Skip to content

Merge pull request #148 from sillsdev/supplyChainHardening #163

Merge pull request #148 from sillsdev/supplyChainHardening

Merge pull request #148 from sillsdev/supplyChainHardening #163

Workflow file for this run

name: Build-Test-Release
on:
push:
branches:
- main
concurrency:
group: release-main
cancel-in-progress: false
# Keep setup/test semantics aligned with runTests.yml where applicable.
jobs:
build-test-release:
if: github.actor != 'github-actions[bot]'
runs-on: windows-latest
permissions:
contents: write
pages: write
id-token: write
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Node, dependencies, and Playwright
uses: ./.github/actions/setup-ci-deps
# Extract new messages, upload to Crowdin, download latest translations
- name: Extract messages
run: npm run l10n:extract
- name: Upload source strings to Crowdin
run: npm run l10n:upload
env:
ETHNOLIB_CROWDIN_TOKEN: ${{ secrets.ETHNOLIB_CROWDIN_TOKEN }}
- name: Download translations from Crowdin
run: npm run l10n:download
env:
ETHNOLIB_CROWDIN_TOKEN: ${{ secrets.ETHNOLIB_CROWDIN_TOKEN }}
- name: Update locales list
run: npm run l10n:update-locales
- name: Compile messages
run: npm run l10n:compile
# We've configured nx to update version numbers in the primary package.json files (rather than in the dist builds to be published)
# Therefore this step must be done before build so that the new version numbers are copied to dist/package.json
- name: Update version numbers in the persistent package.json files
run: npx nx release version
- name: Build package and run tests
uses: ./.github/actions/build-and-test
- name: Set name and email for git so we can commit and tag
run: |
git config user.name "Github Actions"
git config user.email "no-reply@ethnolib-build.com"
- name: Publish
env:
NPM_CONFIG_PROVENANCE: true
shell: bash
run: |
set -euo pipefail
npm config set provenance true
npx nx release --yes 2>&1 | tee nx-release.log
# Nx was failing without propagating a failing exit code.
# Fail the step (and therefore the job) if the output indicates publish failed.
if grep -Eqi "npm publish error:|Failed tasks:|nx-release-publish.*failed" nx-release.log; then
echo "Detected publish failure in nx output."
exit 1
fi
- name: Push the release commit (with version number update and changelog)
run: git push
- name: Push the release tag
run: git push --tags
- name: Build storybook
run: npm run --workspace components/language-chooser/react/language-chooser-react-mui build-storybook:composed
- name: Build composed Svelte storybook
shell: bash
run: |
npm run --workspace components/language-chooser/svelte/language-chooser-svelte-daisyui build-storybook -- --output-dir ../../react/language-chooser-react-mui/storybook-static/svelte
- name: Upload for deploy to github pages
uses: actions/upload-pages-artifact@v3
with:
path: components/language-chooser/react/language-chooser-react-mui/storybook-static
- name: Deploy to GitHub Pages
uses: actions/deploy-pages@v4
with:
token: ${{ github.token }}