mirror of
https://github.com/modelstudioai/cli.git
synced 2026-09-14 19:49:23 +08:00
141 lines
5.3 KiB
YAML
141 lines
5.3 KiB
YAML
name: Publish
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
package:
|
|
description: "Which package set to publish"
|
|
required: true
|
|
type: choice
|
|
options:
|
|
- bailian-cli
|
|
- knowledge-studio-cli
|
|
mode:
|
|
description: "Publish mode"
|
|
required: true
|
|
type: choice
|
|
options:
|
|
- channel
|
|
- stable
|
|
channel:
|
|
description: "Required when mode=channel. npm dist-tag only (lowercase, digits, dashes), e.g. mcp / plugin / sync-release. bailian-cli binary CDN always overwrites sync-release.json; knowledge-studio-cli is npm-only."
|
|
required: false
|
|
type: string
|
|
|
|
concurrency:
|
|
group: publish-${{ inputs.package }}-${{ inputs.mode }}-${{ inputs.channel }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
publish-stable:
|
|
if: inputs.mode == 'stable'
|
|
name: publish stable (${{ inputs.package }}) to npm + binary + tag
|
|
runs-on: ubuntu-latest
|
|
environment: production # Required Reviewers gate
|
|
permissions:
|
|
contents: write # push tag + create GitHub Release with binary assets
|
|
id-token: write # OIDC for npm Trusted Publishing + provenance
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- uses: actions/setup-node@v6
|
|
with:
|
|
node-version: "24"
|
|
cache: pnpm
|
|
registry-url: "https://registry.npmjs.org/"
|
|
|
|
- name: Install gitleaks
|
|
run: |
|
|
set -euo pipefail
|
|
GITLEAKS_VERSION=8.21.2
|
|
curl -sSfL \
|
|
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \
|
|
| sudo tar -xz -C /usr/local/bin gitleaks
|
|
gitleaks version
|
|
|
|
- name: Ensure zip (per-platform binary archives)
|
|
run: sudo apt-get update && sudo apt-get install -y zip
|
|
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
# Binary compile uses `bun build --compile` CLI (not Bun.build API).
|
|
# Keep this pin in sync with any local smoke tests of binary-compile.mjs.
|
|
- uses: oven-sh/setup-bun@v2
|
|
with:
|
|
bun-version: "1.2.19"
|
|
|
|
- name: publish-stable
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
# OSS release channel runs fully in CI: upload + reconcile + manifest.json.
|
|
# All values come from repo Settings → Secrets — no OSS defaults live in
|
|
# code. Leave AK/SK unset to skip the OSS channel; once enabled,
|
|
# bucket/region/prefix are required.
|
|
BAILIAN_OSS_AK: ${{ secrets.BAILIAN_OSS_AK }}
|
|
BAILIAN_OSS_SK: ${{ secrets.BAILIAN_OSS_SK }}
|
|
BAILIAN_OSS_BUCKET: ${{ secrets.BAILIAN_OSS_BUCKET }}
|
|
BAILIAN_OSS_REGION: ${{ secrets.BAILIAN_OSS_REGION }}
|
|
BAILIAN_OSS_ENDPOINT: ${{ secrets.BAILIAN_OSS_ENDPOINT }}
|
|
BAILIAN_RELEASE_PREFIX: ${{ secrets.BAILIAN_RELEASE_PREFIX }}
|
|
BAILIAN_STATIC_PREFIX: ${{ secrets.BAILIAN_STATIC_PREFIX }}
|
|
run: node tools/release/publish-stable.mjs ${{ inputs.package == 'knowledge-studio-cli' && '--knowledge' || '' }}
|
|
|
|
publish-channel:
|
|
if: inputs.mode == 'channel'
|
|
name: publish channel (${{ inputs.package }}) to npm + binary
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write # create prerelease GitHub Release with binary assets
|
|
id-token: write # OIDC for npm Trusted Publishing + provenance
|
|
steps:
|
|
- name: Require channel input
|
|
if: ${{ inputs.channel == '' }}
|
|
run: |
|
|
echo "::error::mode=channel requires the workflow input \"channel\" (npm dist-tag, e.g. mcp / plugin / sync-release). Leave mode=stable if you do not need a dist-tag."
|
|
exit 1
|
|
|
|
- uses: actions/checkout@v6
|
|
|
|
- uses: pnpm/action-setup@v6
|
|
|
|
- uses: actions/setup-node@v6
|
|
with:
|
|
node-version: "24"
|
|
cache: pnpm
|
|
registry-url: "https://registry.npmjs.org/"
|
|
|
|
- name: Install gitleaks
|
|
run: |
|
|
set -euo pipefail
|
|
GITLEAKS_VERSION=8.21.2
|
|
curl -sSfL \
|
|
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz" \
|
|
| sudo tar -xz -C /usr/local/bin gitleaks
|
|
gitleaks version
|
|
|
|
- name: Ensure zip (per-platform binary archives)
|
|
run: sudo apt-get update && sudo apt-get install -y zip
|
|
|
|
- run: pnpm install --frozen-lockfile
|
|
|
|
# Binary compile uses `bun build --compile` CLI (not Bun.build API).
|
|
# Keep this pin in sync with any local smoke tests of binary-compile.mjs.
|
|
- uses: oven-sh/setup-bun@v2
|
|
with:
|
|
bun-version: "1.2.19"
|
|
|
|
- name: publish-channel
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
# OSS release channel — same Settings-injected values as stable.
|
|
BAILIAN_OSS_AK: ${{ secrets.BAILIAN_OSS_AK }}
|
|
BAILIAN_OSS_SK: ${{ secrets.BAILIAN_OSS_SK }}
|
|
BAILIAN_OSS_BUCKET: ${{ secrets.BAILIAN_OSS_BUCKET }}
|
|
BAILIAN_OSS_REGION: ${{ secrets.BAILIAN_OSS_REGION }}
|
|
BAILIAN_OSS_ENDPOINT: ${{ secrets.BAILIAN_OSS_ENDPOINT }}
|
|
BAILIAN_RELEASE_PREFIX: ${{ secrets.BAILIAN_RELEASE_PREFIX }}
|
|
BAILIAN_STATIC_PREFIX: ${{ secrets.BAILIAN_STATIC_PREFIX }}
|
|
run: node tools/release/publish-channel.mjs ${{ inputs.package == 'knowledge-studio-cli' && '--knowledge' || '' }} --channel "${{ inputs.channel }}"
|