Skip to content

build(deps): bump actions/dependency-review-action from 4.6.0 to 4.7.… #92

build(deps): bump actions/dependency-review-action from 4.6.0 to 4.7.…

build(deps): bump actions/dependency-review-action from 4.6.0 to 4.7.… #92

on:
push:
branches:
- main
permissions:
contents: write
pull-requests: write
name: Run Release Please
jobs:
release-please:
runs-on: ubuntu-latest
steps:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
with:
egress-policy: audit
- uses: googleapis/release-please-action@a02a34c4d625f9be7cb89156071d8567266a2445 # v4.2.0
id: release
with:
token: ${{ secrets.RATE_TOKEN_GH }}
outputs:
release_created: ${{ steps.release.outputs.release_created }}
tag_name: ${{ steps.release.outputs.tag_name }}
publish:
needs: [release-please]
runs-on: ubuntu-latest
steps:
# The logic below handles the npm publication:
- name: Harden Runner
uses: step-security/harden-runner@c6295a65d1254861815972266d5933fd6e532bdf # v2.11.1
with:
egress-policy: audit
- name: Checkout Repository
if: ${{ needs.release-please.outputs.release_created }}
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Setup Node
uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
if: ${{ needs.release-please.outputs.release_created }}
with:
node-version: 18
registry-url: 'https://registry.npmjs.org'
- name: Build Packages
if: ${{ needs.release-please.outputs.release_created }}
run: ci/build-and-test.sh
env:
NODE_VERSION: 18
FORCE_COLOR: true
# Release Please has already incremented versions and published tags, so we just
# need to publish all unpublished versions to NPM here
# See: https://github.com/lerna/lerna/tree/main/commands/publish#bump-from-package
# - name: Publish to NPM
# if: ${{ needs.release-please.outputs.release_created }}
# env:
# NODE_AUTH_TOKEN: ${{secrets.CONTRACT_CASE_NPM}}
# run: npx lerna publish from-package --no-push --no-private --yes