-
Notifications
You must be signed in to change notification settings - Fork 1
126 lines (108 loc) · 3.42 KB
/
Copy pathrelease.yml
File metadata and controls
126 lines (108 loc) · 3.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
name: SentinelAI Release
on:
push:
tags:
- "v*.*.*"
pull_request:
paths:
- ".github/workflows/release.yml"
- "CHANGELOG.md"
- "RELEASE_NOTES_v0.1.0.md"
permissions:
contents: read
concurrency:
group: sentinelai-release-${{ github.ref }}
cancel-in-progress: false
jobs:
validate:
name: Validate release candidate
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Verify semantic-version tag and changelog
if: startsWith(github.ref, 'refs/tags/')
shell: bash
run: |
tag="${{ github.ref_name }}"
if [[ ! "$tag" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "Invalid semantic-version tag: $tag" >&2
exit 1
fi
version="${tag#v}"
grep -Fq "## [$version]" CHANGELOG.md
- uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
- name: Install Python test dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements-dev.txt
- name: Run Python test suite
env:
PYTHONPATH: .
run: pytest tests/ -q
- uses: actions/setup-go@v5
with:
go-version: "1.21.x"
cache-dependency-path: ingestion-service/go.sum
- name: Run Go ingestion tests
working-directory: ingestion-service
run: go test ./...
- name: Build ingestion container
run: docker build -t sentinelai-ingestion:release ./ingestion-service
release:
name: Publish GitHub Release
if: startsWith(github.ref, 'refs/tags/')
needs: validate
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Build deterministic source archive and checksum
run: |
mkdir -p dist
git archive --format=tar --prefix="sentinelai-${{ github.ref_name }}/" "${{ github.sha }}" | gzip -n > "dist/sentinelai-${{ github.ref_name }}.tar.gz"
sha256sum "dist/sentinelai-${{ github.ref_name }}.tar.gz" > "dist/sentinelai-${{ github.ref_name }}.tar.gz.sha256"
- name: Publish release
uses: softprops/action-gh-release@v2
with:
body_path: RELEASE_NOTES_v0.1.0.md
generate_release_notes: false
files: |
dist/sentinelai-${{ github.ref_name }}.tar.gz
dist/sentinelai-${{ github.ref_name }}.tar.gz.sha256
publish-container:
name: Publish GHCR ingestion image
if: startsWith(github.ref, 'refs/tags/')
needs: release
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- uses: docker/metadata-action@v5
id: meta
with:
images: ghcr.io/coreyleath-code/sentinelai-ingestion
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- uses: docker/build-push-action@v6
with:
context: ./ingestion-service
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}