# Copyright 2026 yu-iskw
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#      https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.

name: Publish skill-inspector

on:
  release:
    types: [published]
  workflow_dispatch:

concurrency:
  group: publish-skill-inspector
  cancel-in-progress: false

permissions:
  contents: read
  id-token: write

jobs:
  publish:
    name: Publish to npm
    runs-on: ubuntu-latest
    permissions:
      contents: read
      id-token: write
    defaults:
      run:
        shell: bash
    steps:
      - name: Checkout
        uses: actions/checkout@v6
      - uses: step-security/harden-runner@6c439dc8bdf85cadbbce9ed30d1c7b959517bc49 # v2.10.3
        with:
          egress-policy: audit
      - name: Setup Node.js
        uses: actions/setup-node@v6
        with:
          node-version-file: .node-version
          registry-url: https://registry.npmjs.org
          scope: "@yu-iskw"
      - name: Setup pnpm
        uses: pnpm/action-setup@v4
      - name: Install dependencies
        run: |
          pnpm install --frozen-lockfile
      - name: Build package
        run: |
          pnpm build
      - name: Run tests
        run: |
          pnpm test
      - name: Publish to npm
        env:
          NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
        run: |
          pnpm publish --no-git-checks --access public
