name: Publish
on:
workflow_dispatch:
inputs:
tag:
description: Release tag to publish, e.g. tauri-plugin-android-update-v0.3.0
required: true
type: string
dry_run:
description: Dry run (verify versions without publishing)
required: false
type: boolean
default: false
publish:
description: Publish to crates.io and npm after verification
required: false
type: boolean
default: true
jobs:
publish_crate:
if: inputs.publish || inputs.dry_run
permissions:
contents: read
id-token: write runs-on: ubuntu-latest
name: 📦 Publish to crates.io
steps:
- name: 🔄 Checkout release tag
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with:
fetch-depth: 0
persist-credentials: false
ref: ${{ inputs.tag }}
- name: 🦀 Setup Rust
uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87
- name: 🧰 Install Tauri system dependencies
shell: bash
run: sudo apt-get update && sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
- name: 🔍 Verify tag matches crate version
shell: bash
env:
TAG: ${{ inputs.tag }}
run: |
set -euo pipefail
EXPECTED_VERSION="${TAG##*-v}"
ACTUAL_VERSION=$(cargo metadata --no-deps --format-version 1 | jq -r '.packages[] | select(.name == "tauri-plugin-android-update") | .version')
if [ "$ACTUAL_VERSION" != "$EXPECTED_VERSION" ]; then
echo "Error: crate version ($ACTUAL_VERSION) does not match tag $TAG (expected $EXPECTED_VERSION)."
exit 1
fi
echo "Version: $ACTUAL_VERSION"
- name: 🔐 Authenticate with crates.io (OIDC)
id: auth
uses: rust-lang/crates-io-auth-action@c6f97d42243bad5fab37ca0427f495c86d5b1a18 if: inputs.publish && !inputs.dry_run
- name: 📦 Publish to crates.io
if: inputs.publish && !inputs.dry_run
shell: bash
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
run: |
set -euo pipefail
cargo publish --package tauri-plugin-android-update
- name: 📦 Dry-run publish to crates.io
if: inputs.dry_run
shell: bash
run: |
set -euo pipefail
cargo publish --dry-run --package tauri-plugin-android-update
publish_npm:
if: inputs.publish || inputs.dry_run
permissions:
contents: read
id-token: write runs-on: ubuntu-latest
name: 📦 Publish to npm
steps:
- name: 🔄 Checkout release tag
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 with:
fetch-depth: 0
persist-credentials: false
ref: ${{ inputs.tag }}
- name: 🟢 Setup Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 with:
node-version: 24
registry-url: 'https://registry.npmjs.org'
- name: 🔍 Verify lockstep versions
shell: bash
env:
TAG: ${{ inputs.tag }}
run: |
set -euo pipefail
EXPECTED_VERSION="${TAG##*-v}"
NPM_VERSION=$(npm pkg get version | tr -d '"')
if [ "$NPM_VERSION" != "$EXPECTED_VERSION" ]; then
echo "Error: npm package version ($NPM_VERSION) does not match tag $TAG (expected $EXPECTED_VERSION)."
exit 1
fi
echo "Version: $NPM_VERSION"
- name: 📦 Publish to npm
if: inputs.publish && !inputs.dry_run
shell: bash
run: |
set -euo pipefail
npm ci
npm run build
npm publish --provenance --access public
- name: 📦 Dry-run publish to npm
if: inputs.dry_run
shell: bash
run: |
set -euo pipefail
npm ci
npm publish --dry-run