-
Notifications
You must be signed in to change notification settings - Fork 0
131 lines (119 loc) · 4.68 KB
/
Copy pathrelease.yml
File metadata and controls
131 lines (119 loc) · 4.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
name: Release
on:
push:
tags:
- 'v*.*.*'
permissions:
contents: write
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
release:
name: Validate and publish Glaze
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
fetch-tags: true
- name: Validate annotated tag and main provenance
shell: bash
run: |
set -euo pipefail
# actions/checkout resolves a tag event to GITHUB_SHA and may replace
# the local refs/tags/<name> with that peeled commit. Fetch the real
# remote tag into a private namespace before inspecting its object.
release_tag_ref="refs/release-tags/$GITHUB_REF_NAME"
git fetch --force origin \
"refs/tags/$GITHUB_REF_NAME:$release_tag_ref"
if [[ "$(git cat-file -t "$release_tag_ref")" != "tag" ]]; then
echo "release tag must be annotated" >&2
exit 1
fi
if [[ "$(git rev-parse "$release_tag_ref^{}")" != "$GITHUB_SHA" ]]; then
echo "release tag does not point at the workflow commit" >&2
exit 1
fi
git fetch origin main
if ! git merge-base --is-ancestor HEAD origin/main; then
echo "release commit must be part of origin/main" >&2
exit 1
fi
- name: Install Racket
uses: Bogdanp/setup-racket@v1.11
with:
version: '9.3'
- name: Validate release metadata
shell: bash
run: |
set -euo pipefail
if [[ ! "$GITHUB_REF_NAME" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "release tag must be vMAJOR.MINOR.PATCH" >&2
exit 1
fi
tag_version="${GITHUB_REF_NAME#v}"
package_version="$(sed -n 's/^(define version "\([^"]*\)")/\1/p' info.rkt)"
release_version="$(sed -n 's/^(define release-version "\([^"]*\)")/\1/p' info.rkt)"
if ! racket -e '(require version/utils) (exit (if (valid-version? (vector-ref (current-command-line-arguments) 0)) 0 1))' "$package_version"; then
echo "info.rkt version $package_version is not a valid Racket package version" >&2
exit 1
fi
if [[ "$tag_version" != "$release_version" ]]; then
echo "tag version $tag_version does not match release-version $release_version" >&2
exit 1
fi
if ! grep -Eq "^## \\[$release_version\\]( |$)" CHANGELOG.md; then
echo "CHANGELOG.md has no $release_version section" >&2
exit 1
fi
echo "GLAZE_VERSION=$release_version" >> "$GITHUB_ENV"
- name: Install and test Glaze
shell: bash
run: |
set -euo pipefail
raco pkg install --auto --no-docs --name glaze --link "$PWD"
raco test --package glaze
raco scribble ++xref-in setup/xref load-collections-xref \
--htmls --dest "$RUNNER_TEMP/glaze-doc" \
glaze-doc/scribblings/glaze.scrbl
- name: Build source package and release notes
shell: bash
run: |
set -euo pipefail
mkdir -p dist
raco pkg create --from-dir --source --format zip --dest dist "$PWD"
archive="$(find dist -maxdepth 1 -type f -name '*.zip' -print -quit)"
destination="dist/glaze-${GLAZE_VERSION}.zip"
mv "$archive" "$destination"
sha256sum "$destination" > "${destination}.sha256"
awk -v version="$GLAZE_VERSION" '
$0 ~ ("^## \\[" version "\\]") { capture = 1; next }
capture && /^## / { exit }
capture { print }
' CHANGELOG.md > dist/release-notes.md
test -s dist/release-notes.md
- name: Smoke-test exact source package
shell: bash
run: |
set -euo pipefail
smoke_root="$(mktemp -d)"
PLTUSERHOME="$smoke_root/racket-user" \
raco pkg install --auto --no-docs --name glaze \
"$PWD/dist/glaze-${GLAZE_VERSION}.zip"
PLTUSERHOME="$smoke_root/racket-user" \
racket -e '(require glaze glaze/server glaze/events)'
PLTUSERHOME="$smoke_root/racket-user" raco glaze help >/dev/null
- name: Publish GitHub Release
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
gh release create "$GITHUB_REF_NAME" \
"dist/glaze-${GLAZE_VERSION}.zip" \
"dist/glaze-${GLAZE_VERSION}.zip.sha256" \
--verify-tag \
--title "Glaze ${GLAZE_VERSION}" \
--notes-file dist/release-notes.md