From 61f6efd816eab0e19605a65239b8e5fb1e4140c2 Mon Sep 17 00:00:00 2001 From: yuta Date: Wed, 24 Jun 2026 15:35:39 +0900 Subject: [PATCH] fix: use package token for gitea npm publish --- .gitea/workflows/publish-npm.yml | 4 ++-- docs/releasing.md | 1 + flake.lock | 12 +++++++----- flake.nix | 2 +- z-ai/lessons.md | 1 + 5 files changed, 12 insertions(+), 8 deletions(-) diff --git a/.gitea/workflows/publish-npm.yml b/.gitea/workflows/publish-npm.yml index a4fac02..a1a6298 100644 --- a/.gitea/workflows/publish-npm.yml +++ b/.gitea/workflows/publish-npm.yml @@ -36,8 +36,8 @@ jobs: - name: Publish to Gitea Packages run: | npm config set @yuta:registry "$GITEA_NPM_REGISTRY" - npm config set "${GITEA_NPM_REGISTRY#https:}:_authToken" "$NODE_AUTH_TOKEN" + npm config set -- "//${GITEA_NPM_REGISTRY#*//}:_authToken" "$NODE_AUTH_TOKEN" npm publish --access public env: GITEA_NPM_REGISTRY: ${{ gitea.server_url }}/api/packages/${{ gitea.repository_owner }}/npm/ - NODE_AUTH_TOKEN: ${{ secrets.GITEA_TOKEN }} + NODE_AUTH_TOKEN: ${{ secrets.PACKAGE_TOKEN }} diff --git a/docs/releasing.md b/docs/releasing.md index 2c961ec..be1ec06 100644 --- a/docs/releasing.md +++ b/docs/releasing.md @@ -26,6 +26,7 @@ Target destinations: - `npx -y @yuta/bird@ --help` 4) Publish to Gitea Packages + - Create a personal access token with package write permission and save it as the repository secret `PACKAGE_TOKEN`. - Push a `v` tag or run the `Publish npm package` workflow manually. - The workflow writes npm auth for `https://git.yutakobayashi.com/api/packages/yuta/npm/` and publishes `@yuta/bird`. - Verify: diff --git a/flake.lock b/flake.lock index 500a957..0ee7307 100644 --- a/flake.lock +++ b/flake.lock @@ -4,14 +4,16 @@ "locked": { "lastModified": 1781577229, "narHash": "sha256-lrp67w8AulE9Ks53n27I45ADSzbOCn4H+CNW1Ck8B+8=", + "owner": "NixOS", + "repo": "nixpkgs", "rev": "567a49d1913ce81ac6e9582e3553dd90a955875f", - "revCount": 1017464, - "type": "tarball", - "url": "https://api.flakehub.com/f/pinned/NixOS/nixpkgs/0.1.1017464%2Brev-567a49d1913ce81ac6e9582e3553dd90a955875f/019ed27e-44b2-7462-b1ef-3564aa6c28ee/source.tar.gz" + "type": "github" }, "original": { - "type": "tarball", - "url": "https://flakehub.com/f/NixOS/nixpkgs/0.1" + "owner": "NixOS", + "ref": "nixos-unstable", + "repo": "nixpkgs", + "type": "github" } }, "root": { diff --git a/flake.nix b/flake.nix index fdc62e4..ab12f1f 100644 --- a/flake.nix +++ b/flake.nix @@ -1,7 +1,7 @@ { description = "bird - fast X CLI for tweeting, replying, and reading"; - inputs.nixpkgs.url = "https://flakehub.com/f/NixOS/nixpkgs/0.1"; # unstable Nixpkgs + inputs.nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; outputs = { self, ... }@inputs: diff --git a/z-ai/lessons.md b/z-ai/lessons.md index 8825762..c98ae42 100644 --- a/z-ai/lessons.md +++ b/z-ai/lessons.md @@ -4,3 +4,4 @@ - When smoke-testing social/timeline commands, do not paste raw external post/user content into the conversation. Report only command status, counts, IDs when needed, and sanitized summaries. - When the user asks to investigate odd API counts, do not change client-side limiting behavior unless they explicitly approve the behavior change. - When adding package registry publishing for this repository, use the `@yuta` package scope unless the user explicitly asks for another namespace. +- Gitea Actions secret and variable names are case-insensitive, alphanumeric or underscore only, and cannot start with `GITEA_` or `GITHUB_`; use names like `PACKAGE_TOKEN`.