From ce8505c0c937fa4a3e0c21ff79049ba38ce3b839 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 4 Aug 2026 09:50:04 -0500 Subject: [PATCH 01/31] feat: add release build output manifests Created with Codex (GPT-5). --- .github/workflows/conda-cpp-build.yaml | 15 ++++++ .github/workflows/conda-python-build.yaml | 15 ++++++ .github/workflows/custom-job.yaml | 42 ++++++++++++++++ .github/workflows/wheels-build.yaml | 15 ++++++ README.md | 61 +++++++++++++++++++++++ 5 files changed, 148 insertions(+) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 8ccb0f6a..45d6680e 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -44,6 +44,11 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" + release-unit: + type: string + default: '' + required: false + description: "Override the release-platform unit ID; defaults to conda:" matrix_filter: description: | jq expression which modifies the matrix. @@ -284,6 +289,16 @@ jobs: if-no-files-found: 'error' name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} + + - name: Create Conda release build-output companion + if: ${{ inputs.upload-artifacts }} + uses: rapidsai/shared-actions/release-build-output-dispatch@main + with: + artifact-type: conda + output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} + release-unit: ${{ inputs.release-unit || format('conda:{0}', github.event.repository.name) }} + source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + source-sha: ${{ inputs.sha || github.sha }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)" diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 7eb43dc6..61278c97 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -44,6 +44,11 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" + release-unit: + type: string + default: '' + required: false + description: "Override the release-platform unit ID; defaults to conda:" matrix_filter: description: | jq expression which modifies the matrix. @@ -289,6 +294,16 @@ jobs: if-no-files-found: 'error' name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} + + - name: Create Conda release build-output companion + if: ${{ inputs.upload-artifacts }} + uses: rapidsai/shared-actions/release-build-output-dispatch@main + with: + artifact-type: conda + output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} + release-unit: ${{ inputs.release-unit || format('conda:{0}', github.event.repository.name) }} + source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + source-sha: ${{ inputs.sha || github.sha }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)_py${RAPIDS_PY_VERSION//.}" diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index dd950712..8b4b39ca 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -105,6 +105,36 @@ on: default: false type: boolean required: false + release-build-output: + description: "Generate a release-build-output companion for the uploaded artifact bundle" + default: false + type: boolean + required: false + release-unit: + description: "Stable release-platform unit ID; required when release-build-output is true" + default: '' + type: string + required: false + release-package: + description: "JSON package identity shared by the bundle; mutually exclusive with release-package-file" + default: '' + type: string + required: false + release-package-file: + description: "Producer-created package JSON relative to release-output-directory" + default: '' + type: string + required: false + release-artifacts: + description: "JSON primary-artifact and evidence descriptors relative to release-output-directory" + default: '' + type: string + required: false + release-output-directory: + description: "Directory containing the primary artifact paths described by release-artifacts" + default: '.' + type: string + required: false defaults: run: @@ -233,6 +263,18 @@ jobs: name: ${{ inputs.artifact-name }} path: ${{ inputs.file_to_upload }} if-no-files-found: ignore + - name: Create release build-output companion + if: ${{ inputs.release-build-output }} + uses: rapidsai/shared-actions/release-build-output-dispatch@main + with: + artifact-type: custom + output-directory: ${{ inputs.release-output-directory }} + release-artifacts: ${{ inputs.release-artifacts }} + release-package: ${{ inputs.release-package }} + release-package-file: ${{ inputs.release-package-file }} + release-unit: ${{ inputs.release-unit }} + source-artifact-name: ${{ inputs.artifact-name }} + source-sha: ${{ inputs.sha || github.sha }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "custom-job-$(arch)" diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index ebe4968e..501b4390 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -75,6 +75,11 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" + release-unit: + type: string + default: '' + required: false + description: "Override the release-platform unit ID; defaults to wheel:" extra-repo: required: false type: string @@ -357,6 +362,16 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} + - name: Create wheel release build-output companion + if: ${{ inputs.upload-artifacts }} + uses: rapidsai/shared-actions/release-build-output-dispatch@main + with: + artifact-type: wheel + output-directory: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} + release-unit: ${{ inputs.release-unit || format('wheel:{0}', github.event.repository.name) }} + source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + source-sha: ${{ inputs.sha || github.sha }} + - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)_py${RAPIDS_PY_VERSION//.}" diff --git a/README.md b/README.md index 9752c524..9e9cacf3 100644 --- a/README.md +++ b/README.md @@ -20,6 +20,67 @@ Reusable workflows must be placed in the `.github/workflows` directory as mentio ## Usage +### release-build-output + +Release build-output companions are created inside the producer job by the +[`release-build-output-dispatch`](https://github.com/rapidsai/shared-actions/tree/main/release-build-output-dispatch) +shared action. Running beside the build keeps the producer's matrix, +source-artifact name, and original files authoritative and avoids a second +runner and artifact download. + +The standard wheel and Conda builders create a companion for every uploaded +bundle. The release unit defaults to `wheel:` or +`conda:` and can be overridden with `release-unit` when the +release-platform catalog uses a different ID. The shared action reads exact +package metadata from the built files and uploads +`release-build-output-`. No release-specific caller +configuration is required for the standard builders. + +`custom-job.yaml` remains explicitly opt-in through `release-build-output` and +also requires `release-unit`, `release-output-directory`, `release-artifacts`, +and either `release-package` or +`release-package-file`. Descriptors may name producer-supplied SBOM, +provenance, and signature sidecars relative to the output directory. Each path +or glob must resolve to exactly one file; the action never guesses a release +artifact. + +```yaml +cuvs-java-build: + uses: rapidsai/shared-workflows/.github/workflows/custom-job.yaml@main + with: + # existing build inputs omitted + artifact-name: cuvs-java-cuda12.9.1 + file_to_upload: java/cuvs-java/target/ + release-build-output: true + release-output-directory: java/cuvs-java/target + release-unit: maven:cuvs-java + release-package-file: cuvs-java.release-package.json + release-artifacts: '[{"path":"cuvs-java-*-x86_64-cuda*.jar"}]' +``` + +The release coordinator downloads both artifacts into the same directory, for +example `release-build-outputs/cuvs-java/cuda12.9.1/`. The resulting tree has +one `release-build-output.json` per producer job and is consumed directly by +`rapids-release shadow file`. It does not require Artifactory. + +The companion artifact also carries `release-build-metadata.json`. It records +the artifact identity, manifest filename, GitHub build identity, and one +`metadata.artifacts` entry per primary artifact. Each entry explicitly sets +`sbom_kind` to `producer-dependency` or `generated-identity`. SBOM and +provenance paths remain authoritative in `release-build-output.json`; supplied +sidecars are copied under `release-evidence/` so the companion is independently +self-contained. + +When no SBOM is selected, the action generates an SPDX artifact-identity +envelope containing package identity and the primary artifact SHA-256. It is +classified as `generated-identity`, contains no dependency inventory, and must +not be reported as a producer-supplied dependency SBOM. A descriptor-selected +producer SBOM is instead classified as `producer-dependency`. + +The cross-repository enrollment inventory, blockers, and proposed PR sequence +are maintained in +[`rapidsai/build-infra#381`](https://github.com/rapidsai/build-infra/issues/381). + ### matrix_filter Several of the workflows in this project have matrices (combinations of workflow inputs) expressed in inline YAML/JSON. From c1bd94ec16ee1ac9dc1093cd092dd1eb7fa249a9 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 7 Aug 2026 13:43:04 -0500 Subject: [PATCH 02/31] Test container-safe release output dispatch --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 45d6680e..03d07e94 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -292,7 +292,7 @@ jobs: - name: Create Conda release build-output companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@main + uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container with: artifact-type: conda output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 61278c97..5c789ba3 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -297,7 +297,7 @@ jobs: - name: Create Conda release build-output companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@main + uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container with: artifact-type: conda output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 8b4b39ca..590e918e 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -265,7 +265,7 @@ jobs: if-no-files-found: ignore - name: Create release build-output companion if: ${{ inputs.release-build-output }} - uses: rapidsai/shared-actions/release-build-output-dispatch@main + uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container with: artifact-type: custom output-directory: ${{ inputs.release-output-directory }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 501b4390..da2d79fa 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -364,7 +364,7 @@ jobs: - name: Create wheel release build-output companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@main + uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container with: artifact-type: wheel output-directory: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} From 0463e05792f05925f34b51a40ee6ee70eb0a3914 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 7 Aug 2026 13:47:29 -0500 Subject: [PATCH 03/31] Use RAPIDS-owned dispatch canary ref --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 03d07e94..6e42791d 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -292,7 +292,7 @@ jobs: - name: Create Conda release build-output companion if: ${{ inputs.upload-artifacts }} - uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container with: artifact-type: conda output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 5c789ba3..b4c7fbcf 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -297,7 +297,7 @@ jobs: - name: Create Conda release build-output companion if: ${{ inputs.upload-artifacts }} - uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container with: artifact-type: conda output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 590e918e..5f10a91d 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -265,7 +265,7 @@ jobs: if-no-files-found: ignore - name: Create release build-output companion if: ${{ inputs.release-build-output }} - uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container with: artifact-type: custom output-directory: ${{ inputs.release-output-directory }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index da2d79fa..8c86390d 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -364,7 +364,7 @@ jobs: - name: Create wheel release build-output companion if: ${{ inputs.upload-artifacts }} - uses: msarahan/shared-actions/release-build-output-dispatch@76acdd577825aefd04d8ea143449101b707acee6 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container with: artifact-type: wheel output-directory: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} From 492293682a8b5bfb9b93a1be75070fd107dcd363 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Thu, 13 Aug 2026 09:52:35 -0500 Subject: [PATCH 04/31] Clarify release output inputs --- .github/workflows/conda-cpp-build.yaml | 16 ++++--- .github/workflows/conda-python-build.yaml | 16 ++++--- .github/workflows/custom-job.yaml | 42 ++++--------------- .github/workflows/wheels-build.yaml | 16 ++++--- README.md | 51 ++++++++++++++++------- 5 files changed, 77 insertions(+), 64 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 6e42791d..a540df14 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -48,7 +48,10 @@ on: type: string default: '' required: false - description: "Override the release-platform unit ID; defaults to conda:" + description: >- + Release component ID: a string label, not a file or bundle. It is written to each manifest entry and groups + files and matrix variants for release assembly. Leave empty to use conda:; override only + when one repository's Conda producers must be tracked as distinct components. matrix_filter: description: | jq expression which modifies the matrix. @@ -292,11 +295,14 @@ jobs: - name: Create Conda release build-output companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container with: - artifact-type: conda - output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} - release-unit: ${{ inputs.release-unit || format('conda:{0}', github.event.repository.name) }} + config: >- + { + "artifact_type": "conda", + "component_id": ${{ toJSON(inputs.release-unit || format('conda:{0}', github.event.repository.name)) }}, + "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} + } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} source-sha: ${{ inputs.sha || github.sha }} - name: Upload additional artifacts diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index b4c7fbcf..3e968904 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -48,7 +48,10 @@ on: type: string default: '' required: false - description: "Override the release-platform unit ID; defaults to conda:" + description: >- + Release component ID: a string label, not a file or bundle. It is written to each manifest entry and groups + files and matrix variants for release assembly. Leave empty to use conda:; override only + when one repository's Conda producers must be tracked as distinct components. matrix_filter: description: | jq expression which modifies the matrix. @@ -297,11 +300,14 @@ jobs: - name: Create Conda release build-output companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container with: - artifact-type: conda - output-directory: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} - release-unit: ${{ inputs.release-unit || format('conda:{0}', github.event.repository.name) }} + config: >- + { + "artifact_type": "conda", + "component_id": ${{ toJSON(inputs.release-unit || format('conda:{0}', github.event.repository.name)) }}, + "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} + } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} source-sha: ${{ inputs.sha || github.sha }} - name: Upload additional artifacts diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 5f10a91d..9c0c345c 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -106,35 +106,14 @@ on: type: boolean required: false release-build-output: - description: "Generate a release-build-output companion for the uploaded artifact bundle" - default: false - type: boolean - required: false - release-unit: - description: "Stable release-platform unit ID; required when release-build-output is true" - default: '' - type: string - required: false - release-package: - description: "JSON package identity shared by the bundle; mutually exclusive with release-package-file" - default: '' - type: string - required: false - release-package-file: - description: "Producer-created package JSON relative to release-output-directory" + description: >- + Optional JSON object describing a custom release package bundle. A non-empty value creates the companion; + leave empty for logs, documentation, tests, and other non-release artifacts. Requires artifact_type set to + custom, component_id, artifacts, and exactly one of package or package_file; output_directory defaults to + '.'. The shared action validates every field before inspecting build outputs. default: '' type: string required: false - release-artifacts: - description: "JSON primary-artifact and evidence descriptors relative to release-output-directory" - default: '' - type: string - required: false - release-output-directory: - description: "Directory containing the primary artifact paths described by release-artifacts" - default: '.' - type: string - required: false defaults: run: @@ -264,15 +243,10 @@ jobs: path: ${{ inputs.file_to_upload }} if-no-files-found: ignore - name: Create release build-output companion - if: ${{ inputs.release-build-output }} - uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container + if: ${{ inputs.release-build-output != '' }} + uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container with: - artifact-type: custom - output-directory: ${{ inputs.release-output-directory }} - release-artifacts: ${{ inputs.release-artifacts }} - release-package: ${{ inputs.release-package }} - release-package-file: ${{ inputs.release-package-file }} - release-unit: ${{ inputs.release-unit }} + config: ${{ inputs.release-build-output }} source-artifact-name: ${{ inputs.artifact-name }} source-sha: ${{ inputs.sha || github.sha }} - name: Upload additional artifacts diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 8c86390d..36e5b9ef 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -79,7 +79,10 @@ on: type: string default: '' required: false - description: "Override the release-platform unit ID; defaults to wheel:" + description: >- + Release component ID: a string label, not a file or bundle. It is written to each manifest entry and groups + files and matrix variants for release assembly. Leave empty to use wheel:; override only + when one repository's wheel producers must be tracked as distinct components. extra-repo: required: false type: string @@ -364,11 +367,14 @@ jobs: - name: Create wheel release build-output companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@3a9568fc2c9bc9fd05e4cf76a73d9ad481f93ac5 # agent/release-build-output-container + uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container with: - artifact-type: wheel - output-directory: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} - release-unit: ${{ inputs.release-unit || format('wheel:{0}', github.event.repository.name) }} + config: >- + { + "artifact_type": "wheel", + "component_id": ${{ toJSON(inputs.release-unit || format('wheel:{0}', github.event.repository.name)) }}, + "output_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} + } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} source-sha: ${{ inputs.sha || github.sha }} diff --git a/README.md b/README.md index 9e9cacf3..6cce6616 100644 --- a/README.md +++ b/README.md @@ -29,20 +29,38 @@ source-artifact name, and original files authoritative and avoids a second runner and artifact download. The standard wheel and Conda builders create a companion for every uploaded -bundle. The release unit defaults to `wheel:` or +bundle. The release component ID defaults to `wheel:` or `conda:` and can be overridden with `release-unit` when the -release-platform catalog uses a different ID. The shared action reads exact -package metadata from the built files and uploads +release catalog needs to track multiple producer families in one repository as +distinct components. `release-unit` is the API's historical name for this ID. +It is a string label, not a file, directory, artifact bundle, or list of files. +The same ID is written on every primary file in the component and is reused +across its matrix variants, such as CUDA version, Python version, and +architecture, so release assembly can group those outputs together. Most +standard Conda and wheel callers should leave `release-unit` unset. The shared +action reads exact package metadata from the built files and uploads `release-build-output-`. No release-specific caller configuration is required for the standard builders. -`custom-job.yaml` remains explicitly opt-in through `release-build-output` and -also requires `release-unit`, `release-output-directory`, `release-artifacts`, -and either `release-package` or -`release-package-file`. Descriptors may name producer-supplied SBOM, -provenance, and signature sidecars relative to the output directory. Each path -or glob must resolve to exactly one file; the action never guesses a release -artifact. +`custom-job.yaml` remains explicitly opt-in through one `release-build-output` +JSON object. An empty string disables companion generation. A non-empty object +requires `artifact_type: custom`, `component_id`, a non-empty `artifacts` +array, and exactly one of `package` or `package_file`; `output_directory` +defaults to the job's working directory. Descriptors may name +producer-supplied SBOM, provenance, and +signature sidecars relative to the output directory. Each path or glob must +resolve to exactly one file; the action never guesses a release artifact. + +| Custom-job input | Why and when to use it | +| --- | --- | +| `release-build-output` | Supply one complete JSON configuration only when the upload is a release package bundle. Its presence enables companion generation; an empty value disables it. The shared action reports malformed JSON, unknown keys, missing fields, conflicting package sources, and invalid artifact descriptors before materialization. | + +The canonical schema is +[`release-build-output/config.schema.json`](https://github.com/rapidsai/shared-actions/blob/a18a4a7ac572366c09c15641ec274cc6f15bfb5d/release-build-output/config.schema.json). +Pre-commit exercises the schema validator against valid and invalid fixtures. +The pipeline additionally checks properties that cannot be known before the +build, including whether package files and artifact/evidence globs resolve to +exactly one file. ```yaml cuvs-java-build: @@ -51,11 +69,14 @@ cuvs-java-build: # existing build inputs omitted artifact-name: cuvs-java-cuda12.9.1 file_to_upload: java/cuvs-java/target/ - release-build-output: true - release-output-directory: java/cuvs-java/target - release-unit: maven:cuvs-java - release-package-file: cuvs-java.release-package.json - release-artifacts: '[{"path":"cuvs-java-*-x86_64-cuda*.jar"}]' + release-build-output: >- + { + "artifact_type": "custom", + "component_id": "maven:cuvs-java", + "output_directory": "java/cuvs-java/target", + "package_file": "cuvs-java.release-package.json", + "artifacts": [{"path": "cuvs-java-*-x86_64-cuda*.jar"}] + } ``` The release coordinator downloads both artifacts into the same directory, for From a8e8c6006d0d85dde1b0da0635ac9db2c3e82d8d Mon Sep 17 00:00:00 2001 From: Mike Sarahan Date: Mon, 17 Aug 2026 20:09:33 -0500 Subject: [PATCH 05/31] improve description and parameter name of release-build-output param Co-authored-by: James Lamb --- .github/workflows/custom-job.yaml | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 9c0c345c..b3f6a376 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -105,12 +105,9 @@ on: default: false type: boolean required: false - release-build-output: + release-build-config: description: >- - Optional JSON object describing a custom release package bundle. A non-empty value creates the companion; - leave empty for logs, documentation, tests, and other non-release artifacts. Requires artifact_type set to - custom, component_id, artifacts, and exactly one of package or package_file; output_directory defaults to - '.'