EVOKORE// WORKFLOWS / release.yml
EVOKORE-MCPworkflow · 75 lines
.github/workflows/release.yml
CI / automation
View on GitHub →# REFERENCE-ONLY: GitHub Actions secrets referenced below are illustrative.
# Do not inject real credentials. See your CI/CD provider for proper secret management.
name: Release
on:
push:
tags: [ 'v*.*.*' ]
workflow_dispatch:
inputs:
chain_complete:
description: Confirm dependency chain completion before release
required: true
type: boolean
default: false
jobs:
publish:
runs-on: ubuntu-latest
# Permissions must be at job level; step-level permissions are not supported in regular GitHub Actions workflow jobs
permissions:
contents: write
env:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Require completed dependency chain for manual release
if: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.chain_complete != 'true' }}
run: |
echo "Manual release blocked: set chain_complete=true only after dependency chain completion."
exit 1
- name: Verify release commit is on origin/main
run: |
git fetch --no-tags origin main:refs/remotes/origin/main
git merge-base --is-ancestor "$GITHUB_SHA" origin/main
- name: Use Node.js
uses: actions/setup-node@v4
with:
node-version: "20"
registry-url: 'https://registry.npmjs.org'
cache: npm
- name: Install dependencies
run: npm ci
- name: Run test suite
run: npm test
- name: Build package
run: npm run build
- name: Publish to npm
if: ${{ env.NPM_TOKEN != '' }}
env:
NODE_AUTH_TOKEN: ${{ env.NPM_TOKEN }}
run: npm publish
- name: Publish skipped (NPM_TOKEN missing)
if: ${{ env.NPM_TOKEN == '' }}
run: echo "NPM_TOKEN is not configured; publish step skipped."
- name: Create GitHub Release
if: startsWith(github.ref, 'refs/tags/')
uses: softprops/action-gh-release@v2
with:
generate_release_notes: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}