mirror of
https://github.com/saymrwulf/anza-cryptography-source.git
synced 2026-09-04 20:24:04 +00:00
ci: update release pipeline (#15)
This commit is contained in:
parent
09198923bb
commit
3a141c3fe3
2 changed files with 138 additions and 216 deletions
216
.github/workflows/publish-rust.yml
vendored
216
.github/workflows/publish-rust.yml
vendored
|
|
@ -1,216 +0,0 @@
|
|||
name: Publish Crate
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
package_path:
|
||||
description: Path to directory with package to release
|
||||
required: true
|
||||
type: string
|
||||
level:
|
||||
description: Level
|
||||
required: true
|
||||
default: patch
|
||||
type: choice
|
||||
options:
|
||||
- patch
|
||||
- minor
|
||||
- major
|
||||
- version
|
||||
version:
|
||||
description: Version (used with level "version")
|
||||
required: false
|
||||
type: string
|
||||
dry_run:
|
||||
description: Dry run
|
||||
required: true
|
||||
default: true
|
||||
type: boolean
|
||||
create_release:
|
||||
description: Create a GitHub release
|
||||
required: true
|
||||
type: boolean
|
||||
default: true
|
||||
dependent_version:
|
||||
description: |
|
||||
How workspace dependencies should be handled.
|
||||
- "fix": (Default) Only bumps the workspace for semver-breakage - prefer this option
|
||||
- "upgrade": Bumps workspace version regardless - only use if another crate requires new code
|
||||
required: true
|
||||
default: fix
|
||||
type: choice
|
||||
options:
|
||||
- fix
|
||||
- upgrade
|
||||
run_semver:
|
||||
description: |
|
||||
Run semver checks.
|
||||
Only disable checks if you are sure of the semver impact of your change and have a good reason
|
||||
to skip it.
|
||||
required: true
|
||||
type: boolean
|
||||
default: true
|
||||
|
||||
jobs:
|
||||
format:
|
||||
name: Format
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Git Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install Rust
|
||||
uses: dtolnay/rust-toolchain@nightly
|
||||
with:
|
||||
components: rustfmt
|
||||
|
||||
- name: Cache
|
||||
uses: Swatinem/rust-cache@v2
|
||||
|
||||
- name: Check formatting
|
||||
run: cargo fmt --all -- --check
|
||||
|
||||
clippy:
|
||||
name: Clippy
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Git Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
with:
|
||||
components: clippy
|
||||
|
||||
- name: Cache
|
||||
uses: Swatinem/rust-cache@v2
|
||||
|
||||
- name: Run clippy
|
||||
run: cargo clippy --workspace --all-targets -- -D warnings
|
||||
|
||||
semver:
|
||||
name: Check Semver
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Git checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Install Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Cache
|
||||
uses: Swatinem/rust-cache@v2
|
||||
|
||||
- name: Install tools
|
||||
uses: taiki-e/install-action@v2
|
||||
with:
|
||||
tool: toml-cli,cargo-semver-checks,cargo-release
|
||||
|
||||
- name: Check if crate is a procedural macro
|
||||
id: is_proc_macro
|
||||
shell: bash
|
||||
run: |
|
||||
set +e # toml crashes the whole shell if it fails to find the key
|
||||
result=$(toml get "${{ inputs.package_path }}/Cargo.toml" lib.proc-macro)
|
||||
if [[ "$result" == *"true"* ]]; then
|
||||
echo "is_proc_macro=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "is_proc_macro=false" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
- name: Set Git Author (required for cargo-release)
|
||||
if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' }}
|
||||
run: |
|
||||
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
||||
git config --global user.name "github-actions[bot]"
|
||||
|
||||
- name: Set Version
|
||||
if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' }}
|
||||
run: |
|
||||
if [ "${{ inputs.level }}" == "version" ]; then
|
||||
LEVEL=${{ inputs.version }}
|
||||
else
|
||||
LEVEL=${{ inputs.level }}
|
||||
fi
|
||||
cargo release $LEVEL --manifest-path "${{ inputs.package_path }}/Cargo.toml" --no-tag --no-publish --no-push --no-confirm --execute
|
||||
|
||||
- name: Check semver
|
||||
if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' && github.event.inputs.run_semver == 'true'}}
|
||||
run: cargo semver-checks --manifest-path "${{ inputs.package_path }}/Cargo.toml"
|
||||
|
||||
publish-crate:
|
||||
name: Publish crate
|
||||
runs-on: ubuntu-latest
|
||||
needs: [format, clippy, semver]
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- name: Git Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
token: ${{ secrets.ANZA_TEAM_PAT }}
|
||||
fetch-depth: 0 # get the whole history for git-cliff
|
||||
|
||||
- name: Install Rust
|
||||
uses: dtolnay/rust-toolchain@stable
|
||||
|
||||
- name: Cache
|
||||
uses: Swatinem/rust-cache@v2
|
||||
|
||||
- name: Install cargo-release
|
||||
uses: taiki-e/install-action@v2
|
||||
with:
|
||||
tool: cargo-release
|
||||
|
||||
- name: Ensure CARGO_REGISTRY_TOKEN variable is set
|
||||
env:
|
||||
token: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
||||
if: ${{ env.token == '' }}
|
||||
run: |
|
||||
echo "The CARGO_REGISTRY_TOKEN secret variable is not set"
|
||||
echo "Go to \"Settings\" -> \"Secrets and variables\" -> \"Actions\" -> \"New repository secret\"."
