v0.9.4-rc1 changelog notes (#437) #51
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Draft Release | |
| on: | |
| push: | |
| tags: | |
| - "v*" | |
| permissions: | |
| contents: write | |
| packages: write | |
| id-token: write | |
| jobs: | |
| # Builds the x64 and arm64 binary for Linux via the Docker builder | |
| build-binaries-linux: | |
| strategy: | |
| matrix: | |
| target: | |
| - amd64 | |
| - arm64 | |
| name: | |
| - commit-boost | |
| include: | |
| - target: amd64 | |
| package-suffix: x86-64 | |
| - target: arm64 | |
| package-suffix: arm64 | |
| - name: commit-boost | |
| target-crate: commit-boost | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| submodules: true | |
| - name: Log commit hash | |
| run: | | |
| echo "Releasing commit: $(git rev-parse HEAD)" | |
| - name: Set lowercase owner | |
| run: echo "OWNER=$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v3 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build binary (Linux) | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| push: false | |
| platforms: linux/amd64,linux/arm64 | |
| cache-from: type=registry,ref=ghcr.io/${{ env.OWNER }}/buildcache:${{ matrix.target-crate}} | |
| cache-to: type=registry,ref=ghcr.io/${{ env.OWNER }}/buildcache:${{ matrix.target-crate }},mode=max | |
| file: provisioning/build.Dockerfile | |
| outputs: type=local,dest=build | |
| build-args: | | |
| TARGET_CRATE=${{ matrix.name }} | |
| - name: Package binary (Linux) | |
| run: | | |
| cd build/linux_${{ matrix.target }} | |
| tar -czvf ${{ matrix.name }}-${{ github.ref_name }}-linux_${{ matrix.package-suffix }}.tar.gz ${{ matrix.name }} | |
| mv ${{ matrix.name }}-${{ github.ref_name }}-linux_${{ matrix.package-suffix }}.tar.gz ../../ | |
| - name: Upload artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: ${{ matrix.name }}-${{ github.ref_name }}-linux_${{ matrix.package-suffix }} | |
| path: | | |
| ${{ matrix.name }}-${{ github.ref_name }}-linux_${{ matrix.package-suffix }}.tar.gz | |
| # Builds the arm64 binary for Darwin natively | |
| build-binaries-darwin: | |
| strategy: | |
| matrix: | |
| target: | |
| # x64 requires macos-latest-large which is not available in the free tier | |
| # - x86_64-apple-darwin | |
| - aarch64-apple-darwin | |
| name: | |
| - commit-boost | |
| include: | |
| # - target: x86_64-apple-darwin | |
| # os: macos-latest-large | |
| # package-suffix: x86-64 | |
| - target: aarch64-apple-darwin | |
| os: macos-latest | |
| package-suffix: arm64 | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| submodules: true | |
| - name: Log commit hash | |
| run: | | |
| echo "Releasing commit: $(git rev-parse HEAD)" | |
| - name: Install Protoc | |
| run: | |
| # Brew's version is much more up to date than the Linux ones, and installing the latest via script runs into curl issues so for now, brew's easier to use | |
| # provisioning/protoc.sh | |
| brew install protobuf | |
| - name: Cache Cargo registry | |
| uses: actions/cache@v3 | |
| with: | |
| path: ~/.cargo/registry | |
| key: ${{ runner.os }}-cargo-registry-${{ hashFiles('**/Cargo.lock') }} | |
| - name: Cache Cargo index | |
| uses: actions/cache@v3 | |
| with: | |
| path: ~/.cargo/git | |
| key: ${{ runner.os }}-cargo-git-${{ hashFiles('**/Cargo.lock') }} | |
| - name: Cache Cargo build | |
| uses: actions/cache@v3 | |
| with: | |
| path: target | |
| key: ${{ runner.os }}-cargo-build-${{ matrix.target }}-${{ matrix.name }}-${{ hashFiles('**/Cargo.lock') }} | |
| restore-keys: | | |
| ${{ runner.os }}-cargo-build-${{ matrix.target }}-${{ matrix.name }}- | |
| ${{ runner.os }}-cargo-build-${{ matrix.target }}- | |
| ${{ runner.os }}-cargo-build- | |
| - name: Build binary (Darwin) | |
| run: cargo build --release --target ${{ matrix.target }} --bin ${{ matrix.name }} | |
| - name: Package binary (Darwin) | |
| run: | | |
| cd target/${{ matrix.target }}/release | |
