Repository navigation
173 lines (171 loc) · 7.76 KB
/
Copy pathrelease.yml
File metadata and controls
173 lines (171 loc) · 7.76 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
name: Release
# Pushing an annotated tag `vX.Y.Z` on main publishes that version: the CI
# checks run and the binaries build first, then the crate goes to crates.io and
# the tag's message body becomes the notes of a GitHub release that carries the
# binaries, their checksums and build provenance; then the Homebrew formula in
# Tech-Byte-Frontier/homebrew-tap installs it, and the npm launcher
# @tech-byte-frontier/jevgate of the same version is staged on npm, where it
# goes live once the maintainer approves it. Every step can be rerun safely.
on:
push:
tags: ["v*"]
permissions:
contents: read
concurrency:
group: release
cancel-in-progress: false
jobs:
ci:
uses: ./.github/workflows/ci.yml
build:
uses: ./.github/workflows/build.yml
publish:
needs: [ci, build]
runs-on: ubuntu-latest
# crates.io trusts only this workflow in this environment (Trusted Publishing).
environment: crates-io
permissions:
contents: write
id-token: write
attestations: write
env:
TAG: ${{ github.ref_name }}
GH_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Check the tag
run: |
# Checkout can leave a lightweight copy of the tag; fetch the annotated one.
git fetch --force origin "refs/tags/$TAG:refs/tags/$TAG"
version=$(cargo metadata --no-deps --format-version 1 | jq -r '.packages[0].version')
[ "$TAG" = "v$version" ] || { echo "::error::Tag $TAG does not match Cargo.toml version $version"; exit 1; }
[ "$(git cat-file -t "refs/tags/$TAG")" = tag ] || { echo "::error::$TAG must be an annotated tag"; exit 1; }
git merge-base --is-ancestor "$GITHUB_SHA" origin/main || { echo "::error::$TAG is not on main"; exit 1; }
git tag -l --format='%(contents:body)' "$TAG" > "$RUNNER_TEMP/notes.md"
grep -q '[^[:space:]]' "$RUNNER_TEMP/notes.md" || { echo "::error::$TAG has no release notes in its message body"; exit 1; }
grep -q "^## \[$version\]" CHANGELOG.md || { echo "::error::CHANGELOG.md has no section for $version"; exit 1; }
echo "VERSION=$version" >> "$GITHUB_ENV"
- name: Check crates.io
run: |
status=$(curl -s -o /dev/null -w '%{http_code}' -A "jevgate-release (${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY})" \
"https://crates.io/api/v1/crates/jevgate/$VERSION")
case "$status" in
200) echo "PUBLISHED=true" >> "$GITHUB_ENV" ;;
404) echo "PUBLISHED=false" >> "$GITHUB_ENV" ;;
*) echo "::error::crates.io answered $status"; exit 1 ;;
esac
- name: Install Rust
if: env.PUBLISHED == 'false'
run: rustup toolchain install stable --profile minimal
- uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18 # v1.0.5
if: env.PUBLISHED == 'false'
id: auth
- name: Publish to crates.io
if: env.PUBLISHED == 'false'
run: cargo +stable publish --locked
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: dist-*
path: dist
merge-multiple: true
- name: Collect the checksums
run: cat dist/*.sha256 > dist/SHA256SUMS
- uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-path: |
dist/*.tar.gz
dist/*.zip
- name: Create the GitHub release
run: |
if gh release view "$TAG" > /dev/null 2>&1; then
# A rerun attaches only the archives a failed run left out.
present=$(gh release view "$TAG" --json assets -q '.assets[].name')
for file in dist/*; do
grep -qxF "$(basename "$file")" <<< "$present" || gh release upload "$TAG" "$file"
done
exit 0
fi
cat - "$RUNNER_TEMP/notes.md" > "$RUNNER_TEMP/release.md" <<EOF
\`\`\`sh
curl -fsSL https://raw.githubusercontent.com/$GITHUB_REPOSITORY/$TAG/install.sh | sh
cargo binstall jevgate # or: cargo install jevgate --locked
\`\`\`
Verify a download with \`gh attestation verify <archive> --repo $GITHUB_REPOSITORY\`.
EOF
gh release create "$TAG" dist/* --verify-tag --latest --title "JevGate $VERSION" --notes-file "$RUNNER_TEMP/release.md"
homebrew:
needs: publish
runs-on: ubuntu-latest
env:
TAG: ${{ github.ref_name }}
GH_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# The deploy key can write only to the tap.
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: Tech-Byte-Frontier/homebrew-tap
ssh-key: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY }}
path: homebrew-tap
- name: Update the Homebrew formula
run: |
gh release download "$TAG" --pattern SHA256SUMS --dir "$RUNNER_TEMP"
.github/homebrew-formula.sh "${TAG#v}" "$RUNNER_TEMP/SHA256SUMS" > homebrew-tap/Formula/jevgate.rb
cd homebrew-tap
if git diff --quiet; then
echo "The formula already installs $TAG"
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git commit -qam "jevgate ${TAG#v}"
git push
npm:
needs: publish
runs-on: ubuntu-latest
# npm trusts only this workflow in this environment (trusted publishing), and
# only to stage a version: it goes live when the maintainer approves it on
# npmjs.com with their second factor, so this job alone cannot publish.
environment: npm
permissions:
contents: read
id-token: write
env:
TAG: ${{ github.ref_name }}
GH_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# No package cache: nothing restored runs next to the publish token.
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 24
registry-url: https://registry.npmjs.org
package-manager-cache: false
# Staged publishing needs npm 11.15.0 or later: install a known one rather
# than take the one Node brings.
- name: Install npm
run: npm install --global npm@11.20.0
- name: Stage the npm launcher
run: |
npm_version=$(npm --version)
[ "$(printf '%s\n' 11.15.0 "$npm_version" | sort -V | head -n 1)" = 11.15.0 ] || { echo "::error::npm $npm_version is older than 11.15.0, which staged publishing needs"; exit 1; }
name=$(jq -r .name npm/package.json)
version=$(jq -r .version npm/package.json)
[ "$TAG" = "v$version" ] || { echo "::error::Tag $TAG does not match npm/package.json version $version"; exit 1; }
if [ -n "$(npm view "$name@$version" version 2>/dev/null)" ]; then
echo "npm already has $name $version"
exit 0
fi
# The package ships the release's checksums, which tie it to these binaries.
# A version already staged and not yet approved stops a rerun here.
gh release download "$TAG" --pattern SHA256SUMS --dir npm
npm stage publish ./npm --access public --provenance
echo "::notice::$name $version is staged: approve it on npmjs.com (the package's Staged Packages) to publish it"