diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index c1b929e..c33c664 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,15 +1,32 @@ name: publish +# Publish an existing release tag to the Bend hub as emerging-ezimg@X.Y.Z.0 by hand, +# e.g. to retry a release whose automatic publish failed. Releases are +# published automatically by release-please.yml. dry-run runs every check +# (proof gate, LICENSE, the hub's name check) and stops before the upload. + on: workflow_dispatch: inputs: tag: - description: "Existing tag to publish, e.g. v0.4.0" + description: "The existing tag to publish, e.g. v1.2.0" required: true type: string + dry-run: + description: "Check everything, upload nothing" + required: false + type: boolean + default: false + +permissions: + contents: read jobs: publish: - uses: Emerging-Patterns/actions/.github/workflows/publish.yml@main + uses: Emerging-Patterns/actions/.github/workflows/publish.yml@0fb03f81b72096c8db54be388d09ef5ab75fed3f with: tag: ${{ inputs.tag }} + hub-name: emerging-ezimg + dry-run: ${{ inputs.dry-run }} + secrets: + bend-key: ${{ secrets.BEND_HUB_KEY }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index e50ba7f..4662519 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -1,5 +1,12 @@ name: release-please +# release-please opens the release PR from conventional commits; merging it +# tags vX.Y.Z and creates the GitHub release. The publish job then sends that +# tag to the Bend hub as emerging-ezimg@X.Y.Z.0: the shared publish workflow runs the +# proof gate and refuses a package with no LICENSE beside its entry before it +# uploads, since an upload is public and permanent. BEND_HUB_KEY is the Bender +# login of the account that owns the hub name. + on: push: branches: [main] @@ -11,7 +18,23 @@ permissions: jobs: release-please: - uses: Emerging-Patterns/actions/.github/workflows/release-please.yml@main + permissions: + contents: write + pull-requests: write + issues: write + uses: Emerging-Patterns/actions/.github/workflows/release-please.yml@0fb03f81b72096c8db54be388d09ef5ab75fed3f with: config-file: .github/release-please-config.json manifest-file: .github/release-please-manifest.json + + publish: + needs: release-please + if: needs.release-please.outputs.release_created == 'true' + permissions: + contents: read + uses: Emerging-Patterns/actions/.github/workflows/publish.yml@0fb03f81b72096c8db54be388d09ef5ab75fed3f + with: + tag: ${{ needs.release-please.outputs.tag_name }} + hub-name: emerging-ezimg + secrets: + bend-key: ${{ secrets.BEND_HUB_KEY }}