Repository navigation
96 lines (81 loc) · 3.22 KB
/
Copy pathpreview.yml
File metadata and controls
96 lines (81 loc) · 3.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
# We use pull_request_target so that pull requests from forks (external
# contributors and bots) also get a deployed preview. This event runs in the
# base repository's context with a write token, which means it executes the
# PR's code (npm ci and build) with that token. We accept this trade-off
# knowingly: maintainers review every pull request from forks and bots before
# and while it runs here, and the token scope is limited to what the preview
# deploy needs. If the risk profile changes, we will move to a manual-approval
# environment gate or a split build-then-deploy flow.
name: PR Preview
on:
pull_request_target:
types: [opened, synchronize, reopened, closed]
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref }}
cancel-in-progress: true
permissions:
contents: write
pull-requests: write
jobs:
build-and-preview:
if: github.event.action == 'opened' || github.event.action == 'synchronize' || github.event.action == 'reopened'
runs-on: ubuntu-latest
steps:
- name: Checkout PR code
uses: actions/checkout@v6
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.sha }}
- name: Set up Node.js
uses: actions/setup-node@v6
with:
node-version: '22'
cache: 'npm'
- name: Install dependencies
run: npm ci
- name: Quality check
run: npm run validate:static
- name: Build for preview
env:
BASE_PATH: /pr-previews/${{ github.event.pull_request.number }}/
run: npm run build
- name: Disable Jekyll
run: touch dist/.nojekyll
- name: Deploy preview to gh-pages
uses: JamesIves/github-pages-deploy-action@v4
with:
branch: gh-pages
folder: dist
target-folder: pr-previews/${{ github.event.pull_request.number }}
clean: true
clean-exclude: |
pr-previews
commit-message: 'Deploy preview for PR ${{ github.event.pull_request.number }}'
- name: Comment with preview URL
uses: thollander/actions-comment-pull-request@v3
with:
message: |
<!-- preview-url-comment -->
Preview deployed for this pull request.
**<https://${{ github.repository_owner }}.github.io/pr-previews/${{ github.event.pull_request.number }}/>**
Latest commit: ${{ github.event.pull_request.head.sha }}
comment-tag: preview-url-comment
cleanup-preview:
if: github.event.action == 'closed'
runs-on: ubuntu-latest
steps:
- name: Checkout gh-pages branch
uses: actions/checkout@v6
with:
ref: gh-pages
- name: Remove PR preview
run: |
if [ -d "pr-previews/${{ github.event.pull_request.number }}" ]; then
git config user.name "github-actions[bot]"
git config user.email "github-actions[bot]@users.noreply.github.com"
git rm -rf "pr-previews/${{ github.event.pull_request.number }}"
git commit -m "Remove preview for PR ${{ github.event.pull_request.number }}"
git push
else
echo "Preview directory not found, skipping."
fi