Skip to content

Commit 346890b

Browse files
committed
Add attested ZIP release workflow
1 parent 79278cc commit 346890b

1 file changed

Lines changed: 83 additions & 0 deletions

File tree

‎.github/workflows/release.yml‎

Lines changed: 83 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,83 @@
1+
name: Release Semantic WebView2 module
2+
3+
on:
4+
push:
5+
tags:
6+
- "v*"
7+
workflow_dispatch:
8+
inputs:
9+
tag:
10+
description: "Existing tag to package and release"
11+
required: true
12+
type: string
13+
14+
permissions:
15+
contents: write
16+
id-token: write
17+
attestations: write
18+
19+
jobs:
20+
package-and-release:
21+
runs-on: ubuntu-latest
22+
steps:
23+
- name: Check out release ref
24+
uses: actions/checkout@v4
25+
with:
26+
ref: ${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref }}
27+
fetch-depth: 0
28+
29+
- name: Select release tag
30+
id: release
31+
shell: bash
32+
run: |
33+
if [[ "${GITHUB_EVENT_NAME}" == "workflow_dispatch" ]]; then
34+
tag="${{ inputs.tag }}"
35+
else
36+
tag="${GITHUB_REF_NAME}"
37+
fi
38+
if [[ ! "$tag" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([-.].*)?$ ]]; then
39+
echo "Tag must match vMAJOR.MINOR.PATCH[-suffix]: $tag" >&2
40+
exit 1
41+
fi
42+
echo "tag=$tag" >> "$GITHUB_OUTPUT"
43+
44+
- name: Verify module payload
45+
shell: bash
46+
run: |
47+
test -f semantic-webview2.smod
48+
test -f LICENSE.md
49+
test -d semantic
50+
test -d source
51+
test "$(find semantic -type f -name '*.se' | wc -l)" -gt 0
52+
test "$(find semantic -type f -name '*.spz' | wc -l)" -gt 0
53+
test "$(find source -type f | wc -l)" -gt 0
54+
55+
- name: Create release archive
56+
shell: bash
57+
env:
58+
RELEASE_TAG: ${{ steps.release.outputs.tag }}
59+
run: |
60+
rm -rf dist staging
61+
mkdir -p staging/semantic-webview2 dist
62+
git archive --format=tar "$GITHUB_SHA" | tar -xf - -C staging/semantic-webview2
63+
(cd staging && zip -qr "../dist/semantic-webview2-${RELEASE_TAG}.zip" semantic-webview2)
64+
sha256sum "dist/semantic-webview2-${RELEASE_TAG}.zip" > "dist/SHA256SUMS.txt"
65+
echo "Archive: dist/semantic-webview2-${RELEASE_TAG}.zip"
66+
du -h "dist/semantic-webview2-${RELEASE_TAG}.zip"
67+
cat dist/SHA256SUMS.txt
68+
69+
- name: Attest release archive
70+
uses: actions/attest-build-provenance@v2
71+
with:
72+
subject-path: dist/semantic-webview2-${{ steps.release.outputs.tag }}.zip
73+
74+
- name: Publish GitHub release
75+
uses: softprops/action-gh-release@v2
76+
with:
77+
tag_name: ${{ steps.release.outputs.tag }}
78+
name: Semantic WebView2 ${{ steps.release.outputs.tag }}
79+
generate_release_notes: true
80+
files: |
81+
dist/semantic-webview2-${{ steps.release.outputs.tag }}.zip
82+
dist/SHA256SUMS.txt
83+

0 commit comments

Comments
 (0)