feat(analysis): add type shape facts to symbols #41
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish | |
| on: | |
| push: | |
| branches: [main] | |
| paths: | |
| - "src/**" | |
| - "pnpm-lock.yaml" | |
| - ".github/workflows/publish.yml" | |
| workflow_dispatch: {} | |
| concurrency: | |
| group: publish-${{ github.event_name }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: write | |
| id-token: write | |
| jobs: | |
| quality: | |
| name: Quality Gates | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| - run: pnpm install --frozen-lockfile | |
| - name: Lint | |
| run: pnpm lint | |
| - name: Typecheck | |
| run: pnpm typecheck | |
| - name: Build | |
| run: pnpm build | |
| - name: Test | |
| run: pnpm test | |
| canary: | |
| name: Publish Canary | |
| needs: quality | |
| if: github.event_name == 'push' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| id-token: write | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: pnpm/action-setup@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| registry-url: https://registry.npmjs.org | |
| - run: pnpm install --frozen-lockfile | |
| - name: Build | |
| run: pnpm build | |
| - name: Publish canary | |
| run: | | |
| sed -i '/_authToken/d' "$NPM_CONFIG_USERCONFIG" | |
| unset NODE_AUTH_TOKEN | |
| BASE_VERSION=$(node -p "require('./package.json').version") | |
| SHORT_SHA=$(echo "$GITHUB_SHA" | cut -c1-7) | |
| CANARY_VERSION="${BASE_VERSION}-canary.${SHORT_SHA}" | |
| npm version "$CANARY_VERSION" --no-git-tag-version --ignore-scripts | |
| TARBALL=$(pnpm pack --pack-destination /tmp | tail -1) | |
| npx --yes npm@latest publish "$TARBALL" --tag canary --provenance --access public | |
| release: | |
| name: Publish Release | |
| needs: quality | |
| if: github.event_name == 'workflow_dispatch' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - uses: pnpm/action-setup@v4 | |
| - uses: actions/setup-node@v4 | |
| with: | |
| node-version: 22 | |
| cache: pnpm | |
| registry-url: https://registry.npmjs.org | |
| - run: pnpm install --frozen-lockfile | |
| - name: Build | |
| run: pnpm build | |
| - name: Read version + guard against retag | |
| id: version | |
| run: | | |
| VERSION=$(node -p "require('./package.json').version") | |
| echo "version=$VERSION" >> "$GITHUB_OUTPUT" | |
| if git rev-parse "v${VERSION}" >/dev/null 2>&1; then | |
| echo "::error::Tag v${VERSION} already exists. Bump package.json on main via a PR before dispatching release." | |
| exit 1 | |
| fi | |
| - name: Generate changelog | |
| id: changelog | |
| run: | | |
| LAST_TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "") | |
| if [ -z "$LAST_TAG" ]; then | |
| RANGE="HEAD" | |
| else | |
| RANGE="${LAST_TAG}..HEAD" | |
| fi | |
| { | |
| echo "body<<CHANGELOG_EOF" | |
| FEATS=$(git log "$RANGE" --pretty=format:"%s" --grep="^feat" 2>/dev/null || true) | |
| if [ -n "$FEATS" ]; then | |
| echo "### Features" | |
| echo "$FEATS" | sed 's/^/- /' | |
| echo "" | |
| fi | |
| FIXES=$(git log "$RANGE" --pretty=format:"%s" --grep="^fix" 2>/dev/null || true) | |
| if [ -n "$FIXES" ]; then | |
| echo "### Bug Fixes" | |
| echo "$FIXES" | sed 's/^/- /' | |
| echo "" | |
| fi | |
| OTHERS=$(git log "$RANGE" --pretty=format:"%s" --invert-grep --grep="^feat" --grep="^fix" 2>/dev/null || true) | |
| if [ -n "$OTHERS" ]; then | |
| echo "### Other Changes" | |
| echo "$OTHERS" | sed 's/^/- /' | |
| echo "" | |
| fi | |
| echo "CHANGELOG_EOF" | |
| } >> "$GITHUB_OUTPUT" | |
| - name: Tag release | |
| run: | | |
| git config user.name "github-actions[bot]" | |
| git config user.email "github-actions[bot]@users.noreply.github.com" | |
| git tag -a "v${{ steps.version.outputs.version }}" -m "v${{ steps.version.outputs.version }}" | |
| git push origin "v${{ steps.version.outputs.version }}" | |
| - name: Publish to npm | |
| run: | | |
| sed -i '/_authToken/d' "$NPM_CONFIG_USERCONFIG" | |
| unset NODE_AUTH_TOKEN | |
| TARBALL=$(pnpm pack --pack-destination /tmp | tail -1) | |
| npx --yes npm@latest publish "$TARBALL" --tag latest --provenance --access public | |
| - name: Create GitHub Release | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| cat <<'NOTES_EOF' > /tmp/release-notes.md | |
| ${{ steps.changelog.outputs.body }} | |
| NOTES_EOF | |
| gh release create "v${{ steps.version.outputs.version }}" \ | |
| --title "v${{ steps.version.outputs.version }}" \ | |
| --notes-file /tmp/release-notes.md |