diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index ed9d8509..fe0400dd 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,29 +1,31 @@ name: Build on: [push, pull_request] +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + permissions: contents: read - id-token: write - packages: write jobs: - build: - runs-on: ${{ matrix.os }} - strategy: - matrix: - os: - - ubuntu-latest - - macos-latest - - windows-latest - node_version: - - 24 - name: Node ${{ matrix.node_version }} on ${{ matrix.os }} + version: + name: Determine build version + runs-on: ubuntu-latest + outputs: + version: ${{ steps.version.outputs.version }} steps: - name: Checkout - uses: actions/checkout@v6 + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: fetch-depth: 0 - - name: Build Reason + persist-credentials: false + - name: Setup .NET SDK for MinVer + uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 + with: + dotnet-version: "10.0.x" + - name: Build Version + id: version shell: bash run: | branch=${GITHUB_REF##*/}. @@ -36,68 +38,127 @@ jobs: elif [[ "${GITHUB_REF}" = refs/pull* ]]; then branch="" fi - echo "GIT_BRANCH_SUFFIX=$branch" >> $GITHUB_ENV - echo "ref: $GITHUB_REF event: $GITHUB_EVENT_NAME branch_suffix: $branch" - - name: Setup Node.js environment - uses: actions/setup-node@v6 - with: - node-version: ${{ matrix.node_version }} - registry-url: "https://registry.npmjs.org" - - name: Cache node_modules - uses: actions/cache@v5 - with: - path: node_modules - key: ${{ matrix.node_version }}-${{ runner.os }}-node-modules-${{ hashFiles('package-lock.json') }} - - name: Setup .NET SDK for MinVer - uses: actions/setup-dotnet@v5 - with: - dotnet-version: "10.0.x" - - name: Build Version - id: version - shell: bash - run: | + dotnet tool install --global minver-cli --version 7.0.0 - version=$(minver --tag-prefix v --default-pre-release-identifiers "preview.${GIT_BRANCH_SUFFIX}0" --minimum-major-minor 3.0) + version=$(minver --tag-prefix v --default-pre-release-identifiers "preview.${branch}0" --minimum-major-minor 3.0) - # If on a non-main branch, insert branch name before the height (last numeric segment) - if [ -n "$GIT_BRANCH_SUFFIX" ]; then - branch_name="${GIT_BRANCH_SUFFIX%.}" + if [ -n "$branch" ]; then + branch_name="${branch%.}" if [[ "$version" != *"$branch_name"* ]]; then - version=$(echo "$version" | sed -E "s/\.([0-9]+)$/.${GIT_BRANCH_SUFFIX}\1/") + version=$(echo "$version" | sed -E "s/\.([0-9]+)$/.${branch}\1/") fi fi - echo "version=$version" >> $GITHUB_OUTPUT + echo "version=$version" >> "$GITHUB_OUTPUT" echo "Version: $version" - echo "### Version: $version" >> $GITHUB_STEP_SUMMARY + echo "### Version: $version" >> "$GITHUB_STEP_SUMMARY" - npm install --global replace-in-files-cli - replace-in-files --string="3.0.0-dev" --replacement=$version packages/core/src/configuration/Configuration.ts - replace-in-files --string="3.0.0-dev" --replacement=$version **/package*.json - npm ci + build: + needs: version + runs-on: ${{ matrix.os }} + strategy: + matrix: + os: + - ubuntu-latest + - macos-latest + - windows-latest + node_version: + - 24 + name: Node ${{ matrix.node_version }} on ${{ matrix.os }} + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Setup Node.js environment + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: ${{ matrix.node_version }} + registry-url: "https://registry.npmjs.org" + cache: npm + cache-dependency-path: package-lock.json + - name: Apply Build Version + env: + BUILD_VERSION: ${{ needs.version.outputs.version }} + run: node scripts/set-build-version.mjs + - name: Install Dependencies + run: npm ci - name: Build run: npm run build - name: Lint run: npm run lint - name: Run Tests run: npm test + + publish-release: + name: Publish npm release + if: startsWith(github.ref, 