feat(web): add Amplitude Analytics and Session Replay through Partyto… #7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # The npm trusted publisher for every package published from this repo names | |
| # this file by its exact filename. Renaming or moving changesets.yml revokes the publish | |
| # credential, and the release then fails with a misleading E404. | |
| # | |
| # On a push to main: | |
| # - pending changesets -> open/update the "Version Packages" PR, publish nothing | |
| # - no changesets and unpublished versions -> pack, publish, tag, release | |
| # - otherwise -> do nothing | |
| # | |
| # Split into sub-actions (changesets/action v2) so `id-token: write` exists only | |
| # on the job that talks to npm. | |
| name: Changesets | |
| on: | |
| push: | |
| branches: [main] | |
| workflow_dispatch: | |
| # Never cancel a release mid-flight. | |
| concurrency: | |
| group: changesets-${{ github.ref }} | |
| cancel-in-progress: false | |
| env: | |
| NODE_VERSION: 24 | |
| permissions: {} | |
| jobs: | |
| # Every other job needs this one, so this guard is the only one required. | |
| # npm trusted publishing does not restrict by branch: without it, a manual | |
| # dispatch on an unreviewed branch could publish that branch to npm. | |
| select-mode: | |
| name: Select mode | |
| if: github.ref == 'refs/heads/main' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| outputs: | |
| mode: ${{ steps.select-mode.outputs.mode }} | |
| publish-plan-artifact-id: ${{ steps.select-mode.outputs.publish-plan-artifact-id }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Select mode | |
| id: select-mode | |
| uses: changesets/action/select-mode@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2 | |
| version: | |
| name: Version packages | |
| needs: select-mode | |
| if: needs.select-mode.outputs.mode == 'version' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: write # the version commit on the release branch | |
| pull-requests: write # the "Version Packages" PR | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| fetch-depth: 0 | |
| persist-credentials: false | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Open or update the "Version Packages" PR | |
| uses: changesets/action/version@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2 | |
| with: | |
| commit-message: "chore(release): version packages" | |
| pr-title: "chore(release): version packages" | |
| # Builds and packs with no write access at all. The tarballs are handed to | |
| # `publish` as an artifact, so nothing that runs during the build ever sees | |
| # the npm credential. | |
| pack: | |
| name: Pack packages | |
| needs: select-mode | |
| if: needs.select-mode.outputs.mode == 'publish' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| permissions: | |
| contents: read | |
| outputs: | |
| pack-dir-artifact-id: ${{ steps.pack.outputs.pack-dir-artifact-id }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 | |
| - name: Setup Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| cache: pnpm | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile | |
| - name: Build packages | |
| run: pnpm turbo run build --filter='./packages/*' | |
| - name: Pack | |
| id: pack | |
| uses: changesets/action/pack@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2 | |
| with: | |
| publish-plan-artifact-id: ${{ needs.select-mode.outputs.publish-plan-artifact-id }} | |
| publish: | |
| name: Publish to npm | |
| needs: pack | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: write # git tags and GitHub releases | |
| id-token: write # npm trusted publishing (OIDC) | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # v6+ is required: older releases broke OIDC publishing under pnpm 11 | |
| # with an E404 that reads like a missing package (pnpm#11513, pnpm#11566). | |
| - name: Setup pnpm | |
| uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 | |
| # No NODE_AUTH_TOKEN, on purpose. Trusted publishing mints a short-lived | |
| # credential from the OIDC token above; there is no npm token to leak. | |
| # No `registry-url` either: it makes setup-node write a placeholder | |
| # NODE_AUTH_TOKEN into .npmrc, which `pnpm publish` could send instead of | |
| # doing the OIDC exchange. npmjs is already the default registry. | |
| # No dependency cache: this job holds the credential, so it restores | |
| # nothing another job could have written. | |
| - name: Setup Node.js | |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| # Only the Changesets CLI is needed here; the tarballs were built in | |
| # `pack`. Skipping lifecycle scripts keeps dependency code from running | |
| # next to the OIDC token. | |
| - name: Install dependencies | |
| run: pnpm install --frozen-lockfile --ignore-scripts | |
| - name: Publish, tag and release | |
| uses: changesets/action/publish@ae32849d5ba541f9ae29e40e22a623bc13562f51 # v2.1.2 | |
| with: | |
| pack-dir-artifact-id: ${{ needs.pack.outputs.pack-dir-artifact-id }} |