-
Notifications
You must be signed in to change notification settings - Fork 1
86 lines (86 loc) · 2.81 KB
/
Copy pathgithub_release.yml
File metadata and controls
86 lines (86 loc) · 2.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
---
name: Publish GitHub Release
on:
workflow_run:
workflows: [Build]
types: [completed]
jobs:
github-release:
name: Sign the Python distribution with Sigstore and upload them to GitHub Release
Sign the Python distribution with Sigstore and upload them to GitHub Release
runs-on: ubuntu-latest
permissions:
contents: write # IMPORTANT: mandatory for making GitHub Releases
id-token: write # IMPORTANT: mandatory for sigstore
steps:
- name: Download all the dists
uses: actions/download-artifact@v4
with:
name: python-package-distributions
path: dist/
- name: Sign the dists with Sigstore
uses: sigstore/gh-action-sigstore-python@v3.0.0
with:
inputs: >-
./dist/*.tar.gz
./dist/*.whl
- name: Create GitHub Release
env:
GITHUB_TOKEN: ${{ github.token }}
run: >-
gh release create
'${{ github.ref_name }}'
--repo '${{ github.repository }}'
--notes ""
- name: Upload artifact signatures to GitHub Release
env:
GITHUB_TOKEN: ${{ github.token }}
# Upload to GitHub Release using the `gh` CLI.
# `dist/` contains the built packages, and the
# sigstore-produced signatures and certificates.
run: >-
gh release upload
'${{ github.ref_name }}' dist/**
--repo '${{ github.repository }}'
# ---
# name: Publish GitHub Release
# on:
# workflow_run:
# workflows: [Build]
# types: [completed]
# jobs:
# github-release:
# name: Sign the Python distribution with Sigstore and upload them to GitHub Release
# runs-on: ubuntu-latest
# permissions:
# contents: write
# id-token: write
# steps:
# - name: Download all the dists
# uses: actions/download-artifact@v4
# with:
# name: python-package-distributions
# path: dist/
# - name: Sign the dists with Sigstore
# uses: sigstore/gh-action-sigstore-python@v1.2.3
# with:
# inputs: >-
# ./dist/*.tar.gz
# ./dist/*.whl
# - name: Get Tag from Commit
# id: get_tag
# run: |
# echo "tag_name=$(git describe --tags --abbrev=0)" >> $GITHUB_OUTPUT
# - name: Create GitHub Release
# env:
# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# run: |
# gh release create "${{ steps.get_tag.outputs.tag_name }}" \
# --repo "${{ github.repository }}" \
# --notes ""
# - name: Upload artifact signatures to GitHub Release
# env:
# GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# run: |-
# gh release upload "${{ steps.get_tag.outputs.tag_name }}" dist/** \
# --repo "${{ github.repository }}"