Skip to content

Release

Release #20

Workflow file for this run

name: Release
# Manually triggered ("Run workflow"). On trigger it:
# 1. reads the version from package.json,
# 2. promotes `## [Unreleased]` content into `## [<version>]` in
# CHANGELOG.md (and commits + pushes that change back to main), so
# the published release notes are never sparse just because the
# maintainer didn't pre-stage the [<version>] block by hand,
# 3. builds a self-contained bundle for every platform (one runner — there's no
# native compilation, so cross-packaging is fine),
# 4. creates the GitHub Release (tag v<version>) with all archives, using the
# release notes from CHANGELOG.md,
# 5. publishes the npm thin-installer (shim + per-platform packages).
#
# Before triggering: bump package.json. CHANGELOG.md entries can live under
# `## [Unreleased]` — step 2 takes care of moving them. Set the NPM_TOKEN secret.
on:
workflow_dispatch: {}
permissions:
contents: write # create the GitHub Release + tag, push the CHANGELOG promote
jobs:
release:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
# Default checkout is detached at a SHA; we need an actual branch
# so the CHANGELOG-promote commit knows where to push.
ref: ${{ github.ref }}
# NOTE: the upstream workflow uses a fine-grained PAT
# (`secrets.RELEASE_PAT`) to push the auto-promote commit, on the
# assumption that the repo has a "Require PR approval for main
# branch" ruleset blocking the default GITHUB_TOKEN. This fork has
# no branch protection at all (`gh api ... /protection` returns 404),
# so the PAT is unnecessary — the default GITHUB_TOKEN works fine.
# If you ever add a ruleset that gates `main`, restore the
# `token: ${{ secrets.RELEASE_PAT }}` line and create a PAT with
# `contents:write` scoped to this repo.
- uses: pnpm/action-setup@v4
# version is read from package.json's `packageManager` field — don't
# pin it here, or pnpm/action-setup refuses with "Multiple versions
# of pnpm specified".
- uses: actions/setup-node@v6
with:
node-version: 22
registry-url: https://registry.npmjs.org
cache: pnpm
- run: pnpm install --frozen-lockfile
- name: Ensure zip/unzip
run: sudo apt-get update -qq && sudo apt-get install -y -qq zip unzip
- name: Sync pnpm-lock.yaml if version drifted
# Removed: the upstream's sync step assumed pnpm 9's lockfile format
# which carries the package's own version as a top-level
# ` version: '<X.Y.Z>'` line under the `importers:` block. This fork's
# pnpm-lock.yaml is at lockfileVersion: '9.0' but the importers block
# doesn't include the package's own version there, so the grep
# `^ version: '${PKG_V}'$` always fails to match and the step bails
# before the actual pnpm install runs. The next step (`pnpm install
# --frozen-lockfile`) already enforces lockfile integrity on its own
# — if the lockfile is genuinely out of date, that step fails with
# a clear error pointing at the drift, and the maintainer can
# regenerate the lockfile locally with `pnpm install`. No need for
# the broken sync step.
run: echo "sync step skipped (pnpm 9 lockfile format doesn't carry package version)"
- name: Resolve version
id: ver
run: echo "version=$(node -p "require('./package.json').version")" >> "$GITHUB_OUTPUT"
- name: Promote [Unreleased] → [<version>] in CHANGELOG.md
# Idempotent: a no-op if [Unreleased] is empty OR if the previous
# run already moved everything. Auto-commit + push the change back
# so the version block on main is the source of truth going
# forward (and so subsequent extract-release-notes.mjs calls
# surface the full content even if this run is re-triggered).
run: |
set -euo pipefail
V="${{ steps.ver.outputs.version }}"
before=$(git rev-parse HEAD)
node scripts/prepare-release.mjs "$V"
if git diff --quiet -- CHANGELOG.md; then
echo "CHANGELOG.md unchanged — nothing to commit."
else
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add CHANGELOG.md
git commit -m "docs(changelog): promote [Unreleased] into [${V}]" -m "[skip ci] Auto-generated by Release workflow."
# Push to the branch the workflow was triggered on (main).
git push origin "HEAD:${GITHUB_REF#refs/heads/}"
fi
- name: Build all platform bundles
run: |
for t in darwin-arm64 darwin-x64 linux-x64 linux-arm64 win32-x64 win32-arm64; do
