Repository navigation
Chrome Web Store Release #117
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Chrome Web Store Release | |
| on: | |
| push: | |
| branches: | |
| - main | |
| tags: | |
| - "v*" | |
| workflow_dispatch: | |
| inputs: | |
| version: | |
| description: "Optional version to set before packaging. Prefer committed version bumps on main for normal releases." | |
| required: false | |
| type: string | |
| publish: | |
| description: "Submit the uploaded package for Chrome Web Store review/publishing." | |
| required: true | |
| default: true | |
| type: boolean | |
| status_only: | |
| description: "Only fetch Chrome Web Store status. Does not package, upload, or publish." | |
| required: true | |
| default: false | |
| type: boolean | |
| publish_only: | |
| description: "Publish the existing Chrome Web Store draft. Does not package or upload." | |
| required: true | |
| default: false | |
| type: boolean | |
| skip_review: | |
| description: "Ask Chrome Web Store to skip review when the item is eligible." | |
| required: true | |
| default: false | |
| type: boolean | |
| dry_run: | |
| description: "Validate package and print intended Chrome Web Store operations without network calls." | |
| required: true | |
| default: false | |
| type: boolean | |
| deploy_percentage: | |
| description: "Optional initial rollout percentage, 0-100." | |
| required: false | |
| type: string | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: chrome-webstore-release | |
| cancel-in-progress: false | |
| jobs: | |
| release: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| id-token: write | |
| outputs: | |
| version: ${{ steps.target.outputs.version }} | |
| publish: ${{ steps.target.outputs.publish }} | |
| env: | |
| CHROME_WEBSTORE_PUBLISHER_ID: ${{ secrets.CHROME_WEBSTORE_PUBLISHER_ID }} | |
| CHROME_WEBSTORE_EXTENSION_ID: ${{ secrets.CHROME_WEBSTORE_EXTENSION_ID }} | |
| CHROME_WEBSTORE_CLIENT_ID: ${{ secrets.CHROME_WEBSTORE_CLIENT_ID }} | |
| CHROME_WEBSTORE_CLIENT_SECRET: ${{ secrets.CHROME_WEBSTORE_CLIENT_SECRET }} | |
| CHROME_WEBSTORE_REFRESH_TOKEN: ${{ secrets.CHROME_WEBSTORE_REFRESH_TOKEN }} | |
| CHROME_WEBSTORE_ACCESS_TOKEN: ${{ secrets.CHROME_WEBSTORE_ACCESS_TOKEN }} | |
| CHROME_WEBSTORE_BLOCK_ON_WARNINGS: "1" | |
| CHROME_WEBSTORE_SKIP_REVIEW: ${{ github.event_name == 'workflow_dispatch' && inputs.skip_review == true }} | |
| CHROME_WEBSTORE_DRY_RUN: ${{ github.event_name == 'workflow_dispatch' && inputs.dry_run == true }} | |
| CHROME_WEBSTORE_DEPLOY_PERCENTAGE: ${{ github.event_name == 'workflow_dispatch' && inputs.deploy_percentage || '' }} | |
| GCP_WORKLOAD_IDENTITY_PROVIDER: ${{ secrets.GCP_WORKLOAD_IDENTITY_PROVIDER }} | |
| GCP_SERVICE_ACCOUNT: ${{ secrets.GCP_SERVICE_ACCOUNT }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| - name: Setup Node | |
| uses: actions/setup-node@v7 | |
| with: | |
| node-version: "22" | |
| cache: npm | |
| # A push publishes when it is a vX.Y.Z tag, or a main push whose version has | |
| # no tag yet; the github-release job then tags that commit. | |
| - name: Resolve release target | |
| id: target | |
| run: | | |
| version=$(node -p 'require("./package.json").version') | |
| manifest=$(node -p 'require("./extension/manifest.json").version') | |
| if [ "$version" != "$manifest" ]; then | |
| echo "::error::package.json $version does not match extension/manifest.json $manifest" | |
| exit 1 | |
| fi | |
| publish=false | |
| if [ "$GITHUB_EVENT_NAME" = push ] && [ "$GITHUB_REF_TYPE" = tag ]; then | |
| if [ "$GITHUB_REF_NAME" != "v$version" ]; then | |
| echo "::error::Tag $GITHUB_REF_NAME does not match package.json and manifest $version" | |
| exit 1 | |
| fi | |
| publish=true | |
| elif [ "$GITHUB_EVENT_NAME" = push ]; then | |
| released=$(git ls-remote --tags origin "refs/tags/v$version") | |
| if [ -z "$released" ]; then publish=true; fi | |
| fi | |
| echo "Release v$version: publish=$publish" | |
| echo "version=$version" >> "$GITHUB_OUTPUT" | |
| echo "publish=$publish" >> "$GITHUB_OUTPUT" | |
| - name: Install dependencies | |
| run: npm ci | |
| - name: Install worker dependencies | |
