Repository navigation
release: use the file name cargo-cyclonedx writes #3
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: release | |
| on: | |
| push: | |
| tags: ["v*"] | |
| permissions: | |
| contents: read | |
| jobs: | |
| build: | |
| strategy: | |
| matrix: | |
| include: | |
| - target: aarch64-apple-darwin | |
| os: macos-14 | |
| - target: x86_64-apple-darwin | |
| os: macos-14 # cross-compiled; GitHub retired the Intel runners | |
| - target: x86_64-unknown-linux-musl | |
| os: ubuntu-latest | |
| - target: aarch64-unknown-linux-musl | |
| os: ubuntu-24.04-arm | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # v1 | |
| with: | |
| toolchain: stable | |
| targets: ${{ matrix.target }} | |
| - name: musl tools | |
| if: contains(matrix.target, 'musl') | |
| run: sudo apt-get update && sudo apt-get install -y musl-tools | |
| - run: cargo build --release --target ${{ matrix.target }} | |
| - name: package | |
| run: | | |
| cd target/${{ matrix.target }}/release | |
| tar -czf envit-${{ matrix.target }}.tar.gz envit | |
| shasum -a 256 envit-${{ matrix.target }}.tar.gz > envit-${{ matrix.target }}.tar.gz.sha256 | |
| - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: envit-${{ matrix.target }} | |
| path: target/${{ matrix.target }}/release/envit-${{ matrix.target }}.tar.gz* | |
| publish: | |
| needs: build | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| id-token: write | |
| attestations: write | |
| steps: | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # v1 | |
| with: | |
| toolchain: stable | |
| - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| merge-multiple: true | |
| - name: SBOM (CycloneDX) | |
| run: | | |
| cargo install cargo-cyclonedx --locked | |
| cargo cyclonedx --format json --target all --override-filename envit-sbom | |
| mv crates/envit/envit-sbom.json envit-sbom.cdx.json | |
| - name: attest build provenance | |
| uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 | |
| with: | |
| subject-path: "envit-*.tar.gz" | |
| - name: attest SBOM | |
| uses: actions/attest-sbom@c604332985a26aa8cf1bdc465b92731239ec6b9e # v4.1.0 | |
| with: | |
| subject-path: "envit-*.tar.gz" | |
| sbom-path: envit-sbom.cdx.json | |
| - name: publish release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| TAG: ${{ github.ref_name }} | |
| run: gh release create "$TAG" envit-* --generate-notes --verify-tag | |
| npm: | |
| # Publishes the npm meta package and platform packages with provenance. | |
| # First publish of each package is manual (npm trusted publishing needs an | |
| # existing package). Enable this job afterwards by setting the repository | |
| # variable NPM_PUBLISH=true. | |
| needs: build | |
| if: vars.NPM_PUBLISH == 'true' | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4 | |
| with: | |
| merge-multiple: true | |
| - name: place binaries | |
| run: | | |
| set -e | |
| place() { mkdir -p "packages/npm/$1/bin"; tar -xzf "envit-$2.tar.gz" -C "packages/npm/$1/bin"; } | |
| place darwin-arm64 aarch64-apple-darwin | |
| place darwin-x64 x86_64-apple-darwin | |
| place linux-arm64 aarch64-unknown-linux-musl | |
| place linux-x64 x86_64-unknown-linux-musl | |
| - name: set versions from tag | |
| env: | |
| TAG: ${{ github.ref_name }} | |
| run: | | |
| v="${TAG#v}" | |
| for p in darwin-arm64 darwin-x64 linux-arm64 linux-x64 envit; do | |
| (cd "packages/npm/$p" && npm version "$v" --no-git-tag-version >/dev/null) | |
| done | |
| (cd packages/npm/envit && node -e ' | |
| const f="package.json", p=require("./"+f); | |
| for (const k of Object.keys(p.optionalDependencies)) p.optionalDependencies[k]=process.argv[1]; | |
| require("fs").writeFileSync(f, JSON.stringify(p,null,2)+"\n")' "$v") | |
| - name: publish | |
| run: | | |
| set -e | |
| for p in darwin-arm64 darwin-x64 linux-arm64 linux-x64 envit; do | |
| (cd "packages/npm/$p" && npm publish --access public --provenance) | |
| done | |