-
Notifications
You must be signed in to change notification settings - Fork 411
189 lines (154 loc) · 5.67 KB
/
Copy pathpublish-es-packages.yml
File metadata and controls
189 lines (154 loc) · 5.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
name: Publish Noir ES Packages
on:
workflow_dispatch:
inputs:
noir-ref:
description: The noir reference to checkout
required: false
default: "master"
npm-tag:
description: Repository Tag to publish under
required: false
default: "nightly"
run-name: Publish ES Packages from ${{ inputs.noir-ref }} under @${{ inputs.npm-tag }} tag.
permissions: {}
# Authenticate cargo-binstall's GitHub API requests (run by `just build-package`
# via install-js-tools). Unauthenticated they hit GitHub's 60 req/hour limit, get
# 403, and binstall falls back to compiling the wasm toolchain from source —
# turning a ~30s step into minutes. A valid token raises the limit to 5000/hour;
# it needs no permission scopes for this (only public release metadata is read).
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
jobs:
build-noirc_abi_wasm:
runs-on: ubuntu-22.04
permissions:
contents: read
steps:
- name: Checkout Noir repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.noir-ref }}
- name: Setup toolchain
uses: dtolnay/rust-toolchain@1.89.0
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
key: noirc-abi
save-if: false
- name: Install Yarn dependencies
uses: ./.github/actions/setup
- uses: taiki-e/install-action@just
- name: Build noirc_abi
run: just build-package @noir-lang/noirc_abi
- name: Upload artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: noirc_abi_wasm
path: |
./tooling/noirc_abi_wasm/nodejs
./tooling/noirc_abi_wasm/web
retention-days: 10
build-noir_wasm:
runs-on: ubuntu-22.04
permissions:
contents: read
steps:
- name: Checkout sources
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.noir-ref }}
- name: Setup toolchain
uses: dtolnay/rust-toolchain@1.89.0
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
key: noir-wasm
save-if: false
- uses: taiki-e/install-action@just
- name: Install Yarn dependencies
uses: ./.github/actions/setup
- name: Build noir_js_types
run: just build-package @noir-lang/types
- name: Build noir_wasm
run: just build-package @noir-lang/noir_wasm
- name: Upload artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: noir_wasm
path: |
./compiler/wasm/dist
./compiler/wasm/build
retention-days: 3
build-acvm_js:
runs-on: ubuntu-22.04
permissions:
contents: read
steps:
- name: Checkout sources
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.noir-ref }}
- name: Setup toolchain
uses: dtolnay/rust-toolchain@1.89.0
- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
key: acvm-js
save-if: false
- name: Install Yarn dependencies
uses: ./.github/actions/setup
- uses: taiki-e/install-action@just
- name: Build acvm_js
run: just build-package @noir-lang/acvm_js
- name: Upload artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: acvm-js
path: |
./acvm-repo/acvm_js/nodejs
./acvm-repo/acvm_js/web
retention-days: 3
publish-es-packages:
runs-on: ubuntu-22.04
needs: [build-acvm_js, build-noirc_abi_wasm, build-noir_wasm]
permissions:
contents: read
id-token: write # Necessary for NPM provenance: https://docs.npmjs.com/generating-provenance-statements
issues: write # To alert on failure
steps:
- name: Checkout sources
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.noir-ref }}
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: acvm-js
path: acvm-repo/acvm_js
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: noir_wasm
path: compiler/wasm
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
name: noirc_abi_wasm
path: tooling/noirc_abi_wasm
- name: Install Yarn dependencies
uses: ./.github/actions/setup
- name: Build ES Packages
run: yarn build:js:only
- name: Prepare nightly version
if: ${{ inputs.npm-tag != 'latest' }}
run: |
yarn nightly:version -- .${{ inputs.npm-tag }}
- name: Publish ES Packages
run: yarn publish:all --provenance --access public --tag ${{ inputs.npm-tag }}
# Raise an issue if any package failed to publish
- name: Alert on failed publish
uses: JasonEtco/create-an-issue@1b14a70e4d8dc185e5cc76d3bec9eab20257b2c5 # v2
if: ${{ failure() }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
NPM_TAG: ${{ inputs.npm-tag }}
WORKFLOW_NAME: ${{ github.workflow }}
WORKFLOW_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
with:
update_existing: true
filename: .github/JS_PUBLISH_FAILED.md