Repository navigation
89 lines (77 loc) · 3.12 KB
/
Copy pathrelease.yml
File metadata and controls
89 lines (77 loc) · 3.12 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
name: release
# Publishes both packages (CodingAgentRunner + CodingAgentRunner.Rendering) to
# nuget.org when a version tag is pushed (e.g. v0.1.0), then creates a GitHub
# Release for the tag. The version is derived from the tag.
#
# Auth uses nuget.org **Trusted Publishing** (OIDC): there is NO API key to store.
# GitHub Actions mints a short-lived OIDC token; the NuGet/login action exchanges
# it for a temporary key, validated against the Trusted Publishing policy on
# nuget.org (package owner RobertMischke2, repo agent-orc/runner,
# workflow release.yml).
#
# To cut a release: `scripts/release.sh 0.1.0` (or push a `v0.1.0` tag manually).
on:
push:
tags: [ 'v*.*.*' ]
jobs:
publish:
name: pack & publish to nuget.org
runs-on: ubuntu-latest
permissions:
id-token: write # required to request the OIDC token for Trusted Publishing
contents: write # required to create the GitHub Release for the tag
steps:
- uses: actions/checkout@v4
- name: Setup .NET
uses: actions/setup-dotnet@v4
with:
dotnet-version: '10.0.x'
- name: Derive version from tag
id: ver
run: echo "version=${GITHUB_REF_NAME#v}" >> "$GITHUB_OUTPUT"
- name: Restore
run: dotnet restore
- name: Test
run: dotnet test --no-restore -c Release
- name: Pack
run: |
dotnet pack src/CodingAgentRunner/CodingAgentRunner.csproj \
--no-restore -c Release \
-p:Version=${{ steps.ver.outputs.version }} \
-o artifacts
dotnet pack src/CodingAgentRunner.Rendering/CodingAgentRunner.Rendering.csproj \
--no-restore -c Release \
-p:Version=${{ steps.ver.outputs.version }} \
-o artifacts
- name: Authenticate to nuget.org (Trusted Publishing / OIDC)
id: login
uses: NuGet/login@v1
with:
user: RobertMischke2
- name: Push to nuget.org
run: >
dotnet nuget push "artifacts/*.nupkg"
--api-key "${{ steps.login.outputs.NUGET_API_KEY }}"
--source https://api.nuget.org/v3/index.json
--skip-duplicate
# A pushed tag alone does not appear on the GitHub Releases page. Create a
# Release for the tag that points at the published packages on nuget.org
# and carries the .nupkg files as downloadable assets.
- name: Create GitHub Release
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ steps.ver.outputs.version }}
run: |
cat > release-notes.md <<EOF
Published to nuget.org:
- [CodingAgentRunner ${VERSION}](https://www.nuget.org/packages/CodingAgentRunner/${VERSION})
- [CodingAgentRunner.Rendering ${VERSION}](https://www.nuget.org/packages/CodingAgentRunner.Rendering/${VERSION})
\`\`\`
dotnet add package CodingAgentRunner --version ${VERSION}
\`\`\`
EOF
gh release create "${GITHUB_REF_NAME}" artifacts/*.nupkg \
--title "v${VERSION}" \
--notes-file release-notes.md \
--generate-notes \
--verify-tag