t3-code-android-nightly/.repos/alchemy-effect/.github/workflows/pkg.yml
Julius Marminge 6f9cea00ae
chore(refs): sync Effect and Alchemy references to 4.0.1 and beta.80 (#16170)
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-05 13:22:30 -07:00

107 lines
4 KiB
YAML

name: Package Preview
# Builds, packs, and publishes preview packages from the job that built them.
# The job proves it is the run it claims to be by uploading the manifest as
# an artifact of its own run, which only the job's runtime token can do; the
# registry reads the artifact list back through the GitHub API. That works
# the same for pushes, same-repo pull requests, and fork pull requests, and
# needs no permissions or secrets. The upload has to be an action step: the
# runtime token is never exposed to `run:` steps.
on:
push:
branches: [main]
paths:
- "submodules/distilled"
- "packages/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "pnpm-workspace.yaml"
- "turbo.json"
- "tsconfig.json"
- ".github/workflows/pkg.yml"
pull_request:
types: [opened, synchronize, reopened, labeled]
paths:
- "submodules/distilled"
- "packages/**"
- "scripts/**"
- "package.json"
- "pnpm-lock.yaml"
- "pnpm-workspace.yaml"
- "turbo.json"
- "tsconfig.json"
- ".github/workflows/pkg.yml"
permissions:
contents: read
env:
PKG_REGISTRY: https://pkg.alchemy.run
concurrency:
group: pkg-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
publish:
name: Publish preview packages
runs-on: blacksmith-8vcpu-ubuntu-2404
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Pack the pull request head rather than the synthetic merge commit,
# so every tarball is addressed by a commit that exists on the PR.
ref: ${{ github.event.pull_request.head.sha || github.sha }}
fetch-depth: 0
- name: Checkout distilled
run: git submodule update --init --depth=1 --checkout -- submodules/distilled
# No turbo cache here on purpose: the restore keys fall back to any
# earlier run, and replayed outputs for the distilled packages, whose
# sources live in a submodule, have compiled alchemy against stale
# declarations. A clean build is a few minutes and always correct.
- name: Setup pnpm, Node.js, Bun and install dependencies
uses: pnpm/setup@703c52620218391530e48b9e8870d5c0082e1b9b # v2.1.0
with:
cache: true
install: true
require-lockfile: true
# Cold-building the alchemy package peaks near 17 GB of heap, which
# starves the runner agent on a 32 GB machine and drops the job. A soft
# limit holds the peak near 11 GB for roughly twice the compile time.
- name: Build packages
env:
GOMEMLIMIT: 6GiB
GOGC: "40"
run: pnpm build:pkg
# The @distilled.cloud list is alchemy's dependency set, which `build:pkg`
# derives with `--filter=alchemy...`; keep the @alchemy.run list in sync.
- name: Pack packages
id: pack
run: >-
pnpm exec pkg pack
${{ contains(github.event.pull_request.labels.*.name, 'force-ci') && '--all' || '' }}
--rebuild-all-path 'scripts/copy-package-files.ts'
--group 'alchemy=./packages/alchemy'
--group '@alchemy.run[Collapsed]=./packages/{better-auth,cloudflare-runtime,frontend-frameworks,node-utils,floci,pkg}'
--group '@distilled.cloud[Collapsed]=./submodules/distilled/packages/{core,acme,aws,axiom,cloudflare,doppler,fly-io,github,hetzner,infisical,neon,prisma,planetscale,railway,stripe,zerossl}'
- name: Vouch for the manifest
if: steps.pack.outputs.package-count != '0'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ${{ steps.pack.outputs.artifact-name }}
path: .pkg/pkg-manifest.json
include-hidden-files: true
if-no-files-found: error
retention-days: 1
- name: Publish packages
if: steps.pack.outputs.package-count != '0'
run: pnpm exec pkg publish