miden-verify 0.7.0

Verify Miden accounts and notes from the command line.
name: Release

# Publishing a GitHub Release publishes the crate to crates.io and uploads the
# pre-built executables to the release.
#
# The filename is load-bearing: crates.io trusted publishing authorizes this
# repository, *this workflow filename* and the `release` environment for the
# `miden-verify` crate. Renaming the file or the environment breaks publishing
# until the trusted-publisher config on crates.io is updated to match.

on:
  release:
    types: [published]

permissions:
  contents: read

jobs:
  publish:
    name: Publish to crates.io
    runs-on: ubuntu-latest
    if: ${{ github.repository_owner == 'walnuthq' }}
    environment: release
    permissions:
      # Required to exchange a GitHub OIDC token for a short-lived crates.io token.
      id-token: write
      contents: read
    steps:
      - name: Checkout repository
        uses: actions/checkout@v7
        with:
          ref: ${{ github.event.release.tag_name }}

      # Installs the toolchain pinned by `rust-toolchain.toml`.
      - name: Install Rust toolchain
        run: |
          rustup toolchain install
          rustc --version

      - name: Check the tag matches the crate version
        run: |
          version=$(cargo metadata --format-version 1 --no-deps \
            | jq -r '.packages[] | select(.name == "miden-verify") | .version')
          tag="${GITHUB_REF_NAME#v}"
          if [ "$version" != "$tag" ]; then
            echo "tag \`$GITHUB_REF_NAME\` does not match crate version \`$version\`" >&2
            echo "bump the version in Cargo.toml, or retag the release" >&2
            exit 1
          fi

      - name: Run tests
        run: cargo test --all-targets --locked

      - uses: rust-lang/crates-io-auth-action@v1
        id: auth

      - name: Publish
        run: cargo publish --locked
        env:
          CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}

  # Upload the miden-verify CLI as an artifact on the Github release.
  # This is used by midenup to speed installs up. Only runs once the crate is
  # published, so a failed publish never leaves binaries on the release.
  upload-artifacts:
    name: Upload pre-built miden-verify executable artifacts
    needs: publish
    if: ${{ github.repository_owner == 'walnuthq' }}
    permissions:
      contents: write
      id-token: write
      attestations: write
    strategy:
      matrix:
        os: [macos-latest, ubuntu-latest]
        target: [aarch64-apple-darwin, x86_64-unknown-linux-gnu]
        exclude:
          - os: macos-latest
            target: x86_64-unknown-linux-gnu
          - os: ubuntu-latest
            target: aarch64-apple-darwin
    runs-on: ${{ matrix.os }}
    steps:
      - name: Checkout repository
        uses: actions/checkout@v7
        with:
          fetch-depth: 0
          ref: ${{ github.event.release.tag_name }}
      - name: Install Rust
        run: |
          rustup update --no-self-update
          rustc --version
      - name: Add target
        run: |
          rustup target add ${{ matrix.target }}
      - name: Build miden-verify
        run: |
          cargo build --release --locked --target ${{ matrix.target }}
      - name: Prepare artifact
        run: |
          mv target/${{ matrix.target }}/release/miden-verify miden-verify-${{ matrix.target }}
      - name: Attest miden-verify
        uses: actions/attest@v4
        with:
          subject-path: miden-verify-${{ matrix.target }}
      - name: Upload
        env:
          RELEASE_TAG: ${{ github.event.release.tag_name }}
          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
        run: |
          set -e
          gh release upload ${RELEASE_TAG} miden-verify-${{ matrix.target }}