mpp 0.14.0

Rust SDK for the Machine Payments Protocol (MPP)
Documentation
name: Release
on:
  push:
    branches:
      - main

concurrency: ${{ github.workflow }}-${{ github.ref }}

# The changelog-release version PR, branch, tags, and GitHub releases are
# created with a short-lived GitHub App token minted via the github-sts
# action (authorized by .github/sts/release-pr.sts.yaml); the built-in
# GITHUB_TOKEN is not allowed to create pull requests. id-token feeds the
# STS exchange and crates.io trusted publishing.
permissions:
  contents: read
  id-token: write

jobs:
  release:
    name: Version
    runs-on: ubuntu-latest
    steps:
      - name: Secure runner
        uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - name: Fetch GitHub token via STS
        id: app-token
        uses: tempoxyz/gh-actions/actions/github-sts@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        with:
          policy: release-pr

      - name: Checkout
        uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 # zizmor: ignore[artipacked]
        with:
          token: ${{ steps.app-token.outputs.token }}

      - name: Authenticate with crates.io
        uses: tempoxyz/gh-actions/vendor/rust-lang/crates-io-auth-action@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        id: auth

      - name: Changelogs
        uses: tempoxyz/changelogs@83e69646d7ef76c5f35364d3a06fce3a6fe62bf9 # 2026-09-07T12-57-31Z-83e69646 # zizmor: ignore[artipacked]
        with:
          ecosystem: rust
          conventional-commit: true
          crate-token: ${{ steps.auth.outputs.token }}
          github-token: ${{ steps.app-token.outputs.token }}