-
Notifications
You must be signed in to change notification settings - Fork 0
140 lines (136 loc) · 4.89 KB
/
Copy pathrelease.yml
File metadata and controls
140 lines (136 loc) · 4.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
name: Release
on:
push:
tags:
- 'v*'
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
jobs:
release-assets:
name: Build release assets
if: github.event.deleted == false
permissions:
attestations: read
contents: read
id-token: write
uses: ./.github/workflows/go-pre-publish.yml
with:
sign-and-notarize-macos: true
sign-native-packages: true
secrets:
macos-sign-p12: ${{ secrets.MACOS_SIGN_P12 }}
macos-sign-password: ${{ secrets.MACOS_SIGN_PASSWORD }}
macos-notary-key: ${{ secrets.MACOS_NOTARY_KEY }}
macos-notary-key-id: ${{ secrets.MACOS_NOTARY_KEY_ID }}
macos-notary-issuer-id: ${{ secrets.MACOS_NOTARY_ISSUER_ID }}
rpm-signing-key: ${{ secrets.RPM_SIGNING_KEY }}
rpm-signing-passphrase: ${{ secrets.RPM_SIGNING_PASSPHRASE }}
apk-signing-key: ${{ secrets.APK_SIGNING_KEY }}
apk-signing-passphrase: ${{ secrets.APK_SIGNING_PASSPHRASE }}
oci-image:
name: Build OCI image
needs: release-assets
permissions:
actions: read
# The callee installs setup-release-cli, whose installed acquisition path
# runs `gh attestation verify`. A called workflow can never exceed the
# caller's ceiling, so this must be granted here too.
attestations: read
contents: read
uses: ./.github/workflows/go-oci-build.yml
with:
artifact-id: ${{ needs.release-assets.outputs.oci-input-artifact-id }}
artifact-digest: ${{ needs.release-assets.outputs.oci-input-artifact-digest }}
oci-publish:
name: Publish OCI image
needs: oci-image
permissions:
actions: read
artifact-metadata: write
attestations: write
contents: read
id-token: write
packages: write
uses: ./.github/workflows/publish-oci-image.yml
with:
artifact-id: ${{ needs.oci-image.outputs.artifact-id }}
artifact-digest: ${{ needs.oci-image.outputs.artifact-digest }}
image-digest: ${{ needs.oci-image.outputs.image-digest }}
publish-image: true
github-release:
name: Publish GitHub Release
needs:
- release-assets
- oci-image
- oci-publish
permissions:
actions: read
artifact-metadata: write
attestations: write
contents: read
id-token: write
uses: ./.github/workflows/publish-github-release.yml
with:
artifact-id: ${{ needs.release-assets.outputs.artifact-id }}
artifact-digest: ${{ needs.release-assets.outputs.artifact-digest }}
checksum-signing-workflow-ref: ${{ github.repository }}/.github/workflows/go-pre-publish.yml@${{ github.ref }}
require-oci-image: true
oci-image-reference: ${{ needs.oci-publish.outputs.image-reference }}
release-app-client-id: ${{ vars.MEIGMA_RELEASE_APP_CLIENT_ID }}
publish-release: true
secrets:
release-app-private-key: ${{ secrets.MEIGMA_RELEASE_APP_PRIVATE_KEY }}
package-repository-publish:
name: Request package repository publication
needs: github-release
permissions: {}
uses: ./.github/workflows/request-package-repository.yml
with:
package-repository-owner: meigma
package-repository-name: pkgs
release-app-client-id: ${{ vars.MEIGMA_RELEASE_APP_CLIENT_ID }}
publish-package-repository: true
secrets:
release-app-private-key: ${{ secrets.MEIGMA_RELEASE_APP_PRIVATE_KEY }}
homebrew-publish:
name: Open Homebrew tap pull request
needs:
- release-assets
- github-release
permissions:
actions: read
attestations: read
contents: read
uses: ./.github/workflows/publish-homebrew.yml
with:
artifact-id: ${{ needs.release-assets.outputs.artifact-id }}
artifact-digest: ${{ needs.release-assets.outputs.artifact-digest }}
checksum-signing-workflow-ref: ${{ github.repository }}/.github/workflows/go-pre-publish.yml@${{ github.ref }}
tap: meigma/homebrew-tap
cask: meigma-release-cli
release-app-client-id: ${{ vars.MEIGMA_RELEASE_APP_CLIENT_ID }}
publish-homebrew: true
secrets:
release-app-private-key: ${{ secrets.MEIGMA_RELEASE_APP_PRIVATE_KEY }}
scoop-publish:
name: Open Scoop bucket pull request
needs:
- release-assets
- github-release
permissions:
actions: read
attestations: read
contents: read
uses: ./.github/workflows/publish-scoop.yml
with:
artifact-id: ${{ needs.release-assets.outputs.artifact-id }}
artifact-digest: ${{ needs.release-assets.outputs.artifact-digest }}
checksum-signing-workflow-ref: ${{ github.repository }}/.github/workflows/go-pre-publish.yml@${{ github.ref }}
bucket: meigma/scoop-bucket
manifest: meigma-release-cli
release-app-client-id: ${{ vars.MEIGMA_RELEASE_APP_CLIENT_ID }}
publish-scoop: true
secrets:
release-app-private-key: ${{ secrets.MEIGMA_RELEASE_APP_PRIVATE_KEY }}