diff --git a/.github/workflows/publish-sdk.yml b/.github/workflows/publish-sdk.yml index 881c2888a2..3b4805a040 100644 --- a/.github/workflows/publish-sdk.yml +++ b/.github/workflows/publish-sdk.yml @@ -88,28 +88,22 @@ jobs: exit 1 fi - - name: Pack only - if: ${{ inputs.dry_run }} - working-directory: packages/sdk/js - env: - REDROB_VERSION: ${{ steps.resolve.outputs.version }} - REDROB_CHANNEL: latest - run: | - set -euo pipefail - bun pm pack - ls -la ./*.tgz - echo "dry run: packed but published nothing" >> "$GITHUB_STEP_SUMMARY" - + # One step for both modes, so the rehearsal walks the same code as the real thing and stops only at + # the registry call. Packing directly here instead would skip `publish.ts` -- and therefore skip the + # version injection, which is the part most likely to be wrong. - name: Publish - if: ${{ !inputs.dry_run }} working-directory: packages/sdk/js env: REDROB_VERSION: ${{ steps.resolve.outputs.version }} REDROB_CHANNEL: latest + REDROB_PUBLISH_DRY_RUN: ${{ inputs.dry_run }} NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} NPM_TOKEN: ${{ secrets.NPM_TOKEN }} run: | set -euo pipefail # npm reads the token from the registry-scoped line, not from the environment name alone. - echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > ~/.npmrc + if [ -n "${NPM_TOKEN:-}" ]; then + echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > ~/.npmrc + fi bun run ./script/publish.ts + ls -la ./*.tgz diff --git a/packages/sdk/js/script/publish.ts b/packages/sdk/js/script/publish.ts index 926e8b7d42..7fc7c283aa 100755 --- a/packages/sdk/js/script/publish.ts +++ b/packages/sdk/js/script/publish.ts @@ -47,12 +47,25 @@ function transformExports(exports: Record) { if (await published(pkg.name, version)) { console.log(`already published ${pkg.name}@${version}`) } else { - console.log(`publishing ${pkg.name}@${version} on tag ${Script.channel}`) + /* + A dry run walks THIS path, stopping only at the registry call. + + The first version of the workflow rehearsed by invoking `bun pm pack` directly, which skipped this + script entirely -- so it packed the committed `0.0.0` and proved nothing about the version wiring, + which is the part most likely to be wrong. A rehearsal that bypasses the code it is rehearsing is not + one. + */ + const dryRun = process.env["REDROB_PUBLISH_DRY_RUN"] === "true" + console.log(`${dryRun ? "dry run: would publish" : "publishing"} ${pkg.name}@${version} on tag ${Script.channel}`) pkg.exports = transformExports(pkg.exports) await Bun.write("package.json", JSON.stringify(pkg, null, 2)) try { await $`bun pm pack` - await $`npm publish *.tgz --tag ${Script.channel} --access public` + if (dryRun) { + console.log("dry run: packed but published nothing") + } else { + await $`npm publish *.tgz --tag ${Script.channel} --access public` + } } finally { /* The committed 0.0.0 and the untransformed exports go back, so a release leaves no diff behind. */ await Bun.write("package.json", originalText)