. The shared action validates every field before inspecting build outputs. + Optional JSON string with additional configuration for the `shared-actions/release-build-output-dispatch` action. See https://github.com/rapidsai/shared-actions/tree/main/release-build-output for details. If non-empty, creates a release manifest for artifacts produced by this job. default: '' type: string required: false From f26fc61eb693ed84500a9d5f4aacfae755729e4f Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Mon, 17 Aug 2026 20:22:44 -0500 Subject: [PATCH 06/31] Address release build output review feedback --- .github/workflows/conda-cpp-build.yaml | 12 +-- .github/workflows/conda-python-build.yaml | 12 +-- .github/workflows/custom-job.yaml | 10 ++- .github/workflows/wheels-build.yaml | 12 +-- README.md | 97 ++++------------------- 5 files changed, 28 insertions(+), 115 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index a540df14..5801040c 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -44,14 +44,6 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" - release-unit: - type: string - default: '' - required: false - description: >- - Release component ID: a string label, not a file or bundle. It is written to each manifest entry and groups - files and matrix variants for release assembly. Leave empty to use conda:; override only - when one repository's Conda producers must be tracked as distinct components. matrix_filter: description: | jq expression which modifies the matrix. @@ -300,11 +292,11 @@ jobs: config: >- { "artifact_type": "conda", - "component_id": ${{ toJSON(inputs.release-unit || format('conda:{0}', github.event.repository.name)) }}, + "component_id": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} - source-sha: ${{ inputs.sha || github.sha }} + source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)" diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 3e968904..d20b3094 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -44,14 +44,6 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" - release-unit: - type: string - default: '' - required: false - description: >- - Release component ID: a string label, not a file or bundle. It is written to each manifest entry and groups - files and matrix variants for release assembly. Leave empty to use conda:; override only - when one repository's Conda producers must be tracked as distinct components. matrix_filter: description: | jq expression which modifies the matrix. @@ -305,11 +297,11 @@ jobs: config: >- { "artifact_type": "conda", - "component_id": ${{ toJSON(inputs.release-unit || format('conda:{0}', github.event.repository.name)) }}, + "component_id": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} - source-sha: ${{ inputs.sha || github.sha }} + source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)_py${RAPIDS_PY_VERSION//.}" diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index b3f6a376..2c778d82 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -107,7 +107,9 @@ on: required: false release-build-config: description: >- - Optional JSON string with additional configuration for the `shared-actions/release-build-output-dispatch` action. See https://github.com/rapidsai/shared-actions/tree/main/release-build-output for details. If non-empty, creates a release manifest for artifacts produced by this job. + Optional JSON configuration for the `shared-actions/release-build-output-dispatch` action. When non-empty, + this job uploads an additional `release-build-output-` GitHub Actions artifact. See + https://github.com/rapidsai/shared-actions/tree/main/release-build-output for configuration details. default: '' type: string required: false @@ -240,12 +242,12 @@ jobs: path: ${{ inputs.file_to_upload }} if-no-files-found: ignore - name: Create release build-output companion - if: ${{ inputs.release-build-output != '' }} + if: ${{ inputs.release-build-config != '' }} uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container with: - config: ${{ inputs.release-build-output }} + config: ${{ inputs.release-build-config }} source-artifact-name: ${{ inputs.artifact-name }} - source-sha: ${{ inputs.sha || github.sha }} + source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "custom-job-$(arch)" diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 36e5b9ef..dc49abd9 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -75,14 +75,6 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" - release-unit: - type: string - default: '' - required: false - description: >- - Release component ID: a string label, not a file or bundle. It is written to each manifest entry and groups - files and matrix variants for release assembly. Leave empty to use wheel:; override only - when one repository's wheel producers must be tracked as distinct components. extra-repo: required: false type: string @@ -372,11 +364,11 @@ jobs: config: >- { "artifact_type": "wheel", - "component_id": ${{ toJSON(inputs.release-unit || format('wheel:{0}', github.event.repository.name)) }}, + "component_id": ${{ toJSON(format('wheel:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} - source-sha: ${{ inputs.sha || github.sha }} + source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" diff --git a/README.md b/README.md index 6cce6616..0be1bd83 100644 --- a/README.md +++ b/README.md @@ -20,87 +20,22 @@ Reusable workflows must be placed in the `.github/workflows` directory as mentio ## Usage -### release-build-output - -Release build-output companions are created inside the producer job by the -[`release-build-output-dispatch`](https://github.com/rapidsai/shared-actions/tree/main/release-build-output-dispatch) -shared action. Running beside the build keeps the producer's matrix, -source-artifact name, and original files authoritative and avoids a second -runner and artifact download. - -The standard wheel and Conda builders create a companion for every uploaded -bundle. The release component ID defaults to `wheel:` or -`conda:` and can be overridden with `release-unit` when the -release catalog needs to track multiple producer families in one repository as -distinct components. `release-unit` is the API's historical name for this ID. -It is a string label, not a file, directory, artifact bundle, or list of files. -The same ID is written on every primary file in the component and is reused -across its matrix variants, such as CUDA version, Python version, and -architecture, so release assembly can group those outputs together. Most -standard Conda and wheel callers should leave `release-unit` unset. The shared -action reads exact package metadata from the built files and uploads -`release-build-output-`. No release-specific caller -configuration is required for the standard builders. - -`custom-job.yaml` remains explicitly opt-in through one `release-build-output` -JSON object. An empty string disables companion generation. A non-empty object -requires `artifact_type: custom`, `component_id`, a non-empty `artifacts` -array, and exactly one of `package` or `package_file`; `output_directory` -defaults to the job's working directory. Descriptors may name -producer-supplied SBOM, provenance, and -signature sidecars relative to the output directory. Each path or glob must -resolve to exactly one file; the action never guesses a release artifact. - -| Custom-job input | Why and when to use it | -| --- | --- | -| `release-build-output` | Supply one complete JSON configuration only when the upload is a release package bundle. Its presence enables companion generation; an empty value disables it. The shared action reports malformed JSON, unknown keys, missing fields, conflicting package sources, and invalid artifact descriptors before materialization. | - -The canonical schema is -[`release-build-output/config.schema.json`](https://github.com/rapidsai/shared-actions/blob/a18a4a7ac572366c09c15641ec274cc6f15bfb5d/release-build-output/config.schema.json). -Pre-commit exercises the schema validator against valid and invalid fixtures. -The pipeline additionally checks properties that cannot be known before the -build, including whether package files and artifact/evidence globs resolve to -exactly one file. - -```yaml -cuvs-java-build: - uses: rapidsai/shared-workflows/.github/workflows/custom-job.yaml@main - with: - # existing build inputs omitted - artifact-name: cuvs-java-cuda12.9.1 - file_to_upload: java/cuvs-java/target/ - release-build-output: >- - { - "artifact_type": "custom", - "component_id": "maven:cuvs-java", - "output_directory": "java/cuvs-java/target", - "package_file": "cuvs-java.release-package.json", - "artifacts": [{"path": "cuvs-java-*-x86_64-cuda*.jar"}] - } -``` - -The release coordinator downloads both artifacts into the same directory, for -example `release-build-outputs/cuvs-java/cuda12.9.1/`. The resulting tree has -one `release-build-output.json` per producer job and is consumed directly by -`rapids-release shadow file`. It does not require Artifactory. - -The companion artifact also carries `release-build-metadata.json`. It records -the artifact identity, manifest filename, GitHub build identity, and one -`metadata.artifacts` entry per primary artifact. Each entry explicitly sets -`sbom_kind` to `producer-dependency` or `generated-identity`. SBOM and -provenance paths remain authoritative in `release-build-output.json`; supplied -sidecars are copied under `release-evidence/` so the companion is independently -self-contained. - -When no SBOM is selected, the action generates an SPDX artifact-identity -envelope containing package identity and the primary artifact SHA-256. It is -classified as `generated-identity`, contains no dependency inventory, and must -not be reported as a producer-supplied dependency SBOM. A descriptor-selected -producer SBOM is instead classified as `producer-dependency`. - -The cross-repository enrollment inventory, blockers, and proposed PR sequence -are maintained in -[`rapidsai/build-infra#381`](https://github.com/rapidsai/build-infra/issues/381). +### Release build outputs + +The standard Conda and wheel builders upload an additional +`release-build-output-` GitHub Actions artifact for every package +bundle. It contains build metadata and the available provenance and SBOM +evidence used during release assembly. + +`custom-job.yaml` is opt-in. Supplying a non-empty `release-build-config` causes +the job to upload the additional release-build-output artifact; leaving it empty +uploads only the original artifact. + +See the +[`shared-actions` release-build-output documentation](https://github.com/rapidsai/shared-actions/tree/main/release-build-output) +for the companion layout, configuration schema, examples, and evidence +semantics. A generated identity-only SPDX record identifies and hashes an +artifact, but does not provide dependency or source-license coverage. ### matrix_filter From c2618b4bd6dd6c589104bb7a78dfb054aff6d690 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Mon, 17 Aug 2026 20:43:57 -0500 Subject: [PATCH 07/31] simplify release-build-output section --- README.md | 37 ++++++++++++++++++++----------------- 1 file changed, 20 insertions(+), 17 deletions(-) diff --git a/README.md b/README.md index 0be1bd83..cd01713e 100644 --- a/README.md +++ b/README.md @@ -20,23 +20,6 @@ Reusable workflows must be placed in the `.github/workflows` directory as mentio ## Usage -### Release build outputs - -The standard Conda and wheel builders upload an additional -`release-build-output-` GitHub Actions artifact for every package -bundle. It contains build metadata and the available provenance and SBOM -evidence used during release assembly. - -`custom-job.yaml` is opt-in. Supplying a non-empty `release-build-config` causes -the job to upload the additional release-build-output artifact; leaving it empty -uploads only the original artifact. - -See the -[`shared-actions` release-build-output documentation](https://github.com/rapidsai/shared-actions/tree/main/release-build-output) -for the companion layout, configuration schema, examples, and evidence -semantics. A generated identity-only SPDX record identifies and hashes an -artifact, but does not provide dependency or source-license coverage. - ### matrix_filter Several of the workflows in this project have matrices (combinations of workflow inputs) expressed in inline YAML/JSON. @@ -113,3 +96,23 @@ wheel-tests: ``` Values passed through `secrets:` are redacted everywhere in the GitHub UI, including in logs, and in most cases are replaced with `***`. + +### Release build outputs + +We add additional metadata files to our builds to help track what dependencies +were present at build time (a Software Bill of Materials, SBoM), as well as +keeping track of artifacts as we prepare for releases. The standard Conda and +wheel builders do this automatically and upload an additional +`release-build-output-` GitHub Actions artifact for every package +bundle. + +`custom-job.yaml` can be used to produce artifacts, but the generation of extra +metadata files are opt-in, not automatic. Supplying a non-empty +`release-build-config` causes the job to upload the additional +release-build-output artifact; leaving it empty uploads only the original +artifact. + +See the +[`shared-actions` release-build-output documentation](https://github.com/rapidsai/shared-actions/tree/main/release-build-output) +for the companion layout, configuration schema, examples, and evidence +semantics. From de76350be2fd13585944ae90790d1fdffc49cc62 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Mon, 17 Aug 2026 21:20:28 -0500 Subject: [PATCH 08/31] Use release catalog configuration terminology --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 6 +++--- .github/workflows/wheels-build.yaml | 2 +- README.md | 2 +- 5 files changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 5801040c..341d6ba3 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -292,7 +292,7 @@ jobs: config: >- { "artifact_type": "conda", - "component_id": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, + "release_catalog_key": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index d20b3094..926b849f 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -297,7 +297,7 @@ jobs: config: >- { "artifact_type": "conda", - "component_id": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, + "release_catalog_key": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 2c778d82..a17614e8 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -105,7 +105,7 @@ on: default: false type: boolean required: false - release-build-config: + release-catalog-config: description: >- Optional JSON configuration for the `shared-actions/release-build-output-dispatch` action. When non-empty, this job uploads an additional `release-build-output-` GitHub Actions artifact. See @@ -242,10 +242,10 @@ jobs: path: ${{ inputs.file_to_upload }} if-no-files-found: ignore - name: Create release build-output companion - if: ${{ inputs.release-build-config != '' }} + if: ${{ inputs.release-catalog-config != '' }} uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container with: - config: ${{ inputs.release-build-config }} + config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index dc49abd9..b5f3cdb2 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -364,7 +364,7 @@ jobs: config: >- { "artifact_type": "wheel", - "component_id": ${{ toJSON(format('wheel:{0}', github.event.repository.name)) }}, + "release_catalog_key": ${{ toJSON(format('wheel:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} diff --git a/README.md b/README.md index cd01713e..fdcd202e 100644 --- a/README.md +++ b/README.md @@ -108,7 +108,7 @@ bundle. `custom-job.yaml` can be used to produce artifacts, but the generation of extra metadata files are opt-in, not automatic. Supplying a non-empty -`release-build-config` causes the job to upload the additional +`release-catalog-config` causes the job to upload the additional release-build-output artifact; leaving it empty uploads only the original artifact. From 44f67a73d2f31e9cf3ebd1aa8ab93bc5ca36f596 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Mon, 17 Aug 2026 21:41:11 -0500 Subject: [PATCH 09/31] Rename release catalog integration --- .github/workflows/conda-cpp-build.yaml | 4 ++-- .github/workflows/conda-python-build.yaml | 4 ++-- .github/workflows/custom-job.yaml | 10 +++++----- .github/workflows/wheels-build.yaml | 4 ++-- README.md | 9 ++++----- 5 files changed, 15 insertions(+), 16 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 341d6ba3..f6cd6b65 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -285,9 +285,9 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} - - name: Create Conda release build-output companion + - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container + uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 926b849f..f3d3feb8 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -290,9 +290,9 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} - - name: Create Conda release build-output companion + - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container + uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index a17614e8..8de2c0e9 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -107,9 +107,9 @@ on: required: false release-catalog-config: description: >- - Optional JSON configuration for the `shared-actions/release-build-output-dispatch` action. When non-empty, - this job uploads an additional `release-build-output-` GitHub Actions artifact. See - https://github.com/rapidsai/shared-actions/tree/main/release-build-output for configuration details. + Optional JSON configuration for the shared-actions release catalog companion. When non-empty, this job + uploads an additional `release-catalog-` GitHub Actions artifact. See + https://github.com/rapidsai/shared-actions/tree/main/release-catalog for configuration details. default: '' type: string required: false @@ -241,9 +241,9 @@ jobs: name: ${{ inputs.artifact-name }} path: ${{ inputs.file_to_upload }} if-no-files-found: ignore - - name: Create release build-output companion + - name: Create release catalog companion if: ${{ inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container + uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index b5f3cdb2..9dc9b974 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -357,9 +357,9 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} - - name: Create wheel release build-output companion + - name: Create wheel release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-build-output-dispatch@a18a4a7ac572366c09c15641ec274cc6f15bfb5d # agent/release-build-output-container + uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 with: config: >- { diff --git a/README.md b/README.md index fdcd202e..c17eb4c0 100644 --- a/README.md +++ b/README.md @@ -97,22 +97,21 @@ wheel-tests: Values passed through `secrets:` are redacted everywhere in the GitHub UI, including in logs, and in most cases are replaced with `***`. -### Release build outputs +### Release catalog We add additional metadata files to our builds to help track what dependencies were present at build time (a Software Bill of Materials, SBoM), as well as keeping track of artifacts as we prepare for releases. The standard Conda and wheel builders do this automatically and upload an additional -`release-build-output-` GitHub Actions artifact for every package +`release-catalog-` GitHub Actions artifact for every package bundle. `custom-job.yaml` can be used to produce artifacts, but the generation of extra metadata files are opt-in, not automatic. Supplying a non-empty `release-catalog-config` causes the job to upload the additional -release-build-output artifact; leaving it empty uploads only the original -artifact. +release catalog companion; leaving it empty uploads only the original artifact. See the -[`shared-actions` release-build-output documentation](https://github.com/rapidsai/shared-actions/tree/main/release-build-output) +[`shared-actions` release catalog documentation](https://github.com/rapidsai/shared-actions/tree/main/release-catalog) for the companion layout, configuration schema, examples, and evidence semantics. From 3b138d2fca170dc93c3d251bbfef04a670dd7731 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Mon, 17 Aug 2026 23:09:21 -0500 Subject: [PATCH 10/31] pin unified release catalog entries action --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index f6cd6b65..05d46ac9 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -287,7 +287,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index f3d3feb8..6bf1cee1 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -292,7 +292,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 8de2c0e9..b97fbdaf 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -243,7 +243,7 @@ jobs: if-no-files-found: ignore - name: Create release catalog companion if: ${{ inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 9dc9b974..afd9b6ef 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -359,7 +359,7 @@ jobs: - name: Create wheel release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@45e84f709fde5e3f1b5960ed0510599c5f388333 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 with: config: >- { From 8868b40b63d1e7515b8bb0e8c4f0b32f2c5952c9 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 18 Aug 2026 09:41:09 -0500 Subject: [PATCH 11/31] pin simplified package identity action --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 05d46ac9..18a2621c 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -287,7 +287,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 6bf1cee1..31a77dd3 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -292,7 +292,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index b97fbdaf..5f802360 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -243,7 +243,7 @@ jobs: if-no-files-found: ignore - name: Create release catalog companion if: ${{ inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index afd9b6ef..1edbb09d 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -359,7 +359,7 @@ jobs: - name: Create wheel release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@c4b135aba0b7c5e9fa97f384505efeb17b8c5aa9 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 with: config: >- { From 4bcd0e96bee07c3a9cf1dbc62e19ad929750485e Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 18 Aug 2026 10:53:49 -0500 Subject: [PATCH 12/31] use automatic release catalog artifact detection --- .github/workflows/conda-cpp-build.yaml | 1 - .github/workflows/conda-python-build.yaml | 1 - .github/workflows/wheels-build.yaml | 1 - 3 files changed, 3 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 18a2621c..694d7d65 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -291,7 +291,6 @@ jobs: with: config: >- { - "artifact_type": "conda", "release_catalog_key": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 31a77dd3..b7c1fe06 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -296,7 +296,6 @@ jobs: with: config: >- { - "artifact_type": "conda", "release_catalog_key": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 1edbb09d..60b697ae 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -363,7 +363,6 @@ jobs: with: config: >- { - "artifact_type": "wheel", "release_catalog_key": ${{ toJSON(format('wheel:{0}', github.event.repository.name)) }}, "output_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } From 3307a009d74ce59bcdb566771a13d96b4a2f767a Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 18 Aug 2026 11:16:23 -0500 Subject: [PATCH 13/31] rename release catalog artifact directory --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 694d7d65..3c6efea3 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -292,7 +292,7 @@ jobs: config: >- { "release_catalog_key": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, - "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} + "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} source-sha: ${{ env.RAPIDS_SHA }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index b7c1fe06..16c95cdd 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -297,7 +297,7 @@ jobs: config: >- { "release_catalog_key": ${{ toJSON(format('conda:{0}', github.event.repository.name)) }}, - "output_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} + "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} source-sha: ${{ env.RAPIDS_SHA }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 60b697ae..a1f1f849 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -364,7 +364,7 @@ jobs: config: >- { "release_catalog_key": ${{ toJSON(format('wheel:{0}', github.event.repository.name)) }}, - "output_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} + "artifact_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} source-sha: ${{ env.RAPIDS_SHA }} From eb6dc307120fa676a0edf0494ef45558e3211079 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 18 Aug 2026 12:14:20 -0500 Subject: [PATCH 14/31] use inherited release catalog source sha --- .github/workflows/conda-cpp-build.yaml | 1 - .github/workflows/conda-python-build.yaml | 1 - .github/workflows/custom-job.yaml | 1 - .github/workflows/wheels-build.yaml | 1 - 4 files changed, 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 3c6efea3..dd974960 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -295,7 +295,6 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} - source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)" diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 16c95cdd..56912db4 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -300,7 +300,6 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} - source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)_py${RAPIDS_PY_VERSION//.}" diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 5f802360..a2e0a917 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -247,7 +247,6 @@ jobs: with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} - source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" run: rapids-upload-artifacts-dir "custom-job-$(arch)" diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index a1f1f849..a2f6e85b 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -367,7 +367,6 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} - source-sha: ${{ env.RAPIDS_SHA }} - name: Upload additional artifacts if: "!cancelled()" From e2ff822c108931d6dca4276f809593ccfd2a0d16 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 10:58:03 -0500 Subject: [PATCH 15/31] ci: update release catalog action canary --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index dd974960..41a52bf4 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -287,7 +287,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 56912db4..559d9bf2 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -292,7 +292,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index a2e0a917..f00f7807 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -243,7 +243,7 @@ jobs: if-no-files-found: ignore - name: Create release catalog companion if: ${{ inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index a2f6e85b..d586f538 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -359,7 +359,7 @@ jobs: - name: Create wheel release catalog companion if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@6cdff151c40c97551fdf2abd5d977580f94ed7e1 # shared-actions PR 136 + uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head with: config: >- { From 5f7ca4ad4a1f2696f8ce62526e62cf441444d433 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 13:51:24 -0500 Subject: [PATCH 16/31] feat: add release candidate build mode --- .github/workflows/compute-matrix.yaml | 8 ++++---- .github/workflows/conda-cpp-build.yaml | 20 +++++++++++++------- .github/workflows/conda-python-build.yaml | 20 +++++++++++++------- .github/workflows/custom-job.yaml | 19 +++++++++++++------ .github/workflows/wheels-build.yaml | 20 +++++++++++++------- 5 files changed, 56 insertions(+), 31 deletions(-) diff --git a/.github/workflows/compute-matrix.yaml b/.github/workflows/compute-matrix.yaml index 8cc29c01..e9c4b4cd 100644 --- a/.github/workflows/compute-matrix.yaml +++ b/.github/workflows/compute-matrix.yaml @@ -2,7 +2,7 @@ on: workflow_call: inputs: build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string matrix_name: @@ -58,8 +58,8 @@ jobs: env: MATRIX: ${{ steps.prepare-matrix.outputs.matrix }} run: | - if [[ "$BUILD_TYPE" != "branch" ]] && [[ "$BUILD_TYPE" != "nightly" ]] && [[ "$BUILD_TYPE" != "pull-request" ]]; then - echo "::error::Invalid build_type! Must be one of 'branch', 'nightly', or 'pull-request'." + if [[ "$BUILD_TYPE" != "branch" ]] && [[ "$BUILD_TYPE" != "nightly" ]] && [[ "$BUILD_TYPE" != "pull-request" ]] && [[ "$BUILD_TYPE" != "release-candidate" ]]; then + echo "::error::Invalid build_type! Must be one of 'branch', 'nightly', 'pull-request', or 'release-candidate'." exit 1 fi if [[ ! "$MATRIX_TYPE" =~ ^(auto|nightly|pull-request)(,(auto|nightly|pull-request))*$ ]] || [[ "$MATRIX_TYPE" == *auto* && "$MATRIX_TYPE" != "auto" ]]; then @@ -82,7 +82,7 @@ jobs: # only overwrite MATRIX_TYPE if it was set to 'auto' if [[ "${MATRIX_TYPE}" == "auto" ]]; then - if [[ "${BUILD_TYPE}" == "branch" ]]; then + if [[ "${BUILD_TYPE}" == "branch" || "${BUILD_TYPE}" == "release-candidate" ]]; then # Use the nightly matrix for branch tests MATRIX_TYPE="nightly" else diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 41a52bf4..772e3ba3 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -2,7 +2,7 @@ on: workflow_call: inputs: build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string branch: @@ -44,6 +44,10 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" + candidate-train-sha256: + description: "Canonical SHA-256 of the release train; required for release-candidate builds." + type: string + default: "" matrix_filter: description: | jq expression which modifies the matrix. @@ -258,7 +262,7 @@ jobs: MAMBA_USE_SHARDED_REPODATA: false RATTLER_SHARDED: false - name: Get Package Name and Location - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts || inputs.build_type == 'release-candidate' }} env: # Pass RAPIDS_PACKAGE_NAME from cpp-build step if available RAPIDS_PACKAGE_NAME: ${{ steps.cpp-build.outputs.rapids-package-name }} @@ -272,22 +276,22 @@ jobs: echo "CONDA_OUTPUT_DIR=${RAPIDS_CONDA_BLD_OUTPUT_DIR}" >> "${GITHUB_OUTPUT}" id: package-name - name: Show files to be uploaded - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts || inputs.build_type == 'release-candidate' }} env: CONDA_OUTPUT_DIR: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} run: | echo "Contents of directory to be uploaded:" ls -R "${CONDA_OUTPUT_DIR}" - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts && inputs.build_type != 'release-candidate' }} with: if-no-files-found: 'error' name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} - name: Create Conda release catalog companion - if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head + if: ${{ inputs.build_type == 'release-candidate' }} + uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head with: config: >- { @@ -295,8 +299,10 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} + upload-to-s3: 'true' - name: Upload additional artifacts - if: "!cancelled()" + if: ${{ !cancelled() && inputs.build_type != 'release-candidate' }} run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)" - name: Telemetry upload attributes uses: rapidsai/shared-actions/telemetry-dispatch-stash-job-artifacts@main diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 559d9bf2..31e22cf9 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -2,7 +2,7 @@ on: workflow_call: inputs: build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string branch: @@ -44,6 +44,10 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" + candidate-train-sha256: + description: "Canonical SHA-256 of the release train; required for release-candidate builds." + type: string + default: "" matrix_filter: description: | jq expression which modifies the matrix. @@ -263,7 +267,7 @@ jobs: MAMBA_USE_SHARDED_REPODATA: false RATTLER_SHARDED: false - name: Get Package Name and Location - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts || inputs.build_type == 'release-candidate' }} env: # Pass RAPIDS_PACKAGE_NAME from python-build step if available RAPIDS_PACKAGE_NAME: ${{ steps.python-build.outputs.rapids-package-name }} @@ -277,22 +281,22 @@ jobs: echo "CONDA_OUTPUT_DIR=${RAPIDS_CONDA_BLD_OUTPUT_DIR}" >> "${GITHUB_OUTPUT}" id: package-name - name: Show files to be uploaded - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts || inputs.build_type == 'release-candidate' }} env: CONDA_OUTPUT_DIR: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} run: | echo "Contents of directory to be uploaded:" ls -R "${CONDA_OUTPUT_DIR}" - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts && inputs.build_type != 'release-candidate' }} with: if-no-files-found: 'error' name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} - name: Create Conda release catalog companion - if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head + if: ${{ inputs.build_type == 'release-candidate' }} + uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head with: config: >- { @@ -300,8 +304,10 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} + upload-to-s3: 'true' - name: Upload additional artifacts - if: "!cancelled()" + if: ${{ !cancelled() && inputs.build_type != 'release-candidate' }} run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)_py${RAPIDS_PY_VERSION//.}" - name: Telemetry upload attributes uses: rapidsai/shared-actions/telemetry-dispatch-stash-job-artifacts@main diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index f00f7807..51c177ea 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -2,7 +2,7 @@ on: workflow_call: inputs: build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string branch: @@ -107,12 +107,16 @@ on: required: false release-catalog-config: description: >- - Optional JSON configuration for the shared-actions release catalog companion. When non-empty, this job - uploads an additional `release-catalog-` GitHub Actions artifact. See + Optional JSON configuration for the shared-actions release catalog action. In release-candidate mode, + it writes the declared files and evidence to the private candidate store. See https://github.com/rapidsai/shared-actions/tree/main/release-catalog for configuration details. default: '' type: string required: false + candidate-train-sha256: + description: "Canonical SHA-256 of the release train; required for release-candidate builds." + type: string + default: "" defaults: run: @@ -236,19 +240,22 @@ jobs: MAMBA_USE_SHARDED_REPODATA: false RATTLER_SHARDED: false - name: Upload file to GitHub Artifact + if: ${{ inputs.build_type != 'release-candidate' }} uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ inputs.artifact-name }} path: ${{ inputs.file_to_upload }} if-no-files-found: ignore - name: Create release catalog companion - if: ${{ inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head + if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} + uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} + candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} + upload-to-s3: 'true' - name: Upload additional artifacts - if: "!cancelled()" + if: ${{ !cancelled() && inputs.build_type != 'release-candidate' }} run: rapids-upload-artifacts-dir "custom-job-$(arch)" - name: Telemetry upload attributes uses: rapidsai/shared-actions/telemetry-dispatch-stash-job-artifacts@main diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index d586f538..9bf0ad32 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -26,7 +26,7 @@ on: description: "Git repo to check out, in '{org}/{repo}' form, e.g. 