3
0
Fork 0
mirror of https://github.com/Z3Prover/z3 synced 2026-07-22 06:55:51 +00:00
z3/.github/workflows/wasm-release.yml
Copilot 5a03a73685
Allow OTP input for WebAssembly npm publish workflow (#10156)
The `WebAssembly Publish` Actions job failed at `npm publish` with
`EOTP` because the workflow had no path to supply npm one-time passwords
for OTP-protected accounts. This change adds secure OTP input wiring for
manual publish runs while preserving the existing token-based flow.

- **Workflow dispatch input**
- Added optional `workflow_dispatch` input `npm_otp` in
`.github/workflows/wasm-release.yml`.

- **Secure OTP handling**
- Added a dedicated masking step so provided OTP values are redacted in
logs.
- Routed OTP to npm via `NPM_CONFIG_OTP` in the publish step
environment.

- **Publish step behavior**
- Kept publish command as `npm publish`; npm now consumes OTP
automatically when provided through env.

```yaml
on:
  workflow_dispatch:
    inputs:
      npm_otp:
        description: "One-time password for npm publish (optional)"
        required: false
        type: string

# ...

- name: Mask npm OTP
  if: ${{ github.event.inputs.npm_otp != '' }}
  run: echo "::add-mask::${{ github.event.inputs.npm_otp }}"

- name: Publish
  run: npm publish
  env:
    NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
    NPM_CONFIG_OTP: ${{ github.event.inputs.npm_otp }}
```

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-07-17 10:55:05 -07:00

77 lines
1.9 KiB
YAML

name: WebAssembly Publish
on:
workflow_dispatch:
inputs:
npm_otp:
description: "One-time password for npm publish (optional)"
required: false
type: string
release:
types: [published]
defaults:
run:
working-directory: src/api/js
env:
EM_VERSION: 3.1.73
permissions:
contents: read # to fetch code (actions/checkout)
jobs:
publish:
name: Publish
runs-on: ubuntu-latest
environment: release
steps:
- name: Checkout
uses: actions/checkout@v7.0.0
- name: Setup node
uses: actions/setup-node@v7
with:
node-version: "22"
registry-url: "https://registry.npmjs.org"
- name: Prepare for publish
run: |
npm version $(node -e 'console.log(fs.readFileSync("../../../.github/workflows/release.yml", "utf8").match(/RELEASE_VERSION:\s*\x27(\S+)\x27/)[1])')
mv PUBLISHED_README.md README.md
cp ../../../LICENSE.txt .
- name: Setup emscripten
uses: mymindstorm/setup-emsdk@v16
with:
no-install: true
version: ${{env.EM_VERSION}}
actions-cache-folder: "emsdk-cache"
- name: Install dependencies
run: npm ci
- name: Build TypeScript
run: npm run build:ts
- name: Build wasm
run: |
emsdk install ${EM_VERSION}
emsdk activate ${EM_VERSION}
source $(dirname $(which emsdk))/emsdk_env.sh
which node
which clang++
npm run build:wasm
- name: Test
run: npm test
- name: Mask npm OTP
if: ${{ github.event.inputs.npm_otp != '' }}
run: echo "::add-mask::${{ github.event.inputs.npm_otp }}"
- name: Publish
run: npm publish
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
NPM_CONFIG_OTP: ${{ github.event.inputs.npm_otp }}