-
Notifications
You must be signed in to change notification settings - Fork 0
95 lines (83 loc) · 3.08 KB
/
Copy pathrelease.yml
File metadata and controls
95 lines (83 loc) · 3.08 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
---
name: Release
"on":
push:
tags:
- "v*"
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false
jobs:
verify:
name: Tag matches the crate and sits on main
runs-on: ubuntu-latest
outputs:
version: ${{ steps.crate.outputs.version }}
publish: ${{ steps.crate.outputs.publish }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
- id: crate
run: |
set -euo pipefail
version=$(cargo metadata --no-deps --format-version 1 --manifest-path Cargo.toml | jq -r '.packages[0].version')
if [ "v${version%%+*}" != "$GITHUB_REF_NAME" ]; then
echo "tag $GITHUB_REF_NAME does not match crate version $version" >&2
exit 1
fi
git merge-base --is-ancestor HEAD origin/main
status=$(curl -s -o /dev/null -w '%{http_code}' -A "sqlite3mc-src release workflow" \
"https://crates.io/api/v1/crates/sqlite3mc-src/${version}")
if [ "$status" = 200 ]; then
echo "sqlite3mc-src $version is already on crates.io"
else
echo "publish=yes" >> "$GITHUB_OUTPUT"
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
# The full CI workflow on the tagged commit, which publishing cannot start without.
ci:
name: CI
needs: verify
# actionlint 1.7.12 rejects $/ (rhysd/actionlint#711), and a local reusable workflow already loads from this commit.
uses: ./.github/workflows/ci.yml # zizmor: ignore[self-repository]
publish:
name: Publish ${{ github.ref_name }}
needs: [verify, ci]
runs-on: ubuntu-latest
timeout-minutes: 30
# crates.io trusts only this repository, workflow file and environment.
environment: release
permissions:
contents: write
id-token: write
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
- if: needs.verify.outputs.publish == 'yes'
id: auth
uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18 # v1.0.5
- if: needs.verify.outputs.publish == 'yes'
run: cargo publish
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
- name: GitHub release
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ needs.verify.outputs.version }}
run: |
set -euo pipefail
gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1 || gh release create "$GITHUB_REF_NAME" \
--verify-tag \
--title "$GITHUB_REF_NAME" \
--notes "sqlite3mc-src $VERSION on [crates.io](https://crates.io/crates/sqlite3mc-src/$VERSION)."