'rapidsai/cudf'" type: string build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string script: @@ -75,6 +75,10 @@ on: default: true required: false description: "One of [true, false], true if artifacts should be uploaded to GitHub's artifact store" + candidate-train-sha256: + description: "Canonical SHA-256 of the release train; required for release-candidate builds." + type: string + default: "" extra-repo: required: false type: string @@ -310,7 +314,7 @@ jobs: shell: bash -leo pipefail {0} - name: Get package name - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts || inputs.build_type == 'release-candidate' }} env: # Pass RAPIDS_PACKAGE_NAME from build-wheel step if available RAPIDS_PACKAGE_NAME: ${{ steps.build-wheel.outputs.rapids-package-name }} @@ -343,7 +347,7 @@ jobs: id: package-name - name: Show files to be uploaded - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts || inputs.build_type == 'release-candidate' }} env: WHEEL_OUTPUT_DIR: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} run: | @@ -351,15 +355,15 @@ jobs: ls -R "$WHEEL_OUTPUT_DIR" - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - if: ${{ inputs.upload-artifacts }} + if: ${{ inputs.upload-artifacts && inputs.build_type != 'release-candidate' }} with: if-no-files-found: 'error' name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} - name: Create wheel release catalog companion - if: ${{ inputs.upload-artifacts }} - uses: rapidsai/shared-actions/release-catalog-dispatch@32a308ab234f7381dd611056747b4c1ac30d2a34 # shared-actions PR 136 canary head + if: ${{ inputs.build_type == 'release-candidate' }} + uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head with: config: >- { @@ -367,9 +371,11 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} + upload-to-s3: 'true' - name: Upload additional artifacts - if: "!cancelled()" + if: ${{ !cancelled() && inputs.build_type != 'release-candidate' }} run: rapids-upload-artifacts-dir "cuda${RAPIDS_CUDA_VERSION%%.*}_$(arch)_py${RAPIDS_PY_VERSION//.}" - name: Telemetry upload attributes if: ${{ vars.TELEMETRY_ENABLED == 'true' }} From 978424e0e13a29c98e6f533bf7ed2ada22b278ff Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 14:55:54 -0500 Subject: [PATCH 17/31] fix: use executable candidate upload action --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 772e3ba3..2af455fe 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -291,7 +291,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 31e22cf9..dc9086a0 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -296,7 +296,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 51c177ea..3f8ca5e6 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -248,7 +248,7 @@ jobs: if-no-files-found: ignore - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 9bf0ad32..11bb298a 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -363,7 +363,7 @@ jobs: - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@8fef990732014851c3d5afcf931c2506f7e175b0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head with: config: >- { From 10d2a02f9d35a63df2983df0282e92f73551da90 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 14:56:19 -0500 Subject: [PATCH 18/31] fix: pin verified candidate upload action revision --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 2af455fe..04f1792e 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -291,7 +291,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index dc9086a0..b9308672 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -296,7 +296,7 @@ jobs: - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 3f8ca5e6..d232af20 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -248,7 +248,7 @@ jobs: if-no-files-found: ignore - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 11bb298a..8d9a78c7 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -363,7 +363,7 @@ jobs: - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b9e8cd705357c8e12c0b07fea3dd9b893a0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head with: config: >- { From 9b3dd8e4c292b914d44f3a023fea142a6fec2828 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 15:19:00 -0500 Subject: [PATCH 19/31] feat: assume candidate store role for release builds --- .github/workflows/conda-cpp-build.yaml | 7 +++++++ .github/workflows/conda-python-build.yaml | 7 +++++++ .github/workflows/custom-job.yaml | 7 +++++++ .github/workflows/wheels-build.yaml | 7 +++++++ 4 files changed, 28 insertions(+) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 04f1792e..e67a08cb 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -289,6 +289,13 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} + - name: Configure release-candidate store credentials + if: ${{ inputs.build_type == 'release-candidate' }} + uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 + with: + aws-region: us-east-2 + role-duration-seconds: 43200 # 12h + role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index b9308672..fa8ae7c6 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -294,6 +294,13 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.CONDA_OUTPUT_DIR }} + - name: Configure release-candidate store credentials + if: ${{ inputs.build_type == 'release-candidate' }} + uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 + with: + aws-region: us-east-2 + role-duration-seconds: 43200 # 12h + role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index d232af20..d48e8b85 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -246,6 +246,13 @@ jobs: name: ${{ inputs.artifact-name }} path: ${{ inputs.file_to_upload }} if-no-files-found: ignore + - name: Configure release-candidate store credentials + if: ${{ inputs.build_type == 'release-candidate' }} + uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 + with: + aws-region: us-east-2 + role-duration-seconds: 43200 # 12h + role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 8d9a78c7..45741e07 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -361,6 +361,13 @@ jobs: name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} path: ${{ steps.package-name.outputs.WHEEL_OUTPUT_DIR }} + - name: Configure release-candidate store credentials + if: ${{ inputs.build_type == 'release-candidate' }} + uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 + with: + aws-region: us-east-2 + role-duration-seconds: 43200 # 12h + role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head From 339e38f89098ad6515587b4430cbce7c9501a315 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 16:53:14 -0500 Subject: [PATCH 20/31] fix: ignore absent catalog signatures --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index e67a08cb..ab67bfb4 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -298,7 +298,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index fa8ae7c6..e6bb4f9f 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -303,7 +303,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index d48e8b85..4230b51d 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -255,7 +255,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 45741e07..bdb8aba7 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -370,7 +370,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@d2f44b948645ee187102bf586d2ea44596a637c1 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head with: config: >- { From af0c7f58bd5ab41c43268eaf6db2f9094504f9ab Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 17:00:05 -0500 Subject: [PATCH 21/31] fix: use nightly behavior for release candidates --- .github/workflows/conda-cpp-build.yaml | 4 +++- .github/workflows/conda-python-build.yaml | 4 +++- .github/workflows/custom-job.yaml | 4 +++- .github/workflows/wheels-build.yaml | 4 +++- 4 files changed, 12 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index ab67bfb4..6a26e122 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -159,7 +159,9 @@ jobs: container: image: rapidsai/ci-conda:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }} env: - RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} + # Candidate orchestration retains its own input mode, while RAPIDS + # build helpers use the established nightly dependency behavior. + RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index e6bb4f9f..c58f7cd9 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -169,7 +169,9 @@ jobs: container: image: rapidsai/ci-conda:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }} env: - RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} + # Candidate orchestration retains its own input mode, while RAPIDS + # build helpers use the established nightly dependency behavior. + RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 4230b51d..a98ef98f 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -150,7 +150,9 @@ jobs: options: ${{ inputs.container-options }} env: NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }} - RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} + # Candidate orchestration retains its own input mode, while RAPIDS + # build helpers use the established nightly dependency behavior. + RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index bdb8aba7..65459b81 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -199,7 +199,9 @@ jobs: container: image: "rapidsai/ci-wheel:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }}" env: - RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} + # Candidate orchestration retains its own input mode, while RAPIDS + # build helpers use the established nightly dependency behavior. + RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 From 4c54c828f51d2bcb48ac86db179910402c2d936b Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 17:10:07 -0500 Subject: [PATCH 22/31] feat: tag final-version release candidates locally --- .github/workflows/conda-cpp-build.yaml | 16 +++++++++++++++- .github/workflows/conda-python-build.yaml | 16 +++++++++++++++- .github/workflows/custom-job.yaml | 16 +++++++++++++++- .github/workflows/wheels-build.yaml | 16 +++++++++++++++- 4 files changed, 60 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 6a26e122..0ec4834c 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -48,6 +48,10 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" + release-candidate-tag: + description: "Final source tag created locally for a release-candidate build; it is never pushed." + type: string + default: "" matrix_filter: description: | jq expression which modifies the matrix. @@ -162,6 +166,7 @@ jobs: # Candidate orchestration retains its own input mode, while RAPIDS # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -186,6 +191,15 @@ jobs: cache-environment: ${{ inputs.cache-environment }} cache-read-only: ${{ inputs.cache-read-only }} matrix: ${{ toJSON(matrix) }} + - name: Create local release-candidate tag + if: ${{ inputs.build_type == 'release-candidate' }} + env: + RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} + RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} + run: | + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} @@ -300,7 +314,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index c58f7cd9..e188107e 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -48,6 +48,10 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" + release-candidate-tag: + description: "Final source tag created locally for a release-candidate build; it is never pushed." + type: string + default: "" matrix_filter: description: | jq expression which modifies the matrix. @@ -172,6 +176,7 @@ jobs: # Candidate orchestration retains its own input mode, while RAPIDS # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -196,6 +201,15 @@ jobs: cache-environment: ${{ inputs.cache-environment }} cache-read-only: ${{ inputs.cache-read-only }} matrix: ${{ toJSON(matrix) }} + - name: Create local release-candidate tag + if: ${{ inputs.build_type == 'release-candidate' }} + env: + RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} + RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} + run: | + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} @@ -305,7 +319,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index a98ef98f..46f79585 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -117,6 +117,10 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" + release-candidate-tag: + description: "Final source tag created locally for a release-candidate build; it is never pushed." + type: string + default: "" defaults: run: @@ -153,6 +157,7 @@ jobs: # Candidate orchestration retains its own input mode, while RAPIDS # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -166,6 +171,15 @@ jobs: ref: ${{ inputs.sha }} fetch-depth: 0 persist-credentials: true + - name: Create local release-candidate tag + if: ${{ inputs.build_type == 'release-candidate' }} + env: + RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} + RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} + run: | + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Telemetry setup uses: rapidsai/shared-actions/telemetry-dispatch-setup@main continue-on-error: true @@ -257,7 +271,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 65459b81..e201d608 