mirror of
https://github.com/saymrwulf/anza-cryptography-source.git
synced 2026-09-04 20:24:04 +00:00
138 lines
4.2 KiB
YAML
138 lines
4.2 KiB
YAML
name: Release
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
crate:
|
|
description: "Crate to release"
|
|
required: true
|
|
type: choice
|
|
options:
|
|
- ""
|
|
- solana-curve25519-cuda
|
|
- solana-ed25519
|
|
- ed25519-pokos
|
|
- solana-bls12-381-syscall
|
|
ref:
|
|
description: "git ref to tag (can be a branch or a commit hash)"
|
|
required: true
|
|
default: "master"
|
|
type: string
|
|
|
|
jobs:
|
|
check:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
tag: ${{ steps.meta.outputs.tag }}
|
|
ref: ${{ steps.meta.outputs.ref }}
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
with:
|
|
ref: ${{ inputs.ref }}
|
|
persist-credentials: false
|
|
|
|
- name: Compute metadata
|
|
id: meta
|
|
run: |
|
|
|
|
version="$(cargo metadata --format-version 1 --no-deps | jq -r '.packages[] | select(.name == "'"${CRATE_NAME}"'") | .version')"
|
|
if [ -z "${version}" ] || [ "${version}" = "null" ]; then
|
|
echo "Could not resolve version for crate: ${CRATE_NAME}"
|
|
exit 1
|
|
fi
|
|
|
|
tag="${CRATE_NAME}@v${version}"
|
|
ref="$(git rev-parse HEAD)"
|
|
|
|
echo "tag=${tag}" >> "${GITHUB_OUTPUT}"
|
|
echo "ref=${ref}" >> "${GITHUB_OUTPUT}"
|
|
env:
|
|
CRATE_NAME: ${{ inputs.crate }}
|
|
|
|
- name: Check tag does not exist
|
|
run: |
|
|
echo "checking: refs/tags/${TAG}"
|
|
if git ls-remote --exit-code --tags origin "refs/tags/${TAG}" >/dev/null 2>&1; then
|
|
echo "Tag already exists: ${TAG}. Please bump the version first (or delete the existing tag) and retry."
|
|
echo "Tag exists: ${TAG}" >> "${GITHUB_STEP_SUMMARY}"
|
|
exit 1
|
|
fi
|
|
env:
|
|
TAG: ${{ steps.meta.outputs.tag }}
|
|
|
|
- name: Cargo publish dry run
|
|
run: |
|
|
cargo publish -p "${CRATE_NAME}" --dry-run
|
|
env:
|
|
CRATE_NAME: ${{ inputs.crate }}
|
|
|
|
- name: Summary
|
|
run: |
|
|
echo "Tag: ${TAG}" >> "${GITHUB_STEP_SUMMARY}"
|
|
echo "Ref: ${REF} (https://github.com/${{ github.repository }}/commit/${REF})" >> "${GITHUB_STEP_SUMMARY}"
|
|
env:
|
|
TAG: ${{ steps.meta.outputs.tag }}
|
|
REF: ${{ steps.meta.outputs.ref }}
|
|
|
|
publish:
|
|
runs-on: ubuntu-latest
|
|
environment: prod
|
|
needs: check
|
|
permissions:
|
|
id-token: write
|
|
contents: write
|
|
attestations: write
|
|
artifact-metadata: write
|
|
steps:
|
|
- uses: actions/create-github-app-token@v3
|
|
id: app-token
|
|
with:
|
|
client-id: ${{ vars.CLIENT_ID }}
|
|
private-key: ${{ secrets.PRIVATE_KEY }}
|
|
|
|
- name: Set git config
|
|
run: |
|
|
git config --global user.email "${APP_ID}+${APP_SLUG}[bot]@users.noreply.github.com"
|
|
git config --global user.name "${APP_SLUG}[bot]"
|
|
git config --global url."https://x-access-token:${GITHUB_TOKEN}@github.com/".insteadOf https://github.com/
|
|
env:
|
|
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
|
APP_ID: ${{ vars.APP_ID }}
|
|
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
|
|
|
|
- uses: actions/checkout@v6
|
|
with:
|
|
token: ${{ steps.app-token.outputs.token }}
|
|
persist-credentials: false
|
|
ref: ${{ needs.check.outputs.ref }}
|
|
|
|
- run: |
|
|
git tag -a "${TAG}" -m "Release ${TAG}"
|
|
git push --tags
|
|
env:
|
|
TAG: ${{ needs.check.outputs.tag }}
|
|
|
|
- name: Package crate
|
|
run: cargo package -p "${CRATE_NAME}"
|
|
env:
|
|
CRATE_NAME: ${{ inputs.crate }}
|
|
|
|
- name: Generate SLSA provenance
|
|
uses: actions/attest-build-provenance@v4
|
|
with:
|
|
subject-path: target/package/*.crate
|
|
|
|
- uses: rust-lang/crates-io-auth-action@v1
|
|
id: auth
|
|
|
|
- run: cargo publish -p "${CRATE_NAME}"
|
|
env:
|
|
CRATE_NAME: ${{ inputs.crate }}
|
|
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
|
|
|
|
- name: Create Github Release
|
|
run: |
|
|
gh release create "${TAG}" --title "${TAG}" --generate-notes
|
|
env:
|
|
TAG: ${{ needs.check.outputs.tag }}
|
|
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|