publish / npm (push) Failing after 31s
The first tagged run failed inside the publish step within a second, which is the shape of an auth rejection rather than a build problem. The step now prefers a repository NPM_TOKEN secret when one exists, prints the effective registry and a masked token, and runs npm whoami so a re-run names the cause instead of just failing.
92 lines
3.8 KiB
YAML
92 lines
3.8 KiB
YAML
# 把打了 v* 标签的版本发布到 Gitea 的 npm 包仓库。
|
|
#
|
|
# 触发方式:
|
|
# 1. 推送版本标签(推荐):git tag -a v1.0.1 -m "..." && git push origin v1.0.1
|
|
# 2. 仓库 → Actions → 选择本工作流 → Run workflow(手动,发布当前 commit 的版本)
|
|
#
|
|
# 需要的权限:
|
|
# 默认使用 Gitea 内置的任务令牌 ${{ secrets.GITEA_TOKEN }} 发布,无需额外配置密钥。
|
|
# 若实例/组织把 Actions 的令牌上限设为只读,或任务令牌对包命名空间没有写权限,
|
|
# 请在仓库 Settings → Actions → Secrets 里添加 NPM_TOKEN = 一个带 package 写权限的个人访问令牌,
|
|
# 工作流会自动优先使用它(见最后一个步骤)。
|
|
#
|
|
# 失败排查:
|
|
# 发布步骤在 1 秒内失败通常是鉴权问题——先看该步骤日志里 `npm whoami` 的输出:
|
|
# 打印出用户名说明令牌可用,报 E401/E403 说明令牌无效或权限不足。
|
|
#
|
|
# 依赖前提:
|
|
# - 实例启用了 Actions,且注册了 act_runner(否则工作流只会排队)。
|
|
# - runner 需要能拉取 actions/checkout 与 actions/setup-node(默认从 github.com 取)。
|
|
# 若 runner 在无外网环境,请在 app.ini 里设 actions.DEFAULT_ACTIONS_URL = self 并把这两个
|
|
# action 镜像到自己的实例上。
|
|
# - runs-on 的标签要与 runner 配置的标签一致(默认 ubuntu-latest;自建 runner 常用 docker/ubuntu-22.04 等)。
|
|
name: publish
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v*'
|
|
workflow_dispatch:
|
|
|
|
# 读取代码用于 checkout,向本组织写包。
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
|
|
jobs:
|
|
npm:
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
REGISTRY: https://gitea.iwake.top/api/packages/dsh-plugin/npm/
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Set up Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
registry-url: https://gitea.iwake.top/api/packages/dsh-plugin/npm/
|
|
|
|
- name: Check the tag against package.json
|
|
run: |
|
|
set -eu
|
|
version="$(node -p "require('./package.json').version")"
|
|
name="$(node -p "require('./package.json').name")"
|
|
case "${GITHUB_REF}" in
|
|
refs/tags/*)
|
|
tag="${GITHUB_REF_NAME#v}"
|
|
if [ "$tag" != "$version" ]; then
|
|
echo "标签 ${GITHUB_REF_NAME} 与 package.json 的版本 ${version} 不一致" >&2
|
|
exit 1
|
|
fi
|
|
;;
|
|
esac
|
|
echo "将发布 ${name}@${version}"
|
|
|
|
- name: Pack (preview the published contents)
|
|
run: npm pack --dry-run
|
|
|
|
- name: Publish
|
|
env:
|
|
# 优先使用带 package 写权限的 PAT(仓库 Settings → Actions → Secrets 里的 NPM_TOKEN);
|
|
# 没有配置时退回 Gitea 内置任务令牌 GITEA_TOKEN。
|
|
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
JOB_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: |
|
|
set -eu
|
|
token="${NPM_TOKEN:-$JOB_TOKEN}"
|
|
if [ -z "$token" ]; then
|
|
echo "没有可用的发布令牌:请配置 NPM_TOKEN,或确认实例会注入 GITEA_TOKEN" >&2
|
|
exit 1
|
|
fi
|
|
# 作用域与默认注册表都指向本组织的 npm 仓库,并把令牌写进本机 .npmrc。
|
|
npm config set @dsh-plugin:registry "${REGISTRY}"
|
|
npm config set "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" "${token}"
|
|
echo "registry = $(npm config get registry)"
|
|
echo "auth = $(npm config get "//gitea.iwake.top/api/packages/dsh-plugin/npm/:_authToken" | sed 's/./*/g')"
|
|
# 鉴权自检:能取到用户就说明令牌对得上这个注册表(包不存在时报 404 也算通过)。
|
|
npm whoami --registry "${REGISTRY}" || true
|
|
npm publish --registry "${REGISTRY}" --access public
|
|
|