ci: fetch immutable release archive
This commit is contained in:
@@ -15,32 +15,39 @@ jobs:
|
|||||||
env:
|
env:
|
||||||
NODE_AUTH_TOKEN: ${{ secrets.SHRINKSDK_PACKAGE_TOKEN }}
|
NODE_AUTH_TOKEN: ${{ secrets.SHRINKSDK_PACKAGE_TOKEN }}
|
||||||
steps:
|
steps:
|
||||||
- name: Install Git
|
- name: Fetch exact tagged release archive
|
||||||
|
env:
|
||||||
|
GITEA_REF: ${{ gitea.ref }}
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -eu
|
set -eu
|
||||||
if ! command -v git >/dev/null 2>&1; then
|
tag="${GITEA_REF#refs/tags/}"
|
||||||
apt-get update
|
case "$tag" in
|
||||||
DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends git ca-certificates
|
v[0-9]*) ;;
|
||||||
rm -rf /var/lib/apt/lists/*
|
*) echo "Expected a version tag ref, got: $GITEA_REF" >&2; exit 1 ;;
|
||||||
fi
|
esac
|
||||||
|
export SHRINKSDK_ARCHIVE_URL="https://git.crash.work/ShrinkSDK/ShrinkApp.Starter.Basic/archive/${tag}.tar.gz"
|
||||||
|
node --input-type=module <<'NODE'
|
||||||
|
import { writeFile } from 'node:fs/promises';
|
||||||
|
|
||||||
- name: Fetch tagged revision
|
const response = await fetch(process.env.SHRINKSDK_ARCHIVE_URL);
|
||||||
shell: bash
|
if (!response.ok) {
|
||||||
run: |
|
throw new Error(`Release archive download failed: ${response.status} ${response.statusText}`);
|
||||||
set -eu
|
}
|
||||||
ref="${{ gitea.sha }}"
|
|
||||||
test -n "$ref"
|
await writeFile('release.tar.gz', new Uint8Array(await response.arrayBuffer()));
|
||||||
git init .
|
NODE
|
||||||
git remote add origin "https://git.crash.work/ShrinkSDK/ShrinkApp.Starter.Basic.git"
|
mkdir release
|
||||||
git fetch --depth=1 --tags origin "$ref"
|
tar -xzf release.tar.gz --strip-components=1 -C release
|
||||||
git checkout --detach FETCH_HEAD
|
rm -f release.tar.gz
|
||||||
|
printf '%s' "$tag" > release/.shrink-sdk-release-tag
|
||||||
|
|
||||||
- name: Validate immutable release version
|
- name: Validate immutable release version
|
||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -eu
|
set -eu
|
||||||
tag="$(git describe --exact-match --tags HEAD)"
|
cd release
|
||||||
|
tag="$(cat .shrink-sdk-release-tag)"
|
||||||
version="$(node -p "require('./package.json').version")"
|
version="$(node -p "require('./package.json').version")"
|
||||||
test "$tag" = "v$version"
|
test "$tag" = "v$version"
|
||||||
npm pack --dry-run
|
npm pack --dry-run
|
||||||
@@ -50,10 +57,11 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
set -eu
|
set -eu
|
||||||
: "${NODE_AUTH_TOKEN:?SHRINKSDK_PACKAGE_TOKEN is required}"
|
: "${NODE_AUTH_TOKEN:?SHRINKSDK_PACKAGE_TOKEN is required}"
|
||||||
|
cd release
|
||||||
npmrc="$HOME/.npmrc"
|
npmrc="$HOME/.npmrc"
|
||||||
cleanup() { rm -f "$npmrc"; }
|
cleanup() { rm -f "$npmrc"; }
|
||||||
trap cleanup EXIT
|
trap cleanup EXIT
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'registry=https://git.crash.work/api/packages/ShrinkSDK/npm/' \
|
'registry=https://git.crash.work/api/packages/ShrinkSDK/npm/' \
|
||||||
'//git.crash.work/api/packages/ShrinkSDK/npm/:_authToken=${NODE_AUTH_TOKEN}' > "$npmrc"
|
'//git.crash.work/api/packages/ShrinkSDK/npm/:_authToken=${NODE_AUTH_TOKEN}' > "$npmrc"
|
||||||
npm publish --registry=https://git.crash.work/api/packages/ShrinkSDK/npm/
|
npm publish --registry=https://git.crash.work/api/packages/ShrinkSDK/npm/
|
||||||
|
|||||||
Reference in New Issue
Block a user