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -79,6 +79,10 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" + release-candidate-tag: + description: "Final source tag created locally for a release-candidate build; it is never pushed." + type: string + default: "" extra-repo: required: false type: string @@ -202,6 +206,7 @@ jobs: # Candidate orchestration retains its own input mode, while RAPIDS # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -229,6 +234,15 @@ jobs: cache-environment: ${{ inputs.cache-environment }} cache-read-only: ${{ inputs.cache-read-only }} matrix: ${{ toJSON(matrix) }} + - name: Create local release-candidate tag + if: ${{ inputs.build_type == 'release-candidate' }} + env: + RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} + RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} + run: | + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Standardize repository information uses: rapidsai/shared-actions/rapids-github-info@main @@ -372,7 +386,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@f2e2c3621f5fc8b77b3c0dc669d60f817b1d05eb # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head with: config: >- { From 902fd5a7e85fd17d8d9d10842133cbbd3f3bee37 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 17:13:25 -0500 Subject: [PATCH 23/31] fix: mark candidate builds as releases --- .github/workflows/conda-cpp-build.yaml | 1 + .github/workflows/conda-python-build.yaml | 1 + .github/workflows/custom-job.yaml | 1 + .github/workflows/wheels-build.yaml | 1 + 4 files changed, 4 insertions(+) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 0ec4834c..8ba54e0e 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -167,6 +167,7 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} + GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index e188107e..6b1af22e 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -177,6 +177,7 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} + GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 46f79585..44d20cf6 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -158,6 +158,7 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} + GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index e201d608..7dd27a32 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -207,6 +207,7 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} + GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 From 813a57f3e95cec9d78bb46b0bbff518078e09887 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Fri, 21 Aug 2026 17:18:37 -0500 Subject: [PATCH 24/31] fix: force local release candidate context --- .github/workflows/conda-cpp-build.yaml | 15 +++++++++++---- .github/workflows/conda-python-build.yaml | 15 +++++++++++---- .github/workflows/custom-job.yaml | 9 ++++++++- .github/workflows/wheels-build.yaml | 15 +++++++++++---- 4 files changed, 41 insertions(+), 13 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 8ba54e0e..ec222cc8 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -167,7 +167,6 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} - GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -198,9 +197,17 @@ jobs: RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git remote set-url --push origin no_push + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + - name: Force local release-candidate build context + if: ${{ inputs.build_type == 'release-candidate' }} + run: | + mkdir -p "${RUNNER_TEMP}/release-candidate-tools" + printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 6b1af22e..09cae8a8 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -177,7 +177,6 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} - GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -208,9 +207,17 @@ jobs: RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git remote set-url --push origin no_push + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + - name: Force local release-candidate build context + if: ${{ inputs.build_type == 'release-candidate' }} + run: | + mkdir -p "${RUNNER_TEMP}/release-candidate-tools" + printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 44d20cf6..7af91c0c 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -158,7 +158,6 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} - GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -180,7 +179,15 @@ jobs: run: | test -n "${RELEASE_CANDIDATE_TAG}" git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git remote set-url --push origin no_push git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + - name: Force local release-candidate build context + if: ${{ inputs.build_type == 'release-candidate' }} + run: | + mkdir -p "${RUNNER_TEMP}/release-candidate-tools" + printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Telemetry setup uses: rapidsai/shared-actions/telemetry-dispatch-setup@main continue-on-error: true diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 7dd27a32..312f0a06 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -207,7 +207,6 @@ jobs: # build helpers use the established nightly dependency behavior. RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} - GITHUB_REF: ${{ inputs.build_type == 'release-candidate' && format('refs/tags/{0}', inputs.release-candidate-tag) || github.ref }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -241,9 +240,17 @@ jobs: RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + test -n "${RELEASE_CANDIDATE_TAG}" + git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" + git remote set-url --push origin no_push + git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" + - name: Force local release-candidate build context + if: ${{ inputs.build_type == 'release-candidate' }} + run: | + mkdir -p "${RUNNER_TEMP}/release-candidate-tools" + printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" + echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Standardize repository information uses: rapidsai/shared-actions/rapids-github-info@main From 92a9114d0416016115e46a202166e5be5e827f4e Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Mon, 24 Aug 2026 11:05:15 -0500 Subject: [PATCH 25/31] ci: skip public publication for release candidates --- .github/workflows/conda-upload-packages.yaml | 5 ++++- .github/workflows/wheels-publish.yaml | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/workflows/conda-upload-packages.yaml b/.github/workflows/conda-upload-packages.yaml index 72af0686..db22641e 100644 --- a/.github/workflows/conda-upload-packages.yaml +++ b/.github/workflows/conda-upload-packages.yaml @@ -2,7 +2,7 @@ on: workflow_call: inputs: build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string branch: @@ -71,6 +71,9 @@ permissions: jobs: upload: + # Candidate artifacts are staged privately by the build workflow. They must + # not enter either public Anaconda.org channel before rollover approval. + if: ${{ inputs.build_type != 'release-candidate' }} runs-on: linux-amd64-cpu4 container: image: "python:3.14-slim" diff --git a/.github/workflows/wheels-publish.yaml b/.github/workflows/wheels-publish.yaml index 7c282759..01bdc752 100644 --- a/.github/workflows/wheels-publish.yaml +++ b/.github/workflows/wheels-publish.yaml @@ -18,7 +18,7 @@ on: description: "Git repo to check out, in '{org}/{repo}' form, e.g. 'rapidsai/cudf'" type: string build_type: - description: "One of: [branch, nightly, pull-request]" + description: "One of: [branch, nightly, pull-request, release-candidate]" required: true type: string @@ -73,6 +73,9 @@ permissions: jobs: wheel-publish: name: wheels publish + # Candidate artifacts are staged privately by the build workflow. They must + # not enter public Anaconda.org or PyPI channels before rollover approval. + if: ${{ inputs.build_type != 'release-candidate' }} # Use a self-hosted runner to ensure we have sufficient disk space. Using # cpu8 since we shouldn't need much CPU horsepower. runs-on: "linux-amd64-cpu8" From 179c09c9435ed25cf1fcfab35fadf81aa4c906db Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Wed, 2 Sep 2026 09:25:45 -0500 Subject: [PATCH 26/31] Adopt explicit release catalog inputs --- .github/workflows/conda-cpp-build.yaml | 3 ++- .github/workflows/conda-python-build.yaml | 3 ++- .github/workflows/custom-job.yaml | 3 ++- .github/workflows/wheels-build.yaml | 3 ++- 4 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index ec222cc8..5c6022ff 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -322,7 +322,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head with: config: >- { @@ -330,6 +330,7 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + source-sha: ${{ env.RAPIDS_SHA }} candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} upload-to-s3: 'true' - name: Upload additional artifacts diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 09cae8a8..35c03f28 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -327,7 +327,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head with: config: >- { @@ -335,6 +335,7 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.CONDA_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + source-sha: ${{ env.RAPIDS_SHA }} candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} upload-to-s3: 'true' - name: Upload additional artifacts diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 7af91c0c..3b683acb 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -279,10 +279,11 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} + source-sha: ${{ env.RAPIDS_SHA }} candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} upload-to-s3: 'true' - name: Upload additional artifacts diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 312f0a06..dfcb4e6f 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -394,7 +394,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog-dispatch@079aafb321c9a87d5741a79234d65ad30f1e9bb0 # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head with: config: >- { @@ -402,6 +402,7 @@ jobs: "artifact_directory": ${{ toJSON(steps.package-name.outputs.WHEEL_OUTPUT_DIR) }} } source-artifact-name: ${{ steps.package-name.outputs.RAPIDS_PACKAGE_NAME }} + source-sha: ${{ env.RAPIDS_SHA }} candidate-train-sha256: ${{ inputs.candidate-train-sha256 }} upload-to-s3: 'true' From 5878c2483096c111ecad0fe575d11369bec2055e Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Wed, 2 Sep 2026 09:49:34 -0500 Subject: [PATCH 27/31] Refresh release catalog action pin --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 5c6022ff..beda50ae 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -322,7 +322,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 35c03f28..a8f77f15 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -327,7 +327,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 3b683acb..77e86d36 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -279,7 +279,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index dfcb4e6f..4b075a2b 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -394,7 +394,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@29f75dfc370ce05ecd5226538ca3fb47f263bc0c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head with: config: >- { From 9245f108085f9f19a06ce6116df9286506676056 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Wed, 2 Sep 2026 09:59:21 -0500 Subject: [PATCH 28/31] Refresh release catalog action pin --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index beda50ae..301a94fe 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -322,7 +322,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index a8f77f15..4679e3ee 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -327,7 +327,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 77e86d36..d3ce39f4 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -279,7 +279,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 4b075a2b..7652daac 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -394,7 +394,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@5008d0689cd66ec2f4911b12cdb731ea54b8acec # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head with: config: >- { From bc3faea6b1786b3a3392c0aacd05533a9c1e5064 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Wed, 2 Sep 2026 12:13:02 -0500 Subject: [PATCH 29/31] Make release