.event.comment.body == '/snapit' }}
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write # Required for OIDC authentication
issues: write
pull-requests: write
steps:
# WARNING: DO NOT RUN ANY CUSTOM LOCAL SCRIPT BEFORE RUNNING THE SNAPIT ACTION
# This action can be executed by 3rd party users and it should not be able to run arbitrary code from a PR.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: ./.github/workflows/actions/prepare
- name: Create snapshot
uses: Shopify/snapit@efd7ad2bbc01ba82ac9a8495eb49b3a8eed0d9b9 # v0.1.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TOKEN: '' # Empty string forces OIDC
NPM_CONFIG_PROVENANCE: true
with:
build_script: pnpm build:snapit
comment_command: /snapit