name: release on: push: tags: - "v*" workflow_dispatch: inputs: tag: description: "Tag to release (e.g. v0.0.1-rc1). Must already exist." required: true type: string permissions: contents: read concurrency: group: release-${{ github.ref }} cancel-in-progress: false jobs: resolve-tag: name: Resolve and validate the tag runs-on: ubuntu-latest permissions: {} outputs: tag: ${{ steps.tag.outputs.tag }} version: ${{ steps.tag.outputs.version }} steps: # A refname is attacker-controlled text and git permits backtick, `$`, # `(`, `;`, `&` and `|` in it, so it goes through env: a `${{ }}` is # substituted before bash ever sees the line. Every later job reads these # outputs rather than the refname, and nothing reaches a shell before it # has matched the pattern. The pattern is anchored and admits no newline, # which is what stops the value below forging a second $GITHUB_OUTPUT key. - name: Validate the tag id: tag run: | pattern='^v[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z]+(\.[0-9A-Za-z]+)*)?$' if [[ ! "$TAG" =~ $pattern ]]; then echo "release: refusing to publish from '$TAG'" >&2 echo "release: a release tag is vMAJOR.MINOR.PATCH with an optional -prerelease, e.g. v0.1.0 or v0.0.1-rc1" >&2 exit 1 fi echo "tag=$TAG" >> "$GITHUB_OUTPUT" echo "version=${TAG#v}" >> "$GITHUB_OUTPUT" env: TAG: ${{ inputs.tag || github.ref_name }} release-npm: name: Publish @sanderling/spec to npm needs: resolve-tag runs-on: ubuntu-latest permissions: contents: read steps: - uses: actions/checkout@v7 with: ref: ${{ needs.resolve-tag.outputs.tag }} # `npm ci` below runs dependency lifecycle scripts, and no step in # this job needs the git credential afterwards. persist-credentials: false - name: Set up Node 22 uses: actions/setup-node@v7 with: node-version: "22" registry-url: "https://registry.npmjs.org" cache: npm cache-dependency-path: pkg/spec/package-lock.json - name: Install dependencies working-directory: pkg/spec run: npm ci - name: Stamp version working-directory: pkg/spec run: npm version "$VERSION" --no-git-tag-version --allow-same-version env: VERSION: ${{ needs.resolve-tag.outputs.version }} - name: Publish working-directory: pkg/spec # npm tag pre-releases (e.g. 0.1.0-rc1) as "next" so npm install @sanderling/spec # keeps resolving the latest stable. run: | if [[ "$VERSION" == *-* ]]; then npm publish --access public --tag next else npm publish --access public fi # The publish credential is scoped to the one step that publishes rather # than to the job, so no other step runs with it in reach. env: VERSION: ${{ needs.resolve-tag.outputs.version }} NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} release-cli: name: Publish sanderling CLI to GitHub Releases needs: resolve-tag runs-on: ubuntu-latest permissions: contents: write steps: - uses: actions/checkout@v7 with: ref: ${{ needs.resolve-tag.outputs.tag }} fetch-depth: 0 - name: Set up Go uses: actions/setup-go@v7 with: go-version-file: go.mod cache: true - name: Set up JDK 17 uses: actions/setup-java@v5 with: distribution: temurin java-version: "17" - name: Set up Android SDK uses: android-actions/setup-android@40fd30fb8d7440372e1316f5d1809ec01dcd3699 # v4.0.1 - name: Cache Gradle uses: actions/cache@v6 with: path: | ~/.gradle/caches ~/.gradle/wrapper key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }} restore-keys: | gradle-${{ runner.os }}- - name: Build sidecar JAR run: make sidecar - name: Run GoReleaser uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 with: version: "~> v2" args: release --clean env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}