|
||||
exit 1
|
||||
|
||||
- name: Set Git Author
|
||||
run: |
|
||||
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
||||
git config --global user.name "github-actions[bot]"
|
||||
|
||||
- name: Rebase (in case any changes landed after)
|
||||
run: git pull --rebase origin
|
||||
|
||||
- name: Publish Crate
|
||||
id: publish
|
||||
env:
|
||||
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
||||
run: |
|
||||
if [ "${{ inputs.level }}" == "version" ]; then
|
||||
LEVEL=${{ inputs.version }}
|
||||
else
|
||||
LEVEL=${{ inputs.level }}
|
||||
fi
|
||||
|
||||
if [ "${{ inputs.dry_run }}" == "true" ]; then
|
||||
OPTIONS="--dry-run"
|
||||
else
|
||||
OPTIONS=""
|
||||
fi
|
||||
|
||||
./scripts/publish-rust.sh "${{ inputs.package_path }}" $LEVEL "${{ inputs.dependent_version }}" $OPTIONS
|
||||
|
||||
- name: Generate a changelog
|
||||
if: github.event.inputs.create_release == 'true'
|
||||
uses: orhun/git-cliff-action@v4
|
||||
with:
|
||||
config: "scripts/cliff.toml"
|
||||
args: ${{ steps.publish.outputs.old_git_tag }}..HEAD --include-path "${{ inputs.package_path }}/**" --github-repo ${{ github.repository }}
|
||||
env:
|
||||
OUTPUT: TEMP_CHANGELOG.md
|
||||
GITHUB_REPO: ${{ github.repository }}
|
||||
|
||||
- name: Create GitHub release
|
||||
if: github.event.inputs.create_release == 'true' && github.event.inputs.dry_run != 'true'
|
||||
uses: ncipollo/release-action@v1
|
||||
with:
|
||||
tag: ${{ steps.publish.outputs.new_git_tag }}
|
||||
bodyFile: TEMP_CHANGELOG.md
|
||||
138
.github/workflows/release.yml
vendored
Normal file
138
.github/workflows/release.yml
vendored
Normal file
|
|
@ -0,0 +1,138 @@
|
|||
name: Release
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
crate:
|
||||
description: "Crate to release"
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- ""
|
||||
- solana-curve25519-cuda
|
||||
- solana-ed25519
|
||||
- ed25519-pokos
|
||||
- solana-bls12-381-syscall
|
||||
ref:
|
||||
description: "git ref to tag (can be a branch or a commit hash)"
|
||||
required: true
|
||||
default: "master"
|
||||
type: string
|
||||
|
||||
jobs:
|
||||
check:
|
||||
runs-on: ubuntu-latest
|
||||
outputs:
|
||||
tag: ${{ steps.meta.outputs.tag }}
|
||||
ref: ${{ steps.meta.outputs.ref }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
ref: ${{ inputs.ref }}
|
||||
persist-credentials: false
|
||||
|
||||
- name: Compute metadata
|
||||
id: meta
|
||||
run: |
|
||||
|
||||
version="$(cargo metadata --format-version 1 --no-deps | jq -r '.packages[] | select(.name == "'"${CRATE_NAME}"'") | .version')"
|
||||
if [ -z "${version}" ] || [ "${version}" = "null" ]; then
|
||||
echo "Could not resolve version for crate: ${CRATE_NAME}"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
tag="${CRATE_NAME}@v${version}"
|
||||
ref="$(git rev-parse HEAD)"
|
||||
|
||||
echo "tag=${tag}" >> "${GITHUB_OUTPUT}"
|
||||
echo "ref=${ref}" >> "${GITHUB_OUTPUT}"
|
||||
env:
|
||||
CRATE_NAME: ${{ inputs.crate }}
|
||||
|
||||
- name: Check tag does not exist
|
||||
run: |
|
||||
echo "checking: refs/tags/${TAG}"
|
||||
if git ls-remote --exit-code --tags origin "refs/tags/${TAG}" >/dev/null 2>&1; then
|
||||
echo "Tag already exists: ${TAG}. Please bump the version first (or delete the existing tag) and retry."
