-
Notifications
You must be signed in to change notification settings - Fork 14
44 lines (41 loc) · 1.74 KB
/
Copy pathrelease.yml
File metadata and controls
44 lines (41 loc) · 1.74 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
name: Release
# On a version tag, build cross-platform binaries + checksums and publish a
# GitHub Release via GoReleaser. Runs alongside docker.yml (which also fires on
# v* tags to publish the image) as an independent job — they share no state.
on:
push:
tags:
- "v*"
permissions:
contents: write # create the Release and upload assets
jobs:
goreleaser:
name: GoReleaser
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # full history + tags — required for the changelog and version
fetch-tags: true
- uses: actions/setup-go@v5
with:
go-version: "1.25"
cache: true
- uses: goreleaser/goreleaser-action@v6
with:
distribution: goreleaser
version: "~> v2"
args: release --clean
env:
# Author the GitHub Release under a maintainer's identity rather than
# the github-actions[bot]. Add a repo secret RELEASE_TOKEN — a PAT
# (fine-grained with Contents: read/write on this repo, or classic
# with `repo`) owned by the maintainer who should appear as the
# release author. Falls back to the default token when unset, so the
# release still publishes (attributed to github-actions) without it.
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN || secrets.GITHUB_TOKEN }}
# Pushes the Homebrew formula to github.com/stackshy/homebrew-tap.
# MAINTAINER PREREQUISITE (one-time): add a repo secret named
# HOMEBREW_TAP_TOKEN — a PAT with write access to the tap repo.
# Without it the release still publishes; only the brew push is skipped.
HOMEBREW_TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}