fix(api): surface server error messages instead of a bare `✖ HTTP 400… #8
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| tags: | |
| - 'v*' | |
| permissions: | |
| contents: write # needed for gh release create | |
| jobs: | |
| build: | |
| name: Build cross-platform binaries | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: latest | |
| - name: Install dependencies | |
| run: bun install --frozen-lockfile | |
| - name: Codegen | |
| run: bun run codegen | |
| - name: Test | |
| run: bun test | |
| - name: Typecheck | |
| run: bun run typecheck | |
| - name: Build cross-platform binaries | |
| run: | | |
| mkdir -p binaries | |
| bun build src/bin/mna.ts --compile --target=bun-darwin-arm64 --outfile=binaries/mna-darwin-arm64 | |
| bun build src/bin/mna.ts --compile --target=bun-darwin-x64 --outfile=binaries/mna-darwin-x64 | |
| bun build src/bin/mna.ts --compile --target=bun-linux-x64 --outfile=binaries/mna-linux-x64 | |
| - name: Package binaries | |
| run: | | |
| cd binaries | |
| for f in mna-*; do | |
| tar -czf "${f}.tar.gz" "$f" | |
| shasum -a 256 "${f}.tar.gz" > "${f}.tar.gz.sha256" | |
| done | |
| ls -la | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| files: | | |
| binaries/*.tar.gz | |
| binaries/*.sha256 | |
| generate_release_notes: true | |
| publish-npm: | |
| name: Publish to npm | |
| runs-on: ubuntu-latest | |
| needs: build | |
| timeout-minutes: 10 | |
| permissions: | |
| contents: read | |
| # OIDC token for npm Trusted Publishing — no NPM_TOKEN/OTP needed once | |
| # the trusted publisher is configured on npmjs.com for this repo+workflow. | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: latest | |
| - name: Setup Node | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: '24' | |
| registry-url: 'https://registry.npmjs.org' | |
| - name: Install dependencies | |
| run: bun install --frozen-lockfile | |
| - name: Codegen | |
| run: bun run codegen | |
| - name: Build npm bundle | |
| run: bun run build | |
| # Trusted Publishing (OIDC) needs npm >= 11.5; runners ship an older npm. | |
| - name: Upgrade npm for OIDC support | |
| run: npm install -g npm@latest | |
| # Scoped packages are private by default — --access public is required | |
| # (belt-and-braces alongside publishConfig.access in package.json). | |
| # Auth: npm Trusted Publishing via GitHub OIDC (no token). NPM_TOKEN is | |
| # kept as a fallback until the trusted publisher is confirmed working. | |
| - name: Publish to npm | |
| run: npm publish --access public | |
| env: | |
| NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} |