| tar -czvf ${{ matrix.name }}-${{ github.ref_name }}-darwin_${{ matrix.package-suffix }}.tar.gz ${{ matrix.name }} | |
| mv ${{ matrix.name }}-${{ github.ref_name }}-darwin_${{ matrix.package-suffix }}.tar.gz ../../../ | |
| - name: Upload artifact | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: ${{ matrix.name }}-${{ github.ref_name }}-darwin_${{ matrix.package-suffix }} | |
| path: | | |
| ${{ matrix.name }}-${{ github.ref_name }}-darwin_${{ matrix.package-suffix }}.tar.gz | |
| # Signs the binaries | |
| sign-binaries: | |
| needs: | |
| - build-binaries-linux | |
| - build-binaries-darwin | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Download artifacts | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: ./artifacts | |
| pattern: "commit-boost*" | |
| - name: Sign binaries | |
| uses: sigstore/gh-action-sigstore-python@a5caf349bc536fbef3668a10ed7f5cd309a4b53d #v3.2.0 | |
| with: | |
| inputs: ./artifacts/**/*.tar.gz | |
| - name: Upload signatures | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: signatures-${{ github.ref_name }} | |
| path: | | |
| ./artifacts/**/*.sigstore.json | |
| # Builds the PBS Docker image | |
| build-and-push-pbs-docker: | |
| needs: [build-binaries-linux] | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| submodules: true | |
| - name: Download binary archives | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: ./artifacts | |
| pattern: "commit-boost*" | |
| - name: Extract binaries | |
| run: | | |
| mkdir -p ./artifacts/bin/linux_amd64 | |
| mkdir -p ./artifacts/bin/linux_arm64 | |
| tar -xzf ./artifacts/commit-boost-${{ github.ref_name }}-linux_x86-64/commit-boost-${{ github.ref_name }}-linux_x86-64.tar.gz -C ./artifacts/bin | |
| mv ./artifacts/bin/commit-boost ./artifacts/bin/linux_amd64/commit-boost | |
| tar -xzf ./artifacts/commit-boost-${{ github.ref_name }}-linux_arm64/commit-boost-${{ github.ref_name }}-linux_arm64.tar.gz -C ./artifacts/bin | |
| mv ./artifacts/bin/commit-boost ./artifacts/bin/linux_arm64/commit-boost | |
| - name: Set lowercase owner | |
| run: echo "OWNER=$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v3 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push PBS Docker image | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| push: true | |
| platforms: linux/amd64,linux/arm64 | |
| build-args: | | |
| BINARIES_PATH=./artifacts/bin | |
| tags: | | |
| ghcr.io/${{ env.OWNER }}/pbs:${{ github.ref_name }} | |
| ${{ !contains(github.ref_name, 'rc') && format('ghcr.io/{0}/pbs:latest', env.OWNER) || '' }} | |
| file: provisioning/pbs.Dockerfile | |
| # Builds the Signer Docker image | |
| build-and-push-signer-docker: | |
| needs: [build-binaries-linux] | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| submodules: true | |
| - name: Download binary archives | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: ./artifacts | |
| pattern: "commit-boost*" | |
| - name: Extract binaries | |
| run: | | |
| mkdir -p ./artifacts/bin/linux_amd64 | |
| mkdir -p ./artifacts/bin/linux_arm64 | |
| tar -xzf ./artifacts/commit-boost-${{ github.ref_name }}-linux_x86-64/commit-boost-${{ github.ref_name }}-linux_x86-64.tar.gz -C ./artifacts/bin | |
| mv ./artifacts/bin/commit-boost ./artifacts/bin/linux_amd64/commit-boost | |
| tar -xzf ./artifacts/commit-boost-${{ github.ref_name }}-linux_arm64/commit-boost-${{ github.ref_name }}-linux_arm64.tar.gz -C ./artifacts/bin | |
| mv ./artifacts/bin/commit-boost ./artifacts/bin/linux_arm64/commit-boost | |
| - name: Set lowercase owner | |
| run: echo "OWNER=$(echo '${{ github.repository_owner }}' | tr '[:upper:]' '[:lower:]')" >> $GITHUB_ENV | |
| - name: Set up QEMU | |
| uses: docker/setup-qemu-action@v3 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Login to GitHub Container Registry | |
| uses: docker/login-action@v3 | |
| with: | |
| registry: ghcr.io | |
| username: ${{ github.actor }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Build and push Signer Docker image | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: . | |
