Repository navigation
Release 0.6.2 #14
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| # Push a tag such as v0.2.0 to release. The tag must match the version in pyproject.toml. | |
| on: | |
| push: | |
| tags: ["v*.*.*"] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: release-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| ci: | |
| name: Lint and Test | |
| uses: ./.github/workflows/ci.yml | |
| # The images are built, scanned and pushed before the release is created, so a release | |
| # never exists without its images. | |
| container: | |
| name: Container images | |
| needs: [ci] | |
| uses: ./.github/workflows/container.yml | |
| with: | |
| ref: ${{ github.ref_name }} | |
| permissions: | |
| contents: read | |
| packages: write | |
| id-token: write | |
| attestations: write | |
| security-events: write | |
| release: | |
| name: Publish the GitHub release | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| needs: [ci, container] | |
| permissions: | |
| # Creating a release and attaching its files is the only write this workflow makes. | |
| contents: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| # The files the gate built and tested, not a fresh build. | |
| - name: Fetch the build | |
| uses: actions/download-artifact@v8 | |
| with: | |
| name: dist | |
| path: dist/ | |
| - name: Check the tag matches the version | |
| env: | |
| TAG: ${{ github.ref_name }} | |
| run: | | |
| version="$(python3 -c 'import tomllib; print(tomllib.load(open("pyproject.toml", "rb"))["project"]["version"])')" | |
| if [ "v${version}" != "${TAG}" ]; then | |
| echo "::error::tag ${TAG} does not match pyproject.toml version ${version}" | |
| exit 1 | |
| fi | |
| ls dist/*"${version}"*.whl dist/*"${version}"*.tar.gz | |
| - name: Write checksums | |
| run: cd dist && sha256sum -- * > SHA256SUMS | |
| - name: Create the release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| TAG: ${{ github.ref_name }} | |
| run: | | |
| flags=() | |
| # A pre-release (v0.5.1rc1) is marked as one, so it never becomes the latest | |
| # release, which is what the weekly patch run rebuilds and people install. | |
| if [[ ! "${TAG#v}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then | |
| flags+=(--prerelease) | |
| fi | |
| gh release create "${TAG}" dist/* --verify-tag --generate-notes --title "${TAG}" "${flags[@]}" | |
| # PyPI, through trusted publishing: PyPI trusts this workflow running in the pypi | |
| # environment, so no token is stored anywhere. It runs last because a version on PyPI | |
| # can never be replaced, and stays off until the repository variable PUBLISH_PYPI is | |
| # "true", since PyPI must know the publisher first (see docs/development.md). | |
| pypi: | |
| name: Publish to PyPI | |
| needs: [release] | |
| if: vars.PUBLISH_PYPI == 'true' | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| environment: | |
| name: pypi | |
| url: https://pypi.org/p/libre-devops-helpers | |
| permissions: | |
| # The OIDC token PyPI exchanges for a short-lived upload token, and that signs the | |
| # upload's provenance attestations. | |
| id-token: write | |
| steps: | |
| # The files the gate built and tested, as the GitHub release has them. | |
| - name: Fetch the build | |
| uses: actions/download-artifact@v8 | |
| with: | |
| name: dist | |
| path: dist/ | |
| - name: Publish | |
| uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 |