Repository navigation
78 lines (78 loc) · 2.96 KB
/
Copy pathrelease.yml
File metadata and controls
78 lines (78 loc) · 2.96 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
name: Release
on:
workflow_dispatch:
inputs:
run_id:
description: Successful CI run ID for the main commit or selected release tag
required: true
type: string
release_tag:
description: Existing GitHub release tag to promote unchanged (optional)
required: false
type: string
permissions:
contents: read
concurrency:
group: rubygems-release
cancel-in-progress: false
jobs:
publish:
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-24.04
timeout-minutes: 15
environment: rubygems
permissions:
contents: read
actions: read
id-token: write
attestations: write
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6
with:
persist-credentials: false
- uses: ruby/setup-ruby@a0102e0972be65f351c307e2d64b9314a57c8073 # v1
with:
ruby-version: '3.3'
- name: Verify tested commit
env:
GH_TOKEN: ${{ github.token }}
RUN_ID: ${{ inputs.run_id }}
RELEASE_TAG: ${{ inputs.release_tag }}
run: |
[[ "$RUN_ID" =~ ^[0-9]+$ ]]
gh api "repos/$GITHUB_REPOSITORY/actions/runs/$RUN_ID" > /tmp/forme-ci-run.json
if [[ -n "$RELEASE_TAG" ]]; then
[[ "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]
gh release view "$RELEASE_TAG" --json isDraft,isPrerelease > /tmp/forme-release.json
ruby -rjson -e 'r = JSON.parse(File.read(ARGV[0])); abort "Require a published stable release" if r.fetch("isDraft") || r.fetch("isPrerelease")' /tmp/forme-release.json
RELEASE_SHA=$(gh api "repos/$GITHUB_REPOSITORY/commits/$RELEASE_TAG" --jq .sha)
GITHUB_SHA="$RELEASE_SHA" ruby script/ci/verify-run.rb /tmp/forme-ci-run.json
else
ruby script/ci/verify-run.rb /tmp/forme-ci-run.json
fi
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
github-token: ${{ github.token }}
run-id: ${{ inputs.run_id }}
pattern: gems-*
path: pkg
merge-multiple: true
- run: ruby script/ci/verify-release.rb
- name: Match published GitHub packages
if: inputs.release_tag != ''
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ inputs.release_tag }}
run: |
gh release download "$RELEASE_TAG" --pattern '*.gem' --dir /tmp/github-release
for gem_file in pkg/*.gem; do
cmp "$gem_file" "/tmp/github-release/$(basename "$gem_file")"
done
- name: Attest tested packages
uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3
with:
subject-path: pkg/*.gem
- uses: rubygems/configure-rubygems-credentials@dc5a8d8553e6ee01fc26761a49e99e733d17954a
- name: Publish validated packages
run: |
for gem_file in pkg/*.gem; do gem push "$gem_file"; done