name: Release
on:
push:
tags: ["v*"]
jobs:
verify:
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
version: ${{ steps.version.outputs.version }}
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- name: Check tag matches Cargo.toml version
id: version
run: |
version=$(cargo metadata --no-deps --format-version 1 | jq -r '.packages[0].version')
if [ "v$version" != "$GITHUB_REF_NAME" ]; then
echo "::error::Tag $GITHUB_REF_NAME does not match Cargo.toml version v$version"
exit 1
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
- run: cargo publish --dry-run --locked
crates-io:
needs: verify
runs-on: ubuntu-latest
environment: release
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: rust-lang/crates-io-auth-action@v1
id: auth
- run: cargo publish --locked
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
github-release:
needs: crates-io
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Create GitHub release
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release create "$GITHUB_REF_NAME" \
--repo "$GITHUB_REPOSITORY" \
--title "$GITHUB_REF_NAME" \
--generate-notes \
--verify-tag
homebrew:
needs: [verify, github-release]
runs-on: ubuntu-latest
environment: release
permissions:
contents: read
steps:
- uses: actions/create-github-app-token@v3
id: app-token
with:
app-id: ${{ vars.TAP_APP_ID }}
private-key: ${{ secrets.TAP_APP_PRIVATE_KEY }}
repositories: homebrew-tap
- uses: actions/checkout@v7
with:
repository: lkurcak/homebrew-tap
token: ${{ steps.app-token.outputs.token }}
- name: Open formula bump PR
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
VERSION: ${{ needs.verify.outputs.version }}
run: |
url="https://github.com/${GITHUB_REPOSITORY}/archive/refs/tags/${GITHUB_REF_NAME}.tar.gz"
sha256=$(curl -fsSL "$url" | sha256sum | cut -d' ' -f1)
formula=Formula/gud.rb
sed -i -E \
-e "s|^ url \".*\"$| url \"${url}\"|" \
-e "s|^ sha256 \"[0-9a-f]+\"$| sha256 \"${sha256}\"|" \
"$formula"
git diff --exit-code --quiet "$formula" && { echo "::error::$formula unchanged"; exit 1; }
branch="bump-gud-${VERSION}"
git config user.name "${APP_SLUG}[bot]"
git config user.email "$(gh api "/users/${APP_SLUG}%5Bbot%5D" --jq .id)+${APP_SLUG}[bot]@users.noreply.github.com"
git switch -c "$branch"
git commit -am "gud ${VERSION}"
git push -u origin "$branch"
gh pr create --title "gud ${VERSION}" --body "Automated bump from ${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/releases/tag/${GITHUB_REF_NAME}"