From d1522b217753e79fe73ea3c2c84823e8ff8eb331 Mon Sep 17 00:00:00 2001 From: Saad Najmi Date: Tue, 29 Sep 2026 14:46:24 -0700 Subject: [PATCH] ci: copy example from changeset v3 docs --- .../microsoft-setup-toolchain/action.yml | 2 +- .../microsoft-changesets-version.yml | 58 --------- .github/workflows/microsoft-npm-publish.yml | 121 ++++++++++++++---- 3 files changed, 98 insertions(+), 83 deletions(-) delete mode 100644 .github/workflows/microsoft-changesets-version.yml diff --git a/.github/actions/microsoft-setup-toolchain/action.yml b/.github/actions/microsoft-setup-toolchain/action.yml index d6fc8ead611c..c72b6514d618 100644 --- a/.github/actions/microsoft-setup-toolchain/action.yml +++ b/.github/actions/microsoft-setup-toolchain/action.yml @@ -63,7 +63,7 @@ runs: distribution: temurin java-version: ${{ inputs.java-version }} - name: Set up Node.js - uses: actions/setup-node@v4.4.0 + uses: actions/setup-node@v7 with: node-version: ${{ inputs.node-version }} cache: ${{ inputs.cache-npm-dependencies }} diff --git a/.github/workflows/microsoft-changesets-version.yml b/.github/workflows/microsoft-changesets-version.yml deleted file mode 100644 index 00ae52403e10..000000000000 --- a/.github/workflows/microsoft-changesets-version.yml +++ /dev/null @@ -1,58 +0,0 @@ -name: Changesets Version Bump - -on: - push: - branches: - - "*-stable" - workflow_dispatch: - -concurrency: - group: changesets-version-${{ github.ref }} - cancel-in-progress: true - -jobs: - version: - name: Create Version Bump PR - runs-on: ubuntu-latest - - if: ${{ github.repository == 'microsoft/react-native-macos' }} - steps: - - name: Checkout - uses: actions/checkout@v6 - with: - filter: blob:none - fetch-depth: 0 - persist-credentials: false - - - name: Setup toolchain - uses: ./.github/actions/microsoft-setup-toolchain - with: - node-version: '22' - - - name: Install dependencies - run: yarn install --immutable - - - name: Test publishing contract - run: node --test .github/scripts/__tests__/publishing-contract.test.mjs - - - name: Generate token for version PR - uses: actions/create-github-app-token@v2 - id: app-token - with: - app-id: ${{ vars.APP_ID }} - private-key: ${{ secrets.GH_APP_PRIVATE_KEY }} - permission-contents: write # for GH releases and Git tags (Changesets) - permission-pull-requests: write # version PRs (Changesets) - - - name: Check stable branch head - id: current-head - run: node .github/scripts/check-version-head.mjs - - - name: Create Version Bump PR - if: steps.current-head.outputs.current == 'true' - uses: changesets/action@v1 - with: - version: yarn changeset:version - createGithubReleases: false - env: - GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} diff --git a/.github/workflows/microsoft-npm-publish.yml b/.github/workflows/microsoft-npm-publish.yml index 858cd018b284..7515c6e2d3df 100644 --- a/.github/workflows/microsoft-npm-publish.yml +++ b/.github/workflows/microsoft-npm-publish.yml @@ -4,39 +4,115 @@ on: push: branches: - "*-stable" + workflow_dispatch: +# recommended: reset permissions and explicitly specify for each job +permissions: {} + +# recommended: avoid concurrent runs for the same branch concurrency: - # Serialize release lines because they share the latest and next tags. - group: npm-publish - # GitHub.com supports up to 100 pending runs; do not replace a release push. - queue: max - cancel-in-progress: false + group: ${{ github.workflow }}-${{ github.ref }} jobs: - publish: - name: Publish to npm + select-mode: + if: github.repository == 'microsoft/react-native-macos' runs-on: ubuntu-latest + outputs: + mode: ${{ steps.select-mode.outputs.mode }} + publish-plan-artifact-id: ${{ steps.select-mode.outputs.publish-plan-artifact-id }} + permissions: + contents: read # to check out repo (actions/checkout) + steps: + - name: Check out repo + uses: actions/checkout@v7 + with: + persist-credentials: false # recommended: do not persist git credentials on disk - if: github.repository == 'microsoft/react-native-macos' + - name: Setup toolchain + uses: ./.github/actions/microsoft-setup-toolchain - # Matches the environment name registered as a Trusted Publisher on npmjs.com. - environment: npm-publish + - name: Install dependencies + run: yarn install --immutable + - name: Select Changesets mode + id: select-mode + uses: changesets/action/select-mode@v2 + + version: + if: needs.select-mode.outputs.mode == 'version' && github.repository == 'microsoft/react-native-macos' + needs: select-mode + runs-on: ubuntu-latest + outputs: + version-dir-artifact-id: ${{ steps.version.outputs.version-dir-artifact-id }} permissions: - contents: read - id-token: write + contents: write # to check out repo (actions/checkout) and commit version changes (changesets/action/version) + pull-requests: write # to create pull request (changesets/action/version) + steps: + - name: Check out repo + uses: actions/checkout@v7 + with: + persist-credentials: false # recommended: do not persist git credentials on disk + + - name: Setup toolchain + uses: ./.github/actions/microsoft-setup-toolchain + - name: Install dependencies + run: yarn install --immutable + + - name: Verify release config + id: configure-publish + run: node .ado/scripts/configure-publish.mts --verbose + + - name: Version packages + id: version + uses: changesets/action/version@v2 + + pack: + if: needs.select-mode.outputs.mode == 'publish' + needs: select-mode + runs-on: ubuntu-latest + outputs: + pack-dir-artifact-id: ${{ steps.pack.outputs.pack-dir-artifact-id }} + permissions: + contents: read # to check out repo (actions/checkout) steps: - - name: Checkout - uses: actions/checkout@v4 + - name: Check out repo + uses: actions/checkout@v7 with: - filter: blob:none - fetch-depth: 0 + persist-credentials: false # recommended: do not persist git credentials on disk - name: Setup toolchain uses: ./.github/actions/microsoft-setup-toolchain + + - name: Install dependencies + run: yarn install --immutable + + - name: Verify release config + id: configure-publish + run: node .ado/scripts/configure-publish.mts --verbose + + - name: Pack packages + id: pack + uses: changesets/action/pack@v2 with: - node-version: "22" + publish-plan-artifact-id: ${{ needs.select-mode.outputs.publish-plan-artifact-id }} + + publish: + needs: pack + runs-on: ubuntu-latest + # Matches the environment name registered as a Trusted Publisher on npmjs.com. + environment: npm-publish + permissions: + contents: write # to check out repo (actions/checkout) and to create releases (changesets/action/publish) + id-token: write # for trusted publishing (changesets/action/publish) + steps: + - name: Check out repo + uses: actions/checkout@v7 + with: + persist-credentials: false # recommended: do not persist git credentials on disk + + - name: Setup toolchain + uses: ./.github/actions/microsoft-setup-toolchain - name: Install dependencies run: yarn install --immutable @@ -46,12 +122,9 @@ jobs: run: node .ado/scripts/configure-publish.mts --verbose - name: Publish packages - if: steps.configure-publish.outputs.publish_react_native_macos == '1' - run: | - yarn workspaces foreach -vv --all --topological --no-private npm publish \ - --provenance \ - --tag "${{ steps.configure-publish.outputs.publishTag }}" \ - --tolerate-republish + uses: changesets/action/publish@v2 + with: + pack-dir-artifact-id: ${{ needs.pack.outputs.pack-dir-artifact-id }} env: YARN_NPM_PUBLISH_ACCESS: public - YARN_NPM_PUBLISH_REGISTRY: https://registry.npmjs.org + YARN_NPM_PUBLISH_REGISTRY: https://registry.npmjs.org \ No newline at end of file