Expand description
GitHub Release publisher adapter (R509-F7).
Creates (or updates) a GitHub Release for a tag and uploads the run’s
produced artifacts as release assets. This is the native path to GitHub
Releases — now the only one, since W224/R533-T7 retired the GHA gh-release
workflow override — so a non-GHA pipeline can tag-and-upload directly. It’s
also how the oss/ crates.io mirror releases publish their binaries.
Driven through the gh CLI rather than a hand-rolled REST client: gh is
ubiquitous in CI, already this workspace’s GitHub surface, and handles auth,
retries, and the two-step asset upload (POST /releases then the
uploads.github.com multipart) — so the adapter adds no new dependency
(same subprocess pattern as notarize/testflight). The gh binary is
overridable; GITHUB_TOKEN is passed via the GH_TOKEN env var.
A GitHub Release is a ship: ProviderReport::produced stays empty and
the release html_url is returned in ProviderReport::published.
§Idempotency
dispatch is find-or-create by tag: if a release already exists for the tag
it uploads the assets with --clobber (re-runs replace same-named assets);
otherwise it creates the release. Re-running a release is safe.
§Credentials
GITHUB_TOKEN— a repo-scoped PAT or installation token, passed toghasGH_TOKEN. Never logged.
§Dry run
ctx.dry_run confirms GITHUB_TOKEN resolves and the selected asset files
exist, then reports would create release <owner/repo>@<tag> with N assets
— spawning no gh and mutating nothing.
Structs§
- Github
Release Provider github-release— native GitHub Release create + asset upload. See module docs.