mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
buf-setup-action was already pinned with a comment saying why; the other five rode mutable major tags, so a tag move is an unreviewed change to what runs. Each major currently resolves to the release named in the comment, so this freezes today's behaviour rather than changing it. actions/* stay on major tags: they are first-party to the runner.
145 lines
4.4 KiB
YAML
145 lines
4.4 KiB
YAML
name: release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: "Tag to release (e.g. v0.0.1-rc1). Must already exist."
|
|
required: true
|
|
type: string
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: release-${{ github.ref }}
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
resolve-tag:
|
|
name: Resolve and validate the tag
|
|
runs-on: ubuntu-latest
|
|
permissions: {}
|
|
outputs:
|
|
tag: ${{ steps.tag.outputs.tag }}
|
|
version: ${{ steps.tag.outputs.version }}
|
|
steps:
|
|
# A refname is attacker-controlled text and git permits backtick, `$`,
|
|
# `(`, `;`, `&` and `|` in it, so it goes through env: a `${{ }}` is
|
|
# substituted before bash ever sees the line. Every later job reads these
|
|
# outputs rather than the refname, and nothing reaches a shell before it
|
|
# has matched the pattern. The pattern is anchored and admits no newline,
|
|
# which is what stops the value below forging a second $GITHUB_OUTPUT key.
|
|
- name: Validate the tag
|
|
id: tag
|
|
run: |
|
|
pattern='^v[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z]+(\.[0-9A-Za-z]+)*)?$'
|
|
if [[ ! "$TAG" =~ $pattern ]]; then
|
|
echo "release: refusing to publish from '$TAG'" >&2
|
|
echo "release: a release tag is vMAJOR.MINOR.PATCH with an optional -prerelease, e.g. v0.1.0 or v0.0.1-rc1" >&2
|
|
exit 1
|
|
fi
|
|
echo "tag=$TAG" >> "$GITHUB_OUTPUT"
|
|
echo "version=${TAG#v}" >> "$GITHUB_OUTPUT"
|
|
env:
|
|
TAG: ${{ inputs.tag || github.ref_name }}
|
|
|
|
release-npm:
|
|
name: Publish @sanderling/spec to npm
|
|
needs: resolve-tag
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
ref: ${{ needs.resolve-tag.outputs.tag }}
|
|
# `npm ci` below runs dependency lifecycle scripts, and no step in
|
|
# this job needs the git credential afterwards.
|
|
persist-credentials: false
|
|
|
|
- name: Set up Node 22
|
|
uses: actions/setup-node@v7
|
|
with:
|
|
node-version: "22"
|
|
registry-url: "https://registry.npmjs.org"
|
|
cache: npm
|
|
cache-dependency-path: pkg/spec/package-lock.json
|
|
|
|
- name: Install dependencies
|
|
working-directory: pkg/spec
|
|
run: npm ci
|
|
|
|
- name: Stamp version
|
|
working-directory: pkg/spec
|
|
run: npm version "$VERSION" --no-git-tag-version --allow-same-version
|
|
env:
|
|
VERSION: ${{ needs.resolve-tag.outputs.version }}
|
|
|
|
- name: Publish
|
|
working-directory: pkg/spec
|
|
# npm tag pre-releases (e.g. 0.1.0-rc1) as "next" so npm install @sanderling/spec
|
|
# keeps resolving the latest stable.
|
|
run: |
|
|
if [[ "$VERSION" == *-* ]]; then
|
|
npm publish --access public --tag next
|
|
else
|
|
npm publish --access public
|
|
fi
|
|
# The publish credential is scoped to the one step that publishes rather
|
|
# than to the job, so no other step runs with it in reach.
|
|
env:
|
|
VERSION: ${{ needs.resolve-tag.outputs.version }}
|
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
|
|
|
release-cli:
|
|
name: Publish sanderling CLI to GitHub Releases
|
|
needs: resolve-tag
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
ref: ${{ needs.resolve-tag.outputs.tag }}
|
|
fetch-depth: 0
|
|
|
|
- name: Set up Go
|
|
uses: actions/setup-go@v7
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
|
|
- name: Set up JDK 17
|
|
uses: actions/setup-java@v5
|
|
with:
|
|
distribution: temurin
|
|
java-version: "17"
|
|
|
|
- name: Set up Android SDK
|
|
uses: android-actions/setup-android@40fd30fb8d7440372e1316f5d1809ec01dcd3699 # v4.0.1
|
|
|
|
- name: Cache Gradle
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: |
|
|
~/.gradle/caches
|
|
~/.gradle/wrapper
|
|
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
|
|
restore-keys: |
|
|
gradle-${{ runner.os }}-
|
|
|
|
- name: Build sidecar JAR
|
|
run: make sidecar
|
|
|
|
- name: Run GoReleaser
|
|
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
|
|
with:
|
|
version: "~> v2"
|
|
args: release --clean
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|