diff --git a/.github/workflows/bump.yml b/.github/workflows/bump.yml index 53cec85..96104b0 100644 --- a/.github/workflows/bump.yml +++ b/.github/workflows/bump.yml @@ -7,7 +7,7 @@ # 4. Opens a pull request with those changes for review. # # After merging the bump PR, the `release` workflow creates a GitHub -# draft release automatically. +# release automatically. # # Authentication: # The default GITHUB_TOKEN cannot trigger CI on new PRs and may be diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 9a044d2..48ec9b5 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,8 +1,8 @@ # Publishes to JSR when a GitHub Release is published. # # Flow: -# bump.yml → merge PR → release.yml creates draft → -# you review & publish the draft → this workflow fires +# bump.yml → merge PR → release.yml publishes release → +# this workflow fires # # Authentication: # Uses GitHub's OIDC token — no JSR secret needed. JSR exchanges the @@ -71,7 +71,7 @@ jobs: - uses: actions/setup-node@v6 with: - node-version: "25" + node-version: "26" registry-url: "https://registry.npmjs.org" - name: Publish to npm diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 6af649d..ec0f305 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,21 +1,20 @@ -# Creates a draft GitHub Release after every push to main. +# Creates a GitHub Release after every push to main. # # What it does: # - Checks whether the current commit's deno.json version is already -# tagged. If not, forge creates a draft release with: +# tagged. If not, forge creates a release with: # • the version from deno.json as the tag (e.g. undent@0.2.0) # • the changelog entries since the last release # • a link to the JSR documentation # - If the version is already released, forge exits cleanly (no-op). # -# You review and publish the draft release in the GitHub UI (or via -# `gh release edit --draft=false`). Publishing it triggers the `publish` -# workflow which pushes to JSR. +# Publishing the release triggers the `publish` workflow, which pushes to +# JSR and npm automatically. # # Authentication: # RELEASE_TOKEN must be a PAT with `contents: write`. The default -# GITHUB_TOKEN works for draft creation but won't trigger downstream -# workflows; a PAT avoids that limitation. +# GITHUB_TOKEN can create the release, but GitHub suppresses downstream +# workflow runs for events it creates; a PAT avoids that limitation. name: Release on: @@ -28,7 +27,7 @@ permissions: jobs: release: - name: Create draft release + name: Create release runs-on: ubuntu-latest steps: - uses: actions/checkout@v6 @@ -48,7 +47,7 @@ jobs: restore-keys: | ${{ runner.os }}-deno- - - name: Create draft release - run: deno task forge release @okikio/undent --draft --emoji + - name: Create release + run: deno task forge release @okikio/undent --emoji env: GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }}