STAT-133: Add NPM_TOKEN support to node and test/npm actions for private registry auth

npm ci fails with E401 when a consuming repo's package-lock.json pins a
package to the private Gitea npm registry, since these composite actions
never write an .npmrc or set a registry auth token. Add an optional
NPM_TOKEN input that writes .npmrc before install; existing consumers that
don't pass it are unaffected.
This commit is contained in:
2026-09-17 11:48:24 -04:00
parent 3f7c00f1e7
commit 9df18983c3
4 changed files with 37 additions and 0 deletions
+1
View File
@@ -19,6 +19,7 @@ Install dependencies, build, and upload a build artifact
| `COPY_PRISMA_ENGINE` | <p>Copy the Prisma query engine binaries into the build directory</p> | `false` | `false` |
| `WORKING_DIRECTORY` | <p>Working directory for install, build, and artifact steps</p> | `false` | `.` |
| `UPLOAD_ARTIFACT` | <p>Whether to upload the build artifact</p> | `false` | `true` |
| `NPM_TOKEN` | <p>Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages.</p> | `false` | `""` |
<!-- action-docs-inputs source="action.yml" -->
<!-- action-docs-runs source="action.yml" -->
+13
View File
@@ -25,6 +25,9 @@ inputs:
UPLOAD_ARTIFACT:
description: "Whether to upload the build artifact"
default: "true"
NPM_TOKEN:
description: "Auth token for the private Gitea npm registry (@stat-tackler scope). Leave empty if the repo installs no private packages."
default: ""
runs:
using: composite
@@ -36,6 +39,16 @@ runs:
with:
node-version-file: ${{ inputs.WORKING_DIRECTORY }}/package.json
- name: Configure private registry auth
if: inputs.NPM_TOKEN != ''
shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }}
run: |
printf '%s\n%s\n' \
'@stat-tackler:registry=https://gitea.pixelparasol.com/api/packages/stat-tackler/npm/' \
'//gitea.pixelparasol.com/api/packages/stat-tackler/npm/:_authToken=${{ inputs.NPM_TOKEN }}' \
>> .npmrc
- name: Install
shell: sh
working-directory: ${{ inputs.WORKING_DIRECTORY }}