Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ jobs:
uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '20'
node-version: '22'
- name: Get yarn cache directory path
id: yarn-cache-dir-path
run: |
Expand Down
86 changes: 0 additions & 86 deletions .github/workflows/publish-dev.yml

This file was deleted.

140 changes: 140 additions & 0 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,140 @@
# Copyright (c) 2023-2026 Datalayer, Inc.
# Distributed under the terms of the MIT License.

# Publishes the release a tag names to npm, with no stored token: npm trusts
# this workflow file (OIDC trusted publishing, through the `npm` environment,
# with provenance). The tag must name @datalayer/icons-react's version
# (icons-react/package.json); @datalayer/icons-all, the root package, is
# published too whenever its own version is not on npm yet. A package
# already published at its version is skipped, so a re-run after a partial
# upload publishes the rest. See RELEASE.md.

name: Release

on:
push:
tags:
- 'v*'

concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false

permissions:
contents: read

jobs:
build:
runs-on: ubuntu-latest
outputs:
npm: ${{ steps.plan.outputs.npm }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: '22'

- name: Check the tag names the version icons-react carries
run: |
set -euo pipefail
tag="${GITHUB_REF_NAME#v}"
version="$(node -p "require('./icons-react/package.json').version")"
echo "tag=$tag @datalayer/icons-react=$version"
test "$tag" = "$version"

- name: Find what is not published yet
id: plan
run: |
set -euo pipefail
todo=""
for pkg in icons-react .; do
name="$(node -p "require('./$pkg/package.json').name")"
version="$(node -p "require('./$pkg/package.json').version")"
if npm view "$name@$version" version >/dev/null 2>&1; then
echo "npm: $name@$version is already published, skipping"
else
echo "npm: $name@$version will be published"
todo="$todo $pkg"
fi
done
echo "npm=${todo# }" >> "$GITHUB_OUTPUT"

- name: Build
if: steps.plan.outputs.npm != ''
run: |
set -eux
corepack enable
yarn set version 3.5.0
yarn install
# The icons (svgo, then the React components into icons-react/), and
# the root package's lib/ for @datalayer/icons-all.
yarn run build

- name: Pack
if: steps.plan.outputs.npm != ''
run: |
set -euo pipefail
mkdir -p dist-npm
for pkg in ${{ steps.plan.outputs.npm }}; do
(cd "$pkg" && npm pack --pack-destination "$GITHUB_WORKSPACE/dist-npm")
done
ls -la dist-npm

- uses: actions/upload-artifact@v4
if: steps.plan.outputs.npm != ''
with:
name: npm
path: dist-npm/*.tgz

npm:
needs: build
if: needs.build.outputs.npm != ''
runs-on: ubuntu-latest
environment: npm
permissions:
id-token: write
steps:
- uses: actions/setup-node@v4
with:
node-version: '22'
registry-url: 'https://registry.npmjs.org'
# Trusted publishing needs npm 11.5.1 or later.
- run: npm install -g npm@^11.5.1 && npm --version
- uses: actions/download-artifact@v4
with:
name: npm
path: dist
- name: Publish
run: |
set -euo pipefail
for tarball in dist/*.tgz; do
name="$(tar -xOzf "$tarball" package/package.json | node -p "JSON.parse(require('fs').readFileSync(0)).name")"
version="$(tar -xOzf "$tarball" package/package.json | node -p "JSON.parse(require('fs').readFileSync(0)).version")"
if npm view "$name@$version" version >/dev/null 2>&1; then
echo "$name@$version is already published, skipping"
continue
fi
# "./": npm reads a bare "dist/x.tgz" as the GitHub shorthand
# github:dist/x.tgz and refuses to fetch it (EALLOWGIT).
npm publish "./$tarball" --provenance --access public
done

release:
name: GitHub release
needs: [build, npm]
if: always() && needs.build.result == 'success' && needs.npm.result != 'failure'
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Create the release with generated notes
run: |
version="${GITHUB_REF_NAME#v}"
gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1 && exit 0
gh release create "$GITHUB_REF_NAME" --title "Release $version" --generate-notes \
--notes "- [npm @datalayer/icons-react](https://www.npmjs.com/package/@datalayer/icons-react/v/$version)"
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
6 changes: 0 additions & 6 deletions .yarnrc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,6 @@ nodeLinker: node-modules

npmRegistryServer: "https://registry.yarnpkg.com"

npmScopes:
datalayer:
npmAlwaysAuth: true
npmAuthToken: ghs_ns7WZk63NPmVl1e63w4mId1Q4Dbt0p4T2cSL
npmRegistryServer: "https://npm.pkg.github.com"

packageExtensions:
"@lerna/legacy-package-management@*":
dependencies:
Expand Down
6 changes: 6 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -43,3 +43,9 @@ publish-npm: clean build ## publish to npm
cd icons-react && \
npm publish --access public )
echo open https://www.npmjs.com/package/@datalayer/icons-react

publish-npm-all: clean build ## publish @datalayer/icons-all to npm
@exec echo PUBLISH NPM ICONS-ALL
($(CONDA_ACTIVATE) ${ENV_NAME}; \
npm publish --access public )
echo open https://www.npmjs.com/package/@datalayer/icons-all
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,7 @@ To add an icon to this repository, add the SVG (preferably of viewBox `0 0 20 20
TODO: Describe the difference between `data1` and `data2`.

```bash
npm run build-icons
npm run build:icons
```

You can preview the icons running the following command (sometimes the colors do not correspond due to many icons being shown).
Expand Down
39 changes: 39 additions & 0 deletions RELEASE.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
<!--
~ Copyright (c) 2023-2026 Datalayer, Inc.
~
~ MIT License
-->

# Making a release

A tag releases `@datalayer/icons-react` to npm, with no stored token: npm
trusts `.github/workflows/release.yaml` through OIDC (trusted publishing,
GitHub environment `npm`, with provenance). The tag names the version in
`icons-react/package.json`. `@datalayer/icons-all` (the root package) is
published by the same run whenever its own version is not on npm yet.

## Steps

1. Bump `version` in `icons-react/package.json` (and the root `package.json`
when icons-all should ship too), on a branch, and open a pull request.
2. Merge, then tag the merge commit and push the tag:

```bash
git checkout main && git pull
git tag vX.Y.Z
git push origin vX.Y.Z
```

3. The `Release` workflow checks that the tag names icons-react's version,
builds the icons and the packages, publishes what is not on npm yet, and
creates a GitHub release with generated notes.

## Trusted publishing

npm packages `@datalayer/icons-react` and `@datalayer/icons-all`: GitHub
Actions, organization `datalayer`, repository `icons`, workflow filename
`release.yaml`, environment `npm`. npm provenance also checks each
`package.json`'s `repository.url`, which names this repository.

The registry matches the repository, the workflow filename and the
environment exactly; renaming any of them means re-registering.
Loading
Loading