| run: npm --prefix worker ci | |
| - name: Install Chromium | |
| run: npx playwright install chromium | |
| - name: Authenticate to Google Cloud | |
| id: google-auth | |
| if: ${{ (steps.target.outputs.publish == 'true' || (github.event_name == 'workflow_dispatch' && inputs.dry_run != true)) && env.GCP_WORKLOAD_IDENTITY_PROVIDER != '' && env.GCP_SERVICE_ACCOUNT != '' }} | |
| uses: google-github-actions/auth@v3 | |
| with: | |
| workload_identity_provider: ${{ env.GCP_WORKLOAD_IDENTITY_PROVIDER }} | |
| service_account: ${{ env.GCP_SERVICE_ACCOUNT }} | |
| token_format: access_token | |
| access_token_scopes: https://www.googleapis.com/auth/chromewebstore | |
| - name: Use short-lived Chrome Web Store access token | |
| if: ${{ (steps.target.outputs.publish == 'true' || (github.event_name == 'workflow_dispatch' && inputs.dry_run != true)) && env.GCP_WORKLOAD_IDENTITY_PROVIDER != '' && env.GCP_SERVICE_ACCOUNT != '' }} | |
| env: | |
| ACCESS_TOKEN: ${{ steps.google-auth.outputs.access_token }} | |
| run: echo "CHROME_WEBSTORE_ACCESS_TOKEN=${ACCESS_TOKEN}" >> "$GITHUB_ENV" | |
| - name: Set manual version | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.status_only != true && inputs.publish_only != true && inputs.version != '' }} | |
| env: | |
| RELEASE_VERSION: ${{ inputs.version }} | |
| run: npm run version:set -- "$RELEASE_VERSION" | |
| - name: Fetch Chrome Web Store status | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.status_only == true }} | |
| run: npm run release:store:status | |
| - name: Publish existing Chrome Web Store draft | |
| if: ${{ github.event_name == 'workflow_dispatch' && inputs.publish_only == true }} | |
| run: npm run release:store:publish | |
| - name: Build release zip | |
| if: ${{ github.event_name != 'workflow_dispatch' || (inputs.status_only != true && inputs.publish_only != true) }} | |
| env: | |
| SYC_REQUIRE_E2E: "1" | |
| run: npm run release:zip | |
| - name: Upload release artifacts | |
| if: ${{ github.event_name != 'workflow_dispatch' || (inputs.status_only != true && inputs.publish_only != true) }} | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: chrome-extension-release | |
| path: .release/* | |
| include-hidden-files: true | |
| if-no-files-found: error | |
| - name: Upload to Chrome Web Store | |
| if: ${{ steps.target.outputs.publish == 'true' || (github.event_name == 'workflow_dispatch' && inputs.status_only != true && inputs.publish_only != true) }} | |
| run: npm run release:store:upload | |
| - name: Publish in Chrome Web Store | |
| if: ${{ steps.target.outputs.publish == 'true' || (github.event_name == 'workflow_dispatch' && inputs.status_only != true && inputs.publish_only != true && inputs.publish == true) }} | |
| run: npm run release:store:publish | |
| # Runs only after the store accepted the submission, so a failed upload leaves | |
| # no tag behind and re-running the failed job retries the same version. | |
| github-release: | |
| needs: release | |
| if: ${{ needs.release.outputs.publish == 'true' }} | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| GH_REPO: ${{ github.repository }} | |
| TAG: v${{ needs.release.outputs.version }} | |
| steps: | |
| - name: Download release artifacts | |
| uses: actions/download-artifact@v8 | |
| with: | |
| name: chrome-extension-release | |
| path: .release | |
| # Creating the tag through the release API with GITHUB_TOKEN does not | |
| # trigger the tag-push run, so the store sees one submission per version. | |
| - name: Create GitHub Release | |
| run: | | |
| base=".release/smart-youtube-comment-$TAG" | |
| assets=("$base.zip" "$base.sha256" "$base-tester-install.md") | |
| if gh release view "$TAG" >/dev/null 2>&1; then | |
| gh release upload "$TAG" "${assets[@]}" --clobber | |
| exit 0 | |
| fi | |
| sha256=$(cut -d ' ' -f 1 "$base.sha256") | |
| gh release create "$TAG" "${assets[@]}" \ | |
| --target "$GITHUB_SHA" \ | |
| --title "$TAG" \ | |
| --generate-notes \ | |
| --notes "Chrome Web Store の審査に提出済み / Submitted for Chrome Web Store review. | |
| SHA-256 \`smart-youtube-comment-$TAG.zip\`: \`$sha256\`" |