bash scripts/build-bundle.sh "$t"
done
ls -lh release
- name: Generate SHA256SUMS
# Published as a release asset; the npm launcher verifies downloaded
# bundles against it (basenames only, so its path.basename match works).
run: |
( cd release && sha256sum codegraph-vba-* > SHA256SUMS )
cat release/SHA256SUMS
- name: Release notes from CHANGELOG.md
# The [<version>] block was guaranteed-populated by the
# "Promote" step above, so the [Unreleased] fallback should
# never be needed in practice. Kept for defense-in-depth.
run: |
V="${{ steps.ver.outputs.version }}"
node scripts/extract-release-notes.mjs "$V" > notes.md 2>/dev/null \
|| node scripts/extract-release-notes.mjs Unreleased > notes.md 2>/dev/null || true
if [ ! -s notes.md ]; then
echo "::error::No release notes in CHANGELOG.md for [$V] or [Unreleased]."
exit 1
fi
echo "----- release notes -----"; cat notes.md
- name: Create GitHub Release
env:
GH_TOKEN: ${{ github.token }}
run: |
TAG="v${{ steps.ver.outputs.version }}"
# Title includes the package name (codegraph-vba) so users browsing the
# Releases page can tell at a glance that this is the VBA/Access fork
# rather than the upstream @colbymchenry/codegraph. The tag itself stays
# the plain semver tag (v<version>) for tooling compatibility.
TITLE="codegraph-vba $TAG"
# Idempotent: create the release once, otherwise (re-run) refresh assets.
if gh release view "$TAG" >/dev/null 2>&1; then
gh release upload "$TAG" release/codegraph-vba-* release/SHA256SUMS --clobber
else
gh release create "$TAG" release/codegraph-vba-* release/SHA256SUMS --title "$TITLE" --notes-file notes.md
fi
- name: Publish to npm
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: |
V="${{ steps.ver.outputs.version }}"
bash scripts/pack-npm.sh "$V"
# Platform packages first, then the main shim (which depends on them).
# Skip any already on the registry so a re-run only fills in gaps.
# `find` is used instead of a bash glob because paths containing `@`
# (scoped npm packages) don't always expand correctly inside the
# GitHub Actions bash subshell — node receives the literal pattern
# with `*` and `Cannot find module` errors out. `find` is portable.
while IFS= read -r dir; do
[ -d "$dir" ] || continue
name=$(node -p "require('./$dir/package.json').name")
if npm view "$name@$V" version >/dev/null 2>&1; then
echo "skip $name@$V (already published)"
else
echo "publishing $name@$V"
( cd "$dir" && npm publish --access public )
fi
done < <(find release/npm -name 'package.json' -not -path '*/node_modules/*' -not -path '*/lib/*' -not -path '*/bin/*' -exec dirname {} \; | sort -u)
- name: Verify every package is actually on the registry
run: |
V="${{ steps.ver.outputs.version }}"
# npm publish can print success without persisting; confirm against the
# registry (with retries for propagation) so green means really shipped.
while IFS= read -r dir; do
[ -d "$dir" ] || continue
name=$(node -p "require('./$dir/package.json').name")
ok=
for i in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20; do
if npm view "$name@$V" version >/dev/null 2>&1; then ok=1; break; fi
echo "waiting for $name@$V to appear ($i)…"; sleep 10
done
[ -n "$ok" ] || { echo "::error::$name@$V never appeared on the registry"; exit 1; }
echo "verified $name@$V"
done < <(find release/npm -name 'package.json' -not -path '*/node_modules/*' -not -path '*/lib/*' -not -path '*/bin/*' -exec dirname {} \; | sort -u)
- name: Sync packages to npmmirror
# npmmirror/cnpm mirror lazily and frequently never pull the per-platform
# optionalDependencies on their own, so `npm i` there fails with
# "no prebuilt bundle" (issue #303). Nudge a sync now so mirror users get
# the bundle without waiting. Best-effort — the launcher also self-heals
# from GitHub Releases — so a mirror hiccup never fails the release.
continue-on-error: true
run: |
while IFS= read -r dir; do
[ -d "$dir" ] || continue
name=$(node -p "require('./$dir/package.json').name")
enc=$(node -p "encodeURIComponent(require('./$dir/package.json').name)")
echo "sync $name"
curl -s -X PUT "https://registry.npmmirror.com/-/package/$enc/syncs" || true
echo
done < <(find release/npm -name 'package.json' -not -path '*/node_modules/*' -not -path '*/lib/*' -not -path '*/bin/*' -exec dirname {} \; | sort -u)