name: Publish # Stages the package on npm via trusted publishing (OIDC, no token). # The maintainer then approves it with `npm stage approve ` (2FA). on: push: tags: ['v*'] permissions: contents: read id-token: write jobs: stage: runs-on: ubuntu-latest environment: npm steps: - uses: actions/checkout@v5 - uses: actions/setup-node@v5 with: node-version: 24 cache: npm registry-url: https://registry.npmjs.org - run: npm install --global npm@latest - name: Check tag matches package.json run: | version="$(node -p "require('./package.json').version")" if [ "v$version" != "$GITHUB_REF_NAME" ]; then echo "::error::Tag $GITHUB_REF_NAME does not match package.json version $version" exit 1 fi - run: npm ci - run: npm test - run: npm stage publish