diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 66c8f48..9a02573 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -18,6 +18,7 @@ env: IOS_XCFRAMEWORK: AmbireCryptoFramework.xcframework # npm stage landed in 11.15.0; the npm bundled with Node is often older. NPM_VERSION: ^11.15.0 + STAGE_RESULT: npm-stage-result.json jobs: build-android: @@ -147,18 +148,24 @@ jobs: # known to work on the directory form; trusted publishing stamps it # without --provenance. if: github.event_name == 'push' || inputs.stage - run: npm stage publish --ignore-scripts + run: | + npm stage publish --ignore-scripts --json > "$RUNNER_TEMP/$STAGE_RESULT" + cat "$RUNNER_TEMP/$STAGE_RESULT" - name: Summarise what is waiting for approval + # Reads the stage id from the publish result rather than asking npm, + # because only publish trades the OIDC token for an npm one. Any other + # npm call here is unauthenticated and fails with E401. if: github.event_name == 'push' || inputs.stage run: | - name="$(node -p "require('./package.json').name")" + stage_id="$(jq -er '.[].stageId' "$RUNNER_TEMP/$STAGE_RESULT")" { echo "### Staged, waiting for approval" echo - echo '```' - npm stage list "$name" - echo '```' + echo "A maintainer approves it with 2FA:" echo - echo "Approve with \`npm stage approve \` (needs 2FA)." + echo '```sh' + echo "npm stage view $stage_id" + echo "npm stage approve $stage_id" + echo '```' } >> "$GITHUB_STEP_SUMMARY" diff --git a/README.md b/README.md index 065de5e..7fd2b55 100644 --- a/README.md +++ b/README.md @@ -183,7 +183,8 @@ npm stage view npm stage approve ``` -The run summary of the release workflow lists what is waiting. `npm stage +The run summary of the release workflow gives the stage id and the commands to +approve it. `npm stage reject ` throws a bad build away instead. Both need npm 11.15.0 or later.