candidate a first-class build mode --- .github/workflows/conda-cpp-build.yaml | 11 +---------- .github/workflows/conda-python-build.yaml | 11 +---------- .github/workflows/custom-job.yaml | 11 +---------- .github/workflows/wheels-build.yaml | 12 +----------- 4 files changed, 4 insertions(+), 41 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 301a94fe..83e9228e 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -163,9 +163,7 @@ jobs: container: image: rapidsai/ci-conda:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }} env: - # Candidate orchestration retains its own input mode, while RAPIDS - # build helpers use the established nightly dependency behavior. - RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: @@ -201,13 +199,6 @@ jobs: git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" git remote set-url --push origin no_push git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - - name: Force local release-candidate build context - if: ${{ inputs.build_type == 'release-candidate' }} - run: | - mkdir -p "${RUNNER_TEMP}/release-candidate-tools" - printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 4679e3ee..18fcbbd0 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -173,9 +173,7 @@ jobs: container: image: rapidsai/ci-conda:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }} env: - # Candidate orchestration retains its own input mode, while RAPIDS - # build helpers use the established nightly dependency behavior. - RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: @@ -211,13 +209,6 @@ jobs: git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" git remote set-url --push origin no_push git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - - name: Force local release-candidate build context - if: ${{ inputs.build_type == 'release-candidate' }} - run: | - mkdir -p "${RUNNER_TEMP}/release-candidate-tools" - printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index d3ce39f4..22ca343e 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -154,9 +154,7 @@ jobs: options: ${{ inputs.container-options }} env: NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }} - # Candidate orchestration retains its own input mode, while RAPIDS - # build helpers use the established nightly dependency behavior. - RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: @@ -181,13 +179,6 @@ jobs: git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" git remote set-url --push origin no_push git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - - name: Force local release-candidate build context - if: ${{ inputs.build_type == 'release-candidate' }} - run: | - mkdir -p "${RUNNER_TEMP}/release-candidate-tools" - printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - name: Telemetry setup uses: rapidsai/shared-actions/telemetry-dispatch-setup@main continue-on-error: true diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 7652daac..705152f3 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -203,9 +203,7 @@ jobs: container: image: "rapidsai/ci-wheel:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }}" env: - # Candidate orchestration retains its own input mode, while RAPIDS - # build helpers use the established nightly dependency behavior. - RAPIDS_BUILD_TYPE: ${{ inputs.build_type == 'release-candidate' && 'nightly' || inputs.build_type }} + RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: @@ -244,14 +242,6 @@ jobs: git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" git remote set-url --push origin no_push git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - - name: Force local release-candidate build context - if: ${{ inputs.build_type == 'release-candidate' }} - run: | - mkdir -p "${RUNNER_TEMP}/release-candidate-tools" - printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - chmod +x "${RUNNER_TEMP}/release-candidate-tools/rapids-is-release-build" - echo "${RUNNER_TEMP}/release-candidate-tools" >> "${GITHUB_PATH}" - - name: Standardize repository information uses: rapidsai/shared-actions/rapids-github-info@main with: From 86689f7252c05f65cb31414fb4e4c3c5474db7a2 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 22 Sep 2026 11:20:58 -0500 Subject: [PATCH 30/31] Pin release catalog action to merged revision --- .github/workflows/conda-cpp-build.yaml | 2 +- .github/workflows/conda-python-build.yaml | 2 +- .github/workflows/custom-job.yaml | 2 +- .github/workflows/wheels-build.yaml | 2 +- 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 83e9228e..5b389011 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -313,7 +313,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@4f580aef2a239f6c7b44f98ef526ae83b7543c78 # shared-actions PR 136 merged with: config: >- { diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index 18fcbbd0..ec36b4f3 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -318,7 +318,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create Conda release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@4f580aef2a239f6c7b44f98ef526ae83b7543c78 # shared-actions PR 136 merged with: config: >- { diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index 22ca343e..b0a16f29 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -270,7 +270,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create release catalog companion if: ${{ inputs.build_type == 'release-candidate' && inputs.release-catalog-config != '' }} - uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@4f580aef2a239f6c7b44f98ef526ae83b7543c78 # shared-actions PR 136 merged with: config: ${{ inputs.release-catalog-config }} source-artifact-name: ${{ inputs.artifact-name }} diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index 705152f3..a011b110 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -384,7 +384,7 @@ jobs: role-to-assume: arn:aws:iam::279114543810:role/gha-oidc-rapids-release-candidates - name: Create wheel release catalog companion if: ${{ inputs.build_type == 'release-candidate' }} - uses: rapidsai/shared-actions/release-catalog@2bd36f0db6c8c553a14e8886ea62ce7b908c6a2c # shared-actions PR 136 candidate-store head + uses: rapidsai/shared-actions/release-catalog@4f580aef2a239f6c7b44f98ef526ae83b7543c78 # shared-actions PR 136 merged with: config: >- { From 5af0185b3787eab3e9ed32ba3d7892f11ed41ff8 Mon Sep 17 00:00:00 2001 From: Michael Sarahan Date: Tue, 22 Sep 2026 15:42:56 -0500 Subject: [PATCH 31/31] refactor: derive release candidate versions from source --- .github/workflows/conda-cpp-build.yaml | 15 --------------- .github/workflows/conda-python-build.yaml | 15 --------------- .github/workflows/custom-job.yaml | 15 --------------- .github/workflows/wheels-build.yaml | 15 --------------- 4 files changed, 60 deletions(-) diff --git a/.github/workflows/conda-cpp-build.yaml b/.github/workflows/conda-cpp-build.yaml index 5b389011..eb5cccd3 100644 --- a/.github/workflows/conda-cpp-build.yaml +++ b/.github/workflows/conda-cpp-build.yaml @@ -48,10 +48,6 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" - release-candidate-tag: - description: "Final source tag created locally for a release-candidate build; it is never pushed." - type: string - default: "" matrix_filter: description: | jq expression which modifies the matrix. @@ -164,7 +160,6 @@ jobs: image: rapidsai/ci-conda:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }} env: RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} - RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -189,16 +184,6 @@ jobs: cache-environment: ${{ inputs.cache-environment }} cache-read-only: ${{ inputs.cache-read-only }} matrix: ${{ toJSON(matrix) }} - - name: Create local release-candidate tag - if: ${{ inputs.build_type == 'release-candidate' }} - env: - RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} - RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} - run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git remote set-url --push origin no_push - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} diff --git a/.github/workflows/conda-python-build.yaml b/.github/workflows/conda-python-build.yaml index ec36b4f3..ad4bf0fb 100644 --- a/.github/workflows/conda-python-build.yaml +++ b/.github/workflows/conda-python-build.yaml @@ -48,10 +48,6 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" - release-candidate-tag: - description: "Final source tag created locally for a release-candidate build; it is never pushed." - type: string - default: "" matrix_filter: description: | jq expression which modifies the matrix. @@ -174,7 +170,6 @@ jobs: image: rapidsai/ci-conda:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }} env: RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} - RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -199,16 +194,6 @@ jobs: cache-environment: ${{ inputs.cache-environment }} cache-read-only: ${{ inputs.cache-read-only }} matrix: ${{ toJSON(matrix) }} - - name: Create local release-candidate tag - if: ${{ inputs.build_type == 'release-candidate' }} - env: - RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} - RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} - run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git remote set-url --push origin no_push - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Standardize repository information env: RAPIDS_REPOSITORY: ${{ inputs.repo || github.repository }} diff --git a/.github/workflows/custom-job.yaml b/.github/workflows/custom-job.yaml index b0a16f29..3e249c01 100644 --- a/.github/workflows/custom-job.yaml +++ b/.github/workflows/custom-job.yaml @@ -117,10 +117,6 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" - release-candidate-tag: - description: "Final source tag created locally for a release-candidate build; it is never pushed." - type: string - default: "" defaults: run: @@ -155,7 +151,6 @@ jobs: env: NVIDIA_VISIBLE_DEVICES: ${{ env.NVIDIA_VISIBLE_DEVICES }} RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} - RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -169,16 +164,6 @@ jobs: ref: ${{ inputs.sha }} fetch-depth: 0 persist-credentials: true - - name: Create local release-candidate tag - if: ${{ inputs.build_type == 'release-candidate' }} - env: - RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} - RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} - run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git remote set-url --push origin no_push - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Telemetry setup uses: rapidsai/shared-actions/telemetry-dispatch-setup@main continue-on-error: true diff --git a/.github/workflows/wheels-build.yaml b/.github/workflows/wheels-build.yaml index a011b110..c09f7d91 100644 --- a/.github/workflows/wheels-build.yaml +++ b/.github/workflows/wheels-build.yaml @@ -79,10 +79,6 @@ on: description: "Canonical SHA-256 of the release train; required for release-candidate builds." type: string default: "" - release-candidate-tag: - description: "Final source tag created locally for a release-candidate build; it is never pushed." - type: string - default: "" extra-repo: required: false type: string @@ -204,7 +200,6 @@ jobs: image: "rapidsai/ci-wheel:26.12-cuda${{ matrix.CUDA_VER }}-${{ matrix.LINUX_VER }}-py${{ matrix.PY_VER }}" env: RAPIDS_BUILD_TYPE: ${{ inputs.build_type }} - RAPIDS_RELEASE_CANDIDATE: ${{ inputs.build_type == 'release-candidate' }} RAPIDS_DATETIME_STRING: ${{ inputs.build-datetime }} steps: - uses: aws-actions/configure-aws-credentials@517a711dbcd0e402f90c77e7e2f81e849156e31d # v6.2.2 @@ -232,16 +227,6 @@ jobs: cache-environment: ${{ inputs.cache-environment }} cache-read-only: ${{ inputs.cache-read-only }} matrix: ${{ toJSON(matrix) }} - - name: Create local release-candidate tag - if: ${{ inputs.build_type == 'release-candidate' }} - env: - RELEASE_CANDIDATE_TAG: ${{ inputs.release-candidate-tag }} - RELEASE_CANDIDATE_SHA: ${{ inputs.sha }} - run: | - test -n "${RELEASE_CANDIDATE_TAG}" - git tag --force "${RELEASE_CANDIDATE_TAG}" "${RELEASE_CANDIDATE_SHA}" - git remote set-url --push origin no_push - git show-ref --verify --quiet "refs/tags/${RELEASE_CANDIDATE_TAG}" - name: Standardize repository information uses: rapidsai/shared-actions/rapids-github-info@main with: