-
Notifications
You must be signed in to change notification settings - Fork 0
109 lines (95 loc) 路 3.34 KB
/
Copy pathrelease.yml
File metadata and controls
109 lines (95 loc) 路 3.34 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
name: Release
# Push a tag such as v0.2.0 to release. The tag must match the version in pyproject.toml.
on:
push:
tags: ["v*.*.*"]
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
ci:
name: Lint and Test
uses: ./.github/workflows/ci.yml
# The images are built, scanned and pushed before the release is created, so a release
# never exists without its images.
container:
name: Container images
needs: [ci]
uses: ./.github/workflows/container.yml
with:
ref: ${{ github.ref_name }}
permissions:
contents: read
packages: write
id-token: write
attestations: write
security-events: write
release:
name: Publish the GitHub release
runs-on: ubuntu-latest
timeout-minutes: 10
needs: [ci, container]
permissions:
# Creating a release and attaching its files is the only write this workflow makes.
contents: write
steps:
- name: Checkout
uses: actions/checkout@v7
# The files the gate built and tested, not a fresh build.
- name: Fetch the build
uses: actions/download-artifact@v8
with:
name: dist
path: dist/
- name: Check the tag matches the version
env:
TAG: ${{ github.ref_name }}
run: |
version="$(python3 -c 'import tomllib; print(tomllib.load(open("pyproject.toml", "rb"))["project"]["version"])')"
if [ "v${version}" != "${TAG}" ]; then
echo "::error::tag ${TAG} does not match pyproject.toml version ${version}"
exit 1
fi
ls dist/*"${version}"*.whl dist/*"${version}"*.tar.gz
- name: Write checksums
run: cd dist && sha256sum -- * > SHA256SUMS
- name: Create the release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.ref_name }}
run: |
flags=()
# A pre-release (v0.5.1rc1) is marked as one, so it never becomes the latest
# release, which is what the weekly patch run rebuilds and people install.
if [[ ! "${TAG#v}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
flags+=(--prerelease)
fi
gh release create "${TAG}" dist/* --verify-tag --generate-notes --title "${TAG}" "${flags[@]}"
# PyPI, through trusted publishing: PyPI trusts this workflow running in the pypi
# environment, so no token is stored anywhere. It runs last because a version on PyPI
# can never be replaced, and stays off until the repository variable PUBLISH_PYPI is
# "true", since PyPI must know the publisher first (see docs/development.md).
pypi:
name: Publish to PyPI
needs: [release]
if: vars.PUBLISH_PYPI == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10
environment:
name: pypi
url: https://pypi.org/p/libre-devops-helpers
permissions:
# The OIDC token PyPI exchanges for a short-lived upload token, and that signs the
# upload's provenance attestations.
id-token: write
steps:
# The files the gate built and tested, as the GitHub release has them.
- name: Fetch the build
uses: actions/download-artifact@v8
with:
name: dist
path: dist/
- name: Publish
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2