fix(ci): test triggering ref on PRs, unify token secret, harden JSON parsing

- ci.yml: check out the PR head (or push SHA) instead of always cloning
  main; PR checks now test the actual diff. Drop http.sslVerify=false.
  Publish to the package registry only on push events.
- preview.yml/release.yml: use GITEATOKEN (GITEA_TOKEN is reserved by
  Gitea, so these token steps were silently broken).
- deploy-chrome.yml/release.yml: parse JSON with node instead of
  python3 (not installed in the container) and grep; fail loudly
  instead of swallowing errors with 2>/dev/null.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
john kevin asprec
2026-07-14 21:26:36 +08:00
parent a5608e7b09
commit 57bc3419fa
4 changed files with 20 additions and 12 deletions

View File

@@ -17,13 +17,19 @@ jobs:
- name: Install system deps
run: apt-get update -qq && apt-get install -y zip curl git ca-certificates -qq
- name: Clone repository
- name: Clone repository (triggering ref)
run: |
git config --global http.sslVerify false
git clone --depth 1 --branch main ${{ gitea.server_url }}/${{ gitea.repository }}.git /tmp/lexai
git clone ${{ gitea.server_url }}/${{ gitea.repository }}.git /tmp/lexai
cd /tmp/lexai
if [ "${{ gitea.event_name }}" = "pull_request" ]; then
git fetch origin pull/${{ gitea.event.pull_request.number }}/head:pr
git checkout pr
else
git checkout ${{ gitea.sha }}
fi
- name: Install dependencies
run: npm ci
run: npm ci --prefer-offline --no-audit --no-fund
working-directory: /tmp/lexai
- name: Type check
@@ -53,6 +59,7 @@ jobs:
working-directory: /tmp/lexai
- name: Publish to Gitea Package Registry
if: gitea.event_name == 'push'
run: |
RESPONSE=$(curl -s -w "\n%{http_code}" -X PUT \
"${{ gitea.server_url }}/api/packages/kibin/generic/lexai-extension/${PACKAGE_VERSION}/lexai-chrome-mv3-${PACKAGE_VERSION}.zip" \