5c: report the depth cause from the guards, and make the publish converge
CI / gate (push) Successful in 7m12s
CI / publish (push) Has been skipped

This commit is contained in:
2026-09-03 21:19:01 +02:00
parent d9056973a1
commit 0dfcc0f9ca
19 changed files with 191 additions and 105 deletions
+19 -12
View File
@@ -1,28 +1,35 @@
#!/usr/bin/env bash
set -euo pipefail
cd "$(dirname "$0")"
source ./docker-images.sh
source ./docker-runner.sh
read_field() {
in_image "$node_image" npm pkg get "$1" | tr -d '"\r'
}
if [ "$(read_field private)" = 'true' ]; then
published_version() {
in_image "$node_image" npm view "$1@$2" version 2>/dev/null || true
}
private=$(read_field private)
if [ "$private" = 'true' ]; then
echo 'package.json is private — the maintainer removes that in the bump that first publishes'
exit 0
fi
name=$(read_field name)
version=$(read_field version)
published=$(in_image "$node_image" npm view "$name@latest" version 2>/dev/null || true)
if [ "$version" = "$published" ]; then
echo "npm holds $name $version already — no bump, no deploy"
exit 0
# Both steps observe their own end state, so a partial run converges on the next push to main.
if [ -z "$(published_version "$name" "$version")" ]; then
: "${NPM_TOKEN:?the publish needs NPM_TOKEN}"
in_image "$node_image" npm ci
in_image "$node_image" npm run build
docker run --rm -u "$(id -u):$(id -g)" -e HOME=/tmp -e NPM_TOKEN -v "$PWD:/app" -w /app --entrypoint sh "$node_image" -c \
'printf "//registry.npmjs.org/:_authToken=%s\n" "$NPM_TOKEN" > "$HOME/.npmrc" && npm publish --access public'
fi
: "${NPM_TOKEN:?the publish needs NPM_TOKEN}"
in_image "$node_image" npm ci
in_image "$node_image" npm run build
in_image "$node_image" sh -c 'printf "//registry.npmjs.org/:_authToken=%s\n" "$NPM_TOKEN" > "$HOME/.npmrc" && npm publish --access public'
git tag "v$version"
git push origin "v$version"
if [ -z "$(git ls-remote --tags origin "v$version")" ]; then
git tag "v$version"
git push origin "v$version"
fi