Skip to content

Release 0.6.3

Release 0.6.3 #15

Workflow file for this run

name: Release
# Push a tag such as v0.2.0 to release. The tag must match the version in pyproject.toml.
on:
push:
tags: ["v*.*.*"]
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
ci:
name: Lint and Test
uses: ./.github/workflows/ci.yml
# The images are built, scanned and pushed before the release is created, so a release
# never exists without its images.
container:
name: Container images
needs: [ci]
uses: ./.github/workflows/container.yml
with:
ref: ${{ github.ref_name }}
permissions:
contents: read
packages: write
id-token: write
attestations: write
security-events: write
release:
name: Publish the GitHub release
runs-on: ubuntu-latest
timeout-minutes: 10
needs: [ci, container]
permissions:
# Creating a release and attaching its files is the only write this workflow makes.
contents: write
steps:
- name: Checkout
uses: actions/checkout@v7
# The files the gate built and tested, not a fresh build.
- name: Fetch the build
uses: actions/download-artifact@v8
with:
name: dist
path: dist/
- name: Check the tag matches the version
env:
TAG: ${{ github.ref_name }}
run: |
version="$(python3 -c 'import tomllib; print(tomllib.load(open("pyproject.toml", "rb"))["project"]["version"])')"
if [ "v${version}" != "${TAG}" ]; then
echo "::error::tag ${TAG} does not match pyproject.toml version ${version}"
exit 1
fi
ls dist/*"${version}"*.whl dist/*"${version}"*.tar.gz
- name: Write checksums
run: cd dist && sha256sum -- * > SHA256SUMS
- name: Create the release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.ref_name }}
run: |
flags=()
# A pre-release (v0.5.1rc1) is marked as one, so it never becomes the latest
# release, which is what the weekly patch run rebuilds and people install.
if [[ ! "${TAG#v}" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
flags+=(--prerelease)
fi
gh release create "${TAG}" dist/* --verify-tag --generate-notes --title "${TAG}" "${flags[@]}"
# PyPI, through trusted publishing: PyPI trusts this workflow running in the pypi
# environment, so no token is stored anywhere. It runs last because a version on PyPI
# can never be replaced, and stays off until the repository variable PUBLISH_PYPI is
# "true", since PyPI must know the publisher first (see docs/development.md).
pypi:
name: Publish to PyPI
needs: [release]
if: vars.PUBLISH_PYPI == 'true'
runs-on: ubuntu-latest
timeout-minutes: 10
environment:
name: pypi
url: https://pypi.org/p/libre-devops-helpers
permissions:
# The OIDC token PyPI exchanges for a short-lived upload token, and that signs the
# upload's provenance attestations.
id-token: write
steps:
# The files the gate built and tested, as the GitHub release has them.
- name: Fetch the build
uses: actions/download-artifact@v8
with:
name: dist
path: dist/
- name: Publish
uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2