mirror of
https://github.com/saymrwulf/anza-cryptography-source.git
synced 2026-09-06 20:41:07 +00:00
ci: update release pipeline (#15)
This commit is contained in:
parent
09198923bb
commit
3a141c3fe3
2 changed files with 138 additions and 216 deletions
216
.github/workflows/publish-rust.yml
vendored
216
.github/workflows/publish-rust.yml
vendored
|
|
@ -1,216 +0,0 @@
|
||||||
name: Publish Crate
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
inputs:
|
|
||||||
package_path:
|
|
||||||
description: Path to directory with package to release
|
|
||||||
required: true
|
|
||||||
type: string
|
|
||||||
level:
|
|
||||||
description: Level
|
|
||||||
required: true
|
|
||||||
default: patch
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- patch
|
|
||||||
- minor
|
|
||||||
- major
|
|
||||||
- version
|
|
||||||
version:
|
|
||||||
description: Version (used with level "version")
|
|
||||||
required: false
|
|
||||||
type: string
|
|
||||||
dry_run:
|
|
||||||
description: Dry run
|
|
||||||
required: true
|
|
||||||
default: true
|
|
||||||
type: boolean
|
|
||||||
create_release:
|
|
||||||
description: Create a GitHub release
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
dependent_version:
|
|
||||||
description: |
|
|
||||||
How workspace dependencies should be handled.
|
|
||||||
- "fix": (Default) Only bumps the workspace for semver-breakage - prefer this option
|
|
||||||
- "upgrade": Bumps workspace version regardless - only use if another crate requires new code
|
|
||||||
required: true
|
|
||||||
default: fix
|
|
||||||
type: choice
|
|
||||||
options:
|
|
||||||
- fix
|
|
||||||
- upgrade
|
|
||||||
run_semver:
|
|
||||||
description: |
|
|
||||||
Run semver checks.
|
|
||||||
Only disable checks if you are sure of the semver impact of your change and have a good reason
|
|
||||||
to skip it.
|
|
||||||
required: true
|
|
||||||
type: boolean
|
|
||||||
default: true
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
format:
|
|
||||||
name: Format
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Git Checkout
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Install Rust
|
|
||||||
uses: dtolnay/rust-toolchain@nightly
|
|
||||||
with:
|
|
||||||
components: rustfmt
|
|
||||||
|
|
||||||
- name: Cache
|
|
||||||
uses: Swatinem/rust-cache@v2
|
|
||||||
|
|
||||||
- name: Check formatting
|
|
||||||
run: cargo fmt --all -- --check
|
|
||||||
|
|
||||||
clippy:
|
|
||||||
name: Clippy
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Git Checkout
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Install Rust
|
|
||||||
uses: dtolnay/rust-toolchain@stable
|
|
||||||
with:
|
|
||||||
components: clippy
|
|
||||||
|
|
||||||
- name: Cache
|
|
||||||
uses: Swatinem/rust-cache@v2
|
|
||||||
|
|
||||||
- name: Run clippy
|
|
||||||
run: cargo clippy --workspace --all-targets -- -D warnings
|
|
||||||
|
|
||||||
semver:
|
|
||||||
name: Check Semver
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- name: Git checkout
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
|
|
||||||
- name: Install Rust
|
|
||||||
uses: dtolnay/rust-toolchain@stable
|
|
||||||
|
|
||||||
- name: Cache
|
|
||||||
uses: Swatinem/rust-cache@v2
|
|
||||||
|
|
||||||
- name: Install tools
|
|
||||||
uses: taiki-e/install-action@v2
|
|
||||||
with:
|
|
||||||
tool: toml-cli,cargo-semver-checks,cargo-release
|
|
||||||
|
|
||||||
- name: Check if crate is a procedural macro
|
|
||||||
id: is_proc_macro
|
|
||||||
shell: bash
|
|
||||||
run: |
|
|
||||||
set +e # toml crashes the whole shell if it fails to find the key
|
|
||||||
result=$(toml get "${{ inputs.package_path }}/Cargo.toml" lib.proc-macro)
|
|
||||||
if [[ "$result" == *"true"* ]]; then
|
|
||||||
echo "is_proc_macro=true" >> "$GITHUB_OUTPUT"
|
|
||||||
else
|
|
||||||
echo "is_proc_macro=false" >> "$GITHUB_OUTPUT"
|
|
||||||
fi
|
|
||||||
|
|
||||||
- name: Set Git Author (required for cargo-release)
|
|
||||||
if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' }}
|
|
||||||
run: |
|
|
||||||
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
||||||
git config --global user.name "github-actions[bot]"
|
|
||||||
|
|
||||||
- name: Set Version
|
|
||||||
if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' }}
|
|
||||||
run: |
|
|
||||||
if [ "${{ inputs.level }}" == "version" ]; then
|
|
||||||
LEVEL=${{ inputs.version }}
|
|
||||||
else
|
|
||||||
LEVEL=${{ inputs.level }}
|
|
||||||
fi
|
|
||||||
cargo release $LEVEL --manifest-path "${{ inputs.package_path }}/Cargo.toml" --no-tag --no-publish --no-push --no-confirm --execute
|
|
||||||
|
|
||||||
- name: Check semver
|
|
||||||
if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' && github.event.inputs.run_semver == 'true'}}
|
|
||||||
run: cargo semver-checks --manifest-path "${{ inputs.package_path }}/Cargo.toml"