| push: true | |
| platforms: linux/amd64,linux/arm64 | |
| build-args: | | |
| BINARIES_PATH=./artifacts/bin | |
| tags: | | |
| ghcr.io/${{ env.OWNER }}/signer:${{ github.ref_name }} | |
| ${{ !contains(github.ref_name, 'rc') && format('ghcr.io/{0}/signer:latest', env.OWNER) || '' }} | |
| file: provisioning/signer.Dockerfile | |
| # Creates a release on GitHub with the binaries | |
| finalize-release: | |
| needs: | |
| - build-binaries-linux | |
| - build-binaries-darwin | |
| - sign-binaries | |
| - build-and-push-pbs-docker | |
| - build-and-push-signer-docker | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/create-github-app-token@v1 | |
| id: app-token | |
| with: | |
| app-id: ${{ secrets.APP_ID }} | |
| private-key: ${{ secrets.APP_PRIVATE_KEY }} | |
| - name: Checkout code | |
| uses: actions/checkout@v4 | |
| with: | |
| token: ${{ steps.app-token.outputs.token }} | |
| - name: Download binaries | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: ./artifacts | |
| pattern: "commit-boost*" | |
| - name: Download signatures | |
| uses: actions/download-artifact@v4 | |
| with: | |
| path: ./artifacts | |
| pattern: "signatures-${{ github.ref_name }}*" | |
| - name: Finalize Release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| files: ./artifacts/**/* | |
| draft: false | |
| prerelease: ${{ contains(github.ref_name, '-rc') }} | |
| tag_name: ${{ github.ref_name }} | |
| name: ${{ github.ref_name }} | |
| generate_release_notes: true | |
| env: | |
| GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} | |
| # Fast-forwards stable (full release) or beta (RC) to the new tag. | |
| # Runs after all artifacts are built and the draft release is created, | |
| # so stable/beta are never touched if any part of the pipeline fails. | |
| fast-forward-branch: | |
| needs: | |
| - finalize-release | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/create-github-app-token@v1 | |
| id: app-token | |
| with: | |
| app-id: ${{ secrets.APP_ID }} | |
| private-key: ${{ secrets.APP_PRIVATE_KEY }} | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| token: ${{ steps.app-token.outputs.token }} | |
| - name: Configure git | |
| run: | | |
| git config user.name "commit-boost-release-bot[bot]" | |
| git config user.email "commit-boost-release-bot[bot]@users.noreply.github.com" | |
| - name: Fast-forward beta branch (RC releases) | |
| if: contains(github.ref_name, '-rc') | |
| run: | | |
| git checkout beta | |
| git merge --ff-only "${{ github.ref_name }}" | |
| git push origin beta | |
| - name: Fast-forward stable branch (full releases) | |
| if: "!contains(github.ref_name, '-rc')" | |
| run: | | |
| git checkout stable | |
| git merge --ff-only "${{ github.ref_name }}" | |
| git push origin stable | |
| # Deletes the tag if any job in the release pipeline fails. | |
| # This keeps the tag and release artifacts in sync — a tag should only | |
| # exist if the full pipeline completed successfully. | |
| # stable/beta are never touched on failure since fast-forward-branch | |
| # only runs after finalize-release succeeds. | |
| # | |
| # Note: if finalize-release specifically fails, a draft release may already | |
| # exist on GitHub pointing at the now-deleted tag and will need manual cleanup. | |
| cleanup-on-failure: | |
| needs: | |
| - build-binaries-linux | |
| - build-binaries-darwin | |
| - sign-binaries | |
| - build-and-push-pbs-docker | |
| - build-and-push-signer-docker | |
| - finalize-release | |
| - fast-forward-branch | |
| runs-on: ubuntu-latest | |
| if: failure() | |
| steps: | |
| - uses: actions/create-github-app-token@v1 | |
| id: app-token | |
| with: | |
| app-id: ${{ secrets.APP_ID }} | |
| private-key: ${{ secrets.APP_PRIVATE_KEY }} | |
| - uses: actions/checkout@v4 | |
| with: | |
| token: ${{ steps.app-token.outputs.token }} | |
| - name: Delete tag | |
| run: git push origin --delete ${{ github.ref_name }} |