-
Notifications
You must be signed in to change notification settings - Fork 0
88 lines (84 loc) · 2.79 KB
/
Copy pathrelease.yml
File metadata and controls
88 lines (84 loc) · 2.79 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
name: Release
on:
push:
tags:
- 'v*'
permissions:
contents: write
jobs:
build:
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
target: x86_64-unknown-linux-gnu
artifact: rynixc-linux-x86_64
- os: windows-latest
target: x86_64-pc-windows-msvc
artifact: rynixc-windows-x86_64.exe
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- name: Build rynixc (release)
run: cargo build -p rynixc --release
- name: Stage binary
shell: bash
run: |
mkdir -p dist
if [ "${{ runner.os }}" = "Windows" ]; then
cp target/release/rynixc.exe "dist/${{ matrix.artifact }}"
else
cp target/release/rynixc "dist/${{ matrix.artifact }}"
fi
- name: SHA256 checksum
shell: bash
run: |
cd dist
if command -v sha256sum >/dev/null 2>&1; then
sha256sum "${{ matrix.artifact }}" > "${{ matrix.artifact }}.sha256"
elif command -v shasum >/dev/null 2>&1; then
shasum -a 256 "${{ matrix.artifact }}" > "${{ matrix.artifact }}.sha256"
else
openssl dgst -sha256 "${{ matrix.artifact }}" | sed 's/.*= //' > "${{ matrix.artifact }}.sha256"
fi
- uses: actions/upload-artifact@v4
with:
name: ${{ matrix.artifact }}
path: dist/*
release:
needs: build
runs-on: ubuntu-latest
steps:
- uses: actions/download-artifact@v4
with:
path: artifacts
merge-multiple: true
- name: Combined SHA256SUMS
run: |
cd artifacts
sha256sum rynixc-linux-* rynixc-windows-* 2>/dev/null | grep -v '\.sha256$' > SHA256SUMS.txt || true
if [ ! -s SHA256SUMS.txt ]; then
find . -maxdepth 1 -type f ! -name '*.sha256' ! -name 'SHA256SUMS.txt' -exec sha256sum {} + > SHA256SUMS.txt
fi
cat SHA256SUMS.txt
- name: Optional GPG detach-sign SHA256SUMS
working-directory: artifacts
env:
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: |
if [ -z "$GPG_PRIVATE_KEY" ]; then
echo "No GPG_PRIVATE_KEY secret — shipping SHA256SUMS only"
exit 0
fi
echo "$GPG_PRIVATE_KEY" | gpg --batch --import
echo "$GPG_PASSPHRASE" | gpg --batch --yes --pinentry-mode loopback --passphrase-fd 0 \
--detach-sign --armor SHA256SUMS.txt
ls -la SHA256SUMS.txt*
- uses: softprops/action-gh-release@v2
with:
files: |
artifacts/*
generate_release_notes: true