Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add npm publishing provenance #1367

Merged
merged 5 commits into from
Nov 29, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions .changeset/soft-guests-film.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
---
'@keystar/ui': patch
'@keystatic/astro': patch
'@keystatic/create': patch
'@keystatic/core': patch
'@keystatic/next': patch
'@keystatic/remix': patch
'@keystatic/templates-astro': patch
'@keystatic/templates-nextjs': patch
'@keystatic/templates-remix': patch
---

Add npm publishing provenance
5 changes: 5 additions & 0 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,10 @@ name: Publish
on:
workflow_dispatch:

permissions:
contents: write
id-token: write

jobs:
publish:
name: Publish
Expand All @@ -27,5 +31,6 @@ jobs:
run: pnpm changeset publish
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
NPM_CONFIG_PROVENANCE: true

- run: git push origin --follow-tags
11 changes: 6 additions & 5 deletions .github/workflows/publish_snapshot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,10 @@ name: Publish (Snapshot)

on:
workflow_dispatch:
inputs:
tag:
description: 'The npm tag to publish to'
required: true

permissions:
contents: write
id-token: write

jobs:
publish_snapshot:
Expand Down Expand Up @@ -33,9 +33,10 @@ jobs:
- run: pnpm build:packages

- name: npm publish, git tag
run: pnpm changeset publish --tag ${{ inputs.tag }}
run: pnpm changeset publish --tag test
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
NPM_CONFIG_PROVENANCE: true

# reset, then push the dangling commit
- name: git push
Expand Down
5 changes: 5 additions & 0 deletions design-system/pkg/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,11 @@
"license": "MIT AND Apache-2.0",
"main": "",
"module": "",
"repository": {
"type": "git",
"url": "https://github.com/Thinkmill/keystatic/",
"directory": "design-system/pkg"
},
"scripts": {
"build-icons": "tsx build-icons.ts && cd ../.. && pnpm preconstruct fix"
},
Expand Down
5 changes: 5 additions & 0 deletions templates/astro/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@
"name": "@keystatic/templates-astro",
"version": "0.0.54",
"license": "MIT",
"repository": {
"type": "git",
"url": "https://github.com/Thinkmill/keystatic/",
"directory": "templates/astro"
},
"scripts": {
"dev": "astro dev",
"start": "astro dev",
Expand Down
5 changes: 5 additions & 0 deletions templates/nextjs/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@
"name": "@keystatic/templates-nextjs",
"version": "0.0.55",
"license": "MIT",
"repository": {
"type": "git",
"url": "https://github.com/Thinkmill/keystatic/",
"directory": "templates/nextjs"
},
"scripts": {
"build": "next build",
"dev": "next dev",
Expand Down
5 changes: 5 additions & 0 deletions templates/remix/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,11 @@
"type": "module",
"version": "0.0.42",
"license": "MIT",
"repository": {
"type": "git",
"url": "https://github.com/Thinkmill/keystatic/",
"directory": "templates/remix"
},
"scripts": {
"build": "remix vite:build",
"dev": "remix vite:dev",
Expand Down