Skip to content

feat(web): add Amplitude Analytics and Session Replay through Partyto… #7

feat(web): add Amplitude Analytics and Session Replay through Partyto…

feat(web): add Amplitude Analytics and Session Replay through Partyto… #7

Workflow file for this run

# The npm trusted publisher for every package published from this repo names
# this file by its exact filename. Renaming or moving changesets.yml revokes the publish
# credential, and the release then fails with a misleading E404.
#
# On a push to main:
# - pending changesets -> open/update the "Version Packages" PR, publish nothing
# - no changesets and unpublished versions -> pack, publish, tag, release
# - otherwise -> do nothing
#
# Split into sub-actions (changesets/action v2) so `id-token: write` exists only
# on the job that talks to npm.
name: Changesets
on:
push:
branches: [main]
workflow_dispatch:
# Never cancel a release mid-flight.
concurrency:
group: changesets-${{ github.ref }}
cancel-in-progress: false
env:
NODE_VERSION: 24
permissions: {}
jobs:
# Every other job needs this one, so this guard is the only one required.
# npm trusted publishing does not restrict by branch: without it, a manual
# dispatch on an unreviewed branch could publish that branch to npm.
select-mode:
name: Select mode
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: read
outputs:
mode: ${{ steps.select-mode.outputs.mode }}
publish-plan-artifact-id: ${{ steps.select-mode.outputs.publish-plan-artifact-id }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Select mode
id: select-mode
uses: changesets/action/select-mode@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2
version:
name: Version packages
needs: select-mode
if: needs.select-mode.outputs.mode == 'version'
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: write # the version commit on the release branch
pull-requests: write # the "Version Packages" PR
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Setup pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Open or update the "Version Packages" PR
uses: changesets/action/version@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2
with:
commit-message: "chore(release): version packages"
pr-title: "chore(release): version packages"
# Builds and packs with no write access at all. The tarballs are handed to
# `publish` as an artifact, so nothing that runs during the build ever sees
# the npm credential.
pack:
name: Pack packages
needs: select-mode
if: needs.select-mode.outputs.mode == 'publish'
runs-on: ubuntu-latest
timeout-minutes: 15
permissions:
contents: read
outputs:
pack-dir-artifact-id: ${{ steps.pack.outputs.pack-dir-artifact-id }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Setup pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}
cache: pnpm
- name: Install dependencies
run: pnpm install --frozen-lockfile
- name: Build packages
run: pnpm turbo run build --filter='./packages/*'
- name: Pack
id: pack
uses: changesets/action/pack@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2
with:
publish-plan-artifact-id: ${{ needs.select-mode.outputs.publish-plan-artifact-id }}
publish:
name: Publish to npm
needs: pack
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: write # git tags and GitHub releases
id-token: write # npm trusted publishing (OIDC)
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# v6+ is required: older releases broke OIDC publishing under pnpm 11
# with an E404 that reads like a missing package (pnpm#11513, pnpm#11566).
- name: Setup pnpm
uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0
# No NODE_AUTH_TOKEN, on purpose. Trusted publishing mints a short-lived
# credential from the OIDC token above; there is no npm token to leak.
# No `registry-url` either: it makes setup-node write a placeholder
# NODE_AUTH_TOKEN into .npmrc, which `pnpm publish` could send instead of
# doing the OIDC exchange. npmjs is already the default registry.
# No dependency cache: this job holds the credential, so it restores
# nothing another job could have written.
- name: Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: ${{ env.NODE_VERSION }}
# Only the Changesets CLI is needed here; the tarballs were built in
# `pack`. Skipping lifecycle scripts keeps dependency code from running
# next to the OIDC token.
- name: Install dependencies
run: pnpm install --frozen-lockfile --ignore-scripts
- name: Publish, tag and release
uses: changesets/action/publish@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2
with:
pack-dir-artifact-id: ${{ needs.pack.outputs.pack-dir-artifact-id }}