# Pack the vendored framework sequence: the nine rescoped Cordis packages under # vendor/, each on its own version line. This sequence releases independently of # dsh and of the native packages. # # Pack runs without credentials on every pull request and master push. # Publication is a manual workflow_dispatch of release-vendor-publish.yml from a # vendor-* tag; a vendor release can carry several versions, so each package has # its own tag. name: Release (vendor) on: pull_request: push: branches: [master] workflow_dispatch: permissions: contents: read concurrency: # Pack runs per ref so concurrent pull requests never displace each other. group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: false env: PRIMARY_NODE_VERSION: '24' DSH_TELEMETRY_DISABLED: '1' jobs: pack: name: Pack npm tarballs runs-on: ubuntu-24.04 steps: # Complete history: the release scripts read tags. - uses: actions/checkout@v6 with: fetch-depth: 0 persist-credentials: false - uses: pnpm/action-setup@v4 with: dest: ${{ runner.temp }}/setup-pnpm - uses: actions/setup-node@v6 with: node-version: ${{ env.PRIMARY_NODE_VERSION }} - name: Configure pnpm store path id: pnpm-store run: | store_root="$HOME/.local/share/pnpm/store" echo "PNPM_CONFIG_STORE_DIR=$store_root" >> "$GITHUB_ENV" store_path=$(PNPM_CONFIG_STORE_DIR="$store_root" pnpm store path --silent) echo "path=$store_path" >> "$GITHUB_OUTPUT" - uses: actions/cache/restore@v4 with: path: ${{ steps.pnpm-store.outputs.path }} key: ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }} restore-keys: | ${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm- - name: Install (immutable) run: pnpm install --frozen-lockfile - name: Verify release version run: pnpm run release:verify --family vendor # The vendored packages publish their own sources and build outputs; the # host build produces what their manifests select. - name: Build run: pnpm run build:lib:host - name: Pack release tarballs run: pnpm run release:pack --family vendor --out dist/npm-vendor - name: Verify packed install run: pnpm run release:verify-packed-install --family vendor --from dist/npm-vendor - uses: actions/upload-artifact@v4 with: name: vendor-npm-tarballs path: dist/npm-vendor/* if-no-files-found: error retention-days: 7