|
|
||||||
|
|
||||||
publish-crate:
|
|
||||||
name: Publish crate
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
needs: [format, clippy, semver]
|
|
||||||
permissions:
|
|
||||||
contents: write
|
|
||||||
steps:
|
|
||||||
- name: Git Checkout
|
|
||||||
uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
token: ${{ secrets.ANZA_TEAM_PAT }}
|
|
||||||
fetch-depth: 0 # get the whole history for git-cliff
|
|
||||||
|
|
||||||
- name: Install Rust
|
|
||||||
uses: dtolnay/rust-toolchain@stable
|
|
||||||
|
|
||||||
- name: Cache
|
|
||||||
uses: Swatinem/rust-cache@v2
|
|
||||||
|
|
||||||
- name: Install cargo-release
|
|
||||||
uses: taiki-e/install-action@v2
|
|
||||||
with:
|
|
||||||
tool: cargo-release
|
|
||||||
|
|
||||||
- name: Ensure CARGO_REGISTRY_TOKEN variable is set
|
|
||||||
env:
|
|
||||||
token: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
|
||||||
if: ${{ env.token == '' }}
|
|
||||||
run: |
|
|
||||||
echo "The CARGO_REGISTRY_TOKEN secret variable is not set"
|
|
||||||
echo "Go to \"Settings\" -> \"Secrets and variables\" -> \"Actions\" -> \"New repository secret\"."
|
|
||||||
exit 1
|
|
||||||
|
|
||||||
- name: Set Git Author
|
|
||||||
run: |
|
|
||||||
git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
||||||
git config --global user.name "github-actions[bot]"
|
|
||||||
|
|
||||||
- name: Rebase (in case any changes landed after)
|
|
||||||
run: git pull --rebase origin
|
|
||||||
|
|
||||||
- name: Publish Crate
|
|
||||||
id: publish
|
|
||||||
env:
|
|
||||||
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
|
||||||
run: |
|
|
||||||
if [ "${{ inputs.level }}" == "version" ]; then
|
|
||||||
LEVEL=${{ inputs.version }}
|
|
||||||
else
|
|
||||||
LEVEL=${{ inputs.level }}
|
|
||||||
fi
|
|
||||||
|
|
||||||
if [ "${{ inputs.dry_run }}" == "true" ]; then
|
|
||||||
OPTIONS="--dry-run"
|
|
||||||
else
|
|
||||||
OPTIONS=""
|
|
||||||
fi
|
|
||||||
|
|
||||||
./scripts/publish-rust.sh "${{ inputs.package_path }}" $LEVEL "${{ inputs.dependent_version }}" $OPTIONS
|
|
||||||
|
|
||||||
- name: Generate a changelog
|
|
||||||
if: github.event.inputs.create_release == 'true'
|
|
||||||
uses: orhun/git-cliff-action@v4
|
|
||||||
with:
|
|
||||||
config: "scripts/cliff.toml"
|
|
||||||
args: ${{ steps.publish.outputs.old_git_tag }}..HEAD --include-path "${{ inputs.package_path }}/**" --github-repo ${{ github.repository }}
|
|
||||||
env:
|
|
||||||
OUTPUT: TEMP_CHANGELOG.md
|
|
||||||
GITHUB_REPO: ${{ github.repository }}
|
|
||||||
|
|
||||||
- name: Create GitHub release
|
|
||||||
if: github.event.inputs.create_release == 'true' && github.event.inputs.dry_run != 'true'
|
|
||||||
uses: ncipollo/release-action@v1
|
|
||||||
with:
|
|
||||||
tag: ${{ steps.publish.outputs.new_git_tag }}
|
|
||||||
bodyFile: TEMP_CHANGELOG.md
|
|
||||||
138
.github/workflows/release.yml
vendored
Normal file
138
.github/workflows/release.yml
vendored
Normal file
|
|
@ -0,0 +1,138 @@
|
||||||
|
name: Release
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
crate:
|
||||||
|
description: "Crate to release"
|
||||||
|
required: true
|
||||||
|
type: choice
|
||||||
|
options:
|
||||||
|
- ""
|
||||||
|
- solana-curve25519-cuda
|
||||||
|
- solana-ed25519
|
||||||
|
- ed25519-pokos
|
||||||
|
- solana-bls12-381-syscall
|
||||||
|
ref:
|
||||||
|
description: "git ref to tag (can be a branch or a commit hash)"
|
||||||
|
required: true
|
||||||
|
default: "master"
|
||||||
|
type: string
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
check:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
outputs:
|
||||||
|
tag: ${{ steps.meta.outputs.tag }}
|
||||||
|
ref: ${{ steps.meta.outputs.ref }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v6
|
||||||
|
with:
|
||||||
|
ref: ${{ inputs.ref }}
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
|
- name: Compute metadata
|
||||||
|
id: meta
|
||||||
|
run: |
|
||||||
|
|
||||||
|
version="$(cargo metadata --format-version 1 --no-deps | jq -r '.packages[] | select(.name == "'"${CRATE_NAME}"'") | .version')"
|
||||||
|
if [ -z "${version}" ] || [ "${version}" = "null" ]; then
|
||||||
|
echo "Could not resolve version for crate: ${CRATE_NAME}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
tag="${CRATE_NAME}@v${version}"
|
||||||
|
ref="$(git rev-parse HEAD)"
|
||||||
|
|
||||||
|
echo "tag=${tag}" >> "${GITHUB_OUTPUT}"
|
||||||
|
echo "ref=${ref}" >> "${GITHUB_OUTPUT}"
|
||||||
|
env:
|
||||||
|
CRATE_NAME: ${{ inputs.crate }}
|
||||||
|
|
||||||
|
- name: Check tag does not exist
|
||||||
|
run: |
|
||||||
|
echo "checking: refs/tags/${TAG}"
|
||||||
|
if git ls-remote --exit-code --tags origin "refs/tags/${TAG}" >/dev/null 2>&1; then
|
||||||
|
echo "Tag already exists: ${TAG}. Please bump the version first (or delete the existing tag) and retry."
