name: Release
on:
push:
tags:
- "v*.*"
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
jobs:
verify-version:
name: Verify tag matches version
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
- name: Check tag against Cargo.toml version
run: |
tag="${GITHUB_REF_NAME#v}"
manifest="$(grep -m1 '^version = ' Cargo.toml | sed -E 's/version = "(.*)"/\1/')"
echo "tag version: $tag"
echo "manifest version: $manifest"
if [ "$tag" != "$manifest" ]; then
echo "::error::tag $tag does not match Cargo.toml version $manifest"
exit 1
fi
ci:
name: CI
needs: verify-version
uses: ./.github/workflows/ci.yml
secrets: inherit
publish:
name: Publish to crates.io
needs: ci
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- name: Checkout
uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09
- name: Install stable toolchain
uses: dtolnay/rust-toolchain@stable
- name: Authenticate to crates.io
id: auth
uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18
- name: Publish crate
run: cargo publish --locked
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}