zapd 1.1.2

The ZAP router — embedded in every ZAP process; one per user login, elected by lock
Documentation
name: release

on:
  push:
    tags: ['v*']

permissions:
  contents: write

jobs:
  build:
    name: ${{ matrix.target }}
    runs-on: ${{ matrix.os }}
    strategy:
      fail-fast: false
      matrix:
        include:
          - { os: macos-14,         target: aarch64-apple-darwin }
          - { os: macos-14,         target: x86_64-apple-darwin }        # native cross-compile, no QEMU/macos-13
          - { os: ubuntu-latest,    target: x86_64-unknown-linux-musl }
          - { os: ubuntu-24.04-arm, target: aarch64-unknown-linux-musl }
    steps:
      - uses: actions/checkout@v4
      - uses: dtolnay/rust-toolchain@stable
        with:
          targets: ${{ matrix.target }}
      - name: musl tools
        if: contains(matrix.target, 'musl')
        run: sudo apt-get update && sudo apt-get install -y musl-tools
      - run: cargo build -p zapd --release --target ${{ matrix.target }}
      - name: package
        run: |
          tar -C target/${{ matrix.target }}/release -czf zapd-${{ matrix.target }}.tar.gz zapd
          shasum -a 256 zapd-${{ matrix.target }}.tar.gz > zapd-${{ matrix.target }}.tar.gz.sha256
      - uses: actions/upload-artifact@v4
        with:
          name: zapd-${{ matrix.target }}
          path: zapd-${{ matrix.target }}.tar.gz*

  release:
    needs: build
    runs-on: ubuntu-latest
    steps:
      - uses: actions/download-artifact@v4
        with: { merge-multiple: true, path: dist }
      - name: GitHub Release
        uses: softprops/action-gh-release@v2
        with:
          files: dist/*
          generate_release_notes: true

  npm:
    needs: release
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-node@v4
        with: { node-version: 20, registry-url: 'https://registry.npmjs.org' }
      - name: publish @zap-proto/zapd (downloads the canonical zap-proto binary)
        working-directory: npm
        run: |
          npm version --no-git-tag-version --allow-same-version "${GITHUB_REF_NAME#v}"
          npm publish --access public
        env:
          NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}

  # The Python binding (`import zapd`): abi3 wheels, one per platform, published
  # with PyPI trusted publishing (no token in the repo).
  wheels:
    name: wheel ${{ matrix.target }}
    runs-on: ${{ matrix.os }}
    strategy:
      fail-fast: false
      matrix:
        include:
          - { os: macos-14,         target: aarch64-apple-darwin }
          - { os: macos-14,         target: x86_64-apple-darwin }
          - { os: ubuntu-latest,    target: x86_64-unknown-linux-gnu }
          - { os: ubuntu-24.04-arm, target: aarch64-unknown-linux-gnu }
    steps:
      - uses: actions/checkout@v4
      - uses: PyO3/maturin-action@v1
        with:
          working-directory: python
          target: ${{ matrix.target }}
          manylinux: auto
          args: --release --out dist
      - uses: actions/upload-artifact@v4
        with:
          name: wheel-${{ matrix.target }}
          path: python/dist/*.whl

  pypi:
    needs: wheels
    runs-on: ubuntu-latest
    permissions:
      id-token: write
    steps:
      - uses: actions/download-artifact@v4
        with: { pattern: 'wheel-*', merge-multiple: true, path: dist }
      - uses: pypa/gh-action-pypi-publish@release/v1

  # The crate the Rust hosts (dev, desktop, the IDE) embed — crates.io trusted
  # publishing, no token in the repository.
  crates:
    runs-on: ubuntu-latest
    permissions:
      id-token: write
    steps:
      - uses: actions/checkout@v4
      - uses: dtolnay/rust-toolchain@stable
      - uses: rust-lang/crates-io-auth-action@v1
        id: auth
      - run: cargo publish -p zapd
        env:
          CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}