|
||||
echo "Tag exists: ${TAG}" >> "${GITHUB_STEP_SUMMARY}"
|
||||
exit 1
|
||||
fi
|
||||
env:
|
||||
TAG: ${{ steps.meta.outputs.tag }}
|
||||
|
||||
- name: Cargo publish dry run
|
||||
run: |
|
||||
cargo publish -p "${CRATE_NAME}" --dry-run
|
||||
env:
|
||||
CRATE_NAME: ${{ inputs.crate }}
|
||||
|
||||
- name: Summary
|
||||
run: |
|
||||
echo "Tag: ${TAG}" >> "${GITHUB_STEP_SUMMARY}"
|
||||
echo "Ref: ${REF} (https://github.com/${{ github.repository }}/commit/${REF})" >> "${GITHUB_STEP_SUMMARY}"
|
||||
env:
|
||||
TAG: ${{ steps.meta.outputs.tag }}
|
||||
REF: ${{ steps.meta.outputs.ref }}
|
||||
|
||||
publish:
|
||||
runs-on: ubuntu-latest
|
||||
environment: prod
|
||||
needs: check
|
||||
permissions:
|
||||
id-token: write
|
||||
contents: write
|
||||
attestations: write
|
||||
artifact-metadata: write
|
||||
steps:
|
||||
- uses: actions/create-github-app-token@v3
|
||||
id: app-token
|
||||
with:
|
||||
app-id: ${{ vars.APP_ID }}
|
||||
private-key: ${{ secrets.PRIVATE_KEY }}
|
||||
|
||||
- name: Set git config
|
||||
run: |
|
||||
git config --global user.email "${APP_ID}+${APP_SLUG}[bot]@users.noreply.github.com"
|
||||
git config --global user.name "${APP_SLUG}[bot]"
|
||||
git config --global url."https://x-access-token:${GITHUB_TOKEN}@github.com/".insteadOf https://github.com/
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||
APP_ID: ${{ vars.APP_ID }}
|
||||
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
|
||||
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
token: ${{ steps.app-token.outputs.token }}
|
||||
persist-credentials: false
|
||||
ref: ${{ needs.check.outputs.ref }}
|
||||
|
||||
- run: |
|
||||
git tag -a "${TAG}" -m "Release ${TAG}"
|
||||
git push --tags
|
||||
env:
|
||||
TAG: ${{ needs.check.outputs.tag }}
|
||||
|
||||
- name: Package crate
|
||||
run: cargo package -p "${CRATE_NAME}"
|
||||
env:
|
||||
CRATE_NAME: ${{ inputs.crate }}
|
||||
|
||||
- name: Generate SLSA provenance
|
||||
uses: actions/attest-build-provenance@v4
|
||||
with:
|
||||
subject-path: target/package/*.crate
|
||||
|
||||
- uses: rust-lang/crates-io-auth-action@v1
|
||||
id: auth
|
||||
|
||||
- run: cargo publish -p "${CRATE_NAME}"
|
||||
env:
|
||||
CRATE_NAME: ${{ inputs.crate }}
|
||||
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
|
||||
|
||||
- name: Create Github Release
|
||||
run: |
|
||||
gh release create "${TAG}" --title "${TAG}" --generate-notes
|
||||
env:
|
||||
TAG: ${{ needs.check.outputs.tag }}
|
||||
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||
Loading…
Reference in a new issue