name: Release
permissions: read-all
on:
push:
tags: ["v*"]
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
release:
if: github.repository == 'zebodotdev/inttegro-sdk-rust'
runs-on: ubuntu-latest
timeout-minutes: 30
environment: release
permissions:
attestations: write
contents: write
id-token: write
steps:
- name: Check out the release commit
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with:
fetch-depth: 0
persist-credentials: false
- name: Set up Rust
uses: dtolnay/rust-toolchain@d1031067263f94b142dd6c0ce24c5eb9d02d52a0
with:
toolchain: "1.88"
components: rustfmt, clippy
- name: Verify the release tag
shell: bash
run: |
set -euo pipefail
version="$(sed -n 's/^version = "\([^"]*\)"$/\1/p' Cargo.toml | head -1)"
test "${GITHUB_REF_NAME}" = "v${version}"
test "$(git rev-list -n 1 "${GITHUB_REF_NAME}")" = "${GITHUB_SHA}"
- name: Run release checks and build the crate
shell: bash
run: |
set -euo pipefail
cargo fmt --check
cargo clippy --all-targets -- -D warnings
cargo test --all-targets
cargo package
mkdir -p artifacts
cp target/package/inttegro-*.crate artifacts/
- name: Attest the crate
id: attest
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 with:
subject-path: artifacts/*.crate
- name: Record release provenance and checksums
shell: bash
run: |
set -euo pipefail
cp "${{ steps.attest.outputs.bundle-path }}" artifacts/ATTESTATIONS.sigstore
{
echo "repository=https://github.com/${GITHUB_REPOSITORY}"
echo "tag=${GITHUB_REF_NAME}"
echo "commit=${GITHUB_SHA}"
echo "workflow=${GITHUB_WORKFLOW_REF}"
echo "package=inttegro"
} > artifacts/PROVENANCE.txt
(cd artifacts && sha256sum ./*.crate ./ATTESTATIONS.sigstore ./PROVENANCE.txt > SHA256SUMS)
- name: Create the draft GitHub release
env:
GH_TOKEN: ${{ github.token }}
run: >-
gh release create "${GITHUB_REF_NAME}" artifacts/*
--draft
--generate-notes
--title "Inttegro Rust SDK ${GITHUB_REF_NAME}"
--verify-tag
- name: Publish to crates.io
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
run: cargo publish
- name: Finalize the immutable GitHub release
env:
GH_TOKEN: ${{ github.token }}
run: gh release edit "${GITHUB_REF_NAME}" --draft=false