|
||||||
|
echo "Tag exists: ${TAG}" >> "${GITHUB_STEP_SUMMARY}"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
env:
|
||||||
|
TAG: ${{ steps.meta.outputs.tag }}
|
||||||
|
|
||||||
|
- name: Cargo publish dry run
|
||||||
|
run: |
|
||||||
|
cargo publish -p "${CRATE_NAME}" --dry-run
|
||||||
|
env:
|
||||||
|
CRATE_NAME: ${{ inputs.crate }}
|
||||||
|
|
||||||
|
- name: Summary
|
||||||
|
run: |
|
||||||
|
echo "Tag: ${TAG}" >> "${GITHUB_STEP_SUMMARY}"
|
||||||
|
echo "Ref: ${REF} (https://github.com/${{ github.repository }}/commit/${REF})" >> "${GITHUB_STEP_SUMMARY}"
|
||||||
|
env:
|
||||||
|
TAG: ${{ steps.meta.outputs.tag }}
|
||||||
|
REF: ${{ steps.meta.outputs.ref }}
|
||||||
|
|
||||||
|
publish:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
environment: prod
|
||||||
|
needs: check
|
||||||
|
permissions:
|
||||||
|
id-token: write
|
||||||
|
contents: write
|
||||||
|
attestations: write
|
||||||
|
artifact-metadata: write
|
||||||
|
steps:
|
||||||
|
- uses: actions/create-github-app-token@v3
|
||||||
|
id: app-token
|
||||||
|
with:
|
||||||
|
app-id: ${{ vars.APP_ID }}
|
||||||
|
private-key: ${{ secrets.PRIVATE_KEY }}
|
||||||
|
|
||||||
|
- name: Set git config
|
||||||
|
run: |
|
||||||
|
git config --global user.email "${APP_ID}+${APP_SLUG}[bot]@users.noreply.github.com"
|
||||||
|
git config --global user.name "${APP_SLUG}[bot]"
|
||||||
|
git config --global url."https://x-access-token:${GITHUB_TOKEN}@github.com/".insteadOf https://github.com/
|
||||||
|
env:
|
||||||
|
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||||
|
APP_ID: ${{ vars.APP_ID }}
|
||||||
|
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
|
||||||
|
|
||||||
|
- uses: actions/checkout@v6
|
||||||
|
with:
|
||||||
|
token: ${{ steps.app-token.outputs.token }}
|
||||||
|
persist-credentials: false
|
||||||
|
ref: ${{ needs.check.outputs.ref }}
|
||||||
|
|
||||||
|
- run: |
|
||||||
|
git tag -a "${TAG}" -m "Release ${TAG}"
|
||||||
|
git push --tags
|
||||||
|
env:
|
||||||
|
TAG: ${{ needs.check.outputs.tag }}
|
||||||
|
|
||||||
|
- name: Package crate
|
||||||
|
run: cargo package -p "${CRATE_NAME}"
|
||||||
|
env:
|
||||||
|
CRATE_NAME: ${{ inputs.crate }}
|
||||||
|
|
||||||
|
- name: Generate SLSA provenance
|
||||||
|
uses: actions/attest-build-provenance@v4
|
||||||
|
with:
|
||||||
|
subject-path: target/package/*.crate
|
||||||
|
|
||||||
|
- uses: rust-lang/crates-io-auth-action@v1
|
||||||
|
id: auth
|
||||||
|
|
||||||
|
- run: cargo publish -p "${CRATE_NAME}"
|
||||||
|
env:
|
||||||
|
CRATE_NAME: ${{ inputs.crate }}
|
||||||
|
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
|
||||||
|
|
||||||
|
- name: Create Github Release
|
||||||
|
run: |
|
||||||
|
gh release create "${TAG}" --title "${TAG}" --generate-notes
|
||||||
|
env:
|
||||||
|
TAG: ${{ needs.check.outputs.tag }}
|
||||||
|
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
||||||
Loading…
Reference in a new issue