'refs/tags/v') + needs: [version, build] + runs-on: ubuntu-latest + permissions: + contents: read + id-token: write # Required for npm trusted publishing. + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + - name: Setup Node.js environment + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: 24 + registry-url: "https://registry.npmjs.org" + cache: npm + cache-dependency-path: package-lock.json + - name: Apply Build Version + env: + BUILD_VERSION: ${{ needs.version.outputs.version }} + run: node scripts/set-build-version.mjs + - name: Install Dependencies + run: npm ci + - name: Build + run: npm run build - name: Publish Release Packages - if: startsWith(github.ref, 'refs/tags/v') && matrix.os == 'ubuntu-latest' run: npm publish --workspaces --access public - - name: Setup GitHub CI Node.js environment - if: github.event_name != 'pull_request' && startsWith(github.ref, 'refs/heads/') && matrix.os == 'ubuntu-latest' && contains(steps.version.outputs.version, '-') - uses: actions/setup-node@v6 + + publish-github: + name: Publish GitHub CI packages + if: github.event_name == 'push' && startsWith(github.ref, 'refs/heads/') && contains(needs.version.outputs.version, '-') + needs: [version, build] + runs-on: ubuntu-latest + permissions: + contents: read + packages: write # Required to publish with GITHUB_TOKEN. + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: - node-version: ${{ matrix.node_version }} + persist-credentials: false + - name: Setup Node.js environment + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: 24 + registry-url: "https://registry.npmjs.org" + cache: npm + cache-dependency-path: package-lock.json + - name: Apply Build Version + env: + BUILD_VERSION: ${{ needs.version.outputs.version }} + run: node scripts/set-build-version.mjs + - name: Install Dependencies + run: npm ci + - name: Build + run: npm run build + - name: Setup GitHub Packages registry + uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 + with: + node-version: 24 registry-url: "https://npm.pkg.github.com" scope: "@exceptionless" - name: Push GitHub CI Packages - if: github.event_name != 'pull_request' && startsWith(github.ref, 'refs/heads/') && matrix.os == 'ubuntu-latest' && contains(steps.version.outputs.version, '-') shell: bash - run: | - TAG_BRANCH="${GIT_BRANCH_SUFFIX%.}" - TAG_BRANCH="${TAG_BRANCH:-main}" - TAG_BRANCH="${TAG_BRANCH//\//-}" - npm publish --workspaces --access public --tag "ci-${TAG_BRANCH}" || true + run: | # zizmor: ignore[use-trusted-publishing] GitHub Packages uses GITHUB_TOKEN. + TAG_BRANCH="${GITHUB_REF##*/}" + npm publish --workspaces --access public --tag "ci-${TAG_BRANCH}" env: - NODE_AUTH_TOKEN: ${{secrets.GITHUB_TOKEN}} + NODE_AUTH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.npmrc b/.npmrc index 8a82e4e2..825d3f87 100644 --- a/.npmrc +++ b/.npmrc @@ -1,2 +1,4 @@ legacy-peer-deps=true min-release-age=7 +# Security fixes for GHSA-w2rr-34g9-rvrj, GHSA-4w3w-2rp5-g8jm, and GHSA-g53g-w8rj-fmg7. +min-release-age-exclude[]=@xmldom/xmldom diff --git a/eslint.config.mjs b/eslint.config.mjs index 9513ed0d..0c16618d 100644 --- a/eslint.config.mjs +++ b/eslint.config.mjs @@ -31,6 +31,17 @@ export default defineConfig( "@typescript-eslint/no-misused-promises": ["error", { checksVoidReturn: false }] } }, + { + files: ["scripts/**/*.mjs"], + ...tseslint.configs.disableTypeChecked, + languageOptions: { + ...tseslint.configs.disableTypeChecked.languageOptions, + globals: { + console: "readonly", + process: "readonly" + } + } + }, eslintConfigPrettier, { files: ["**/test/**/*.ts"], diff --git a/example/browser/index.html b/example/browser/index.html index 9da74706..ec1fec60 100644 --- a/example/browser/index.html +++ b/example/browser/index.html @@ -15,7 +15,7 @@