1- name : Release Semantic WebView2 module
1+ name : Attested main-branch archive
22
33on :
44 push :
5- tags :
6- - " v* "
5+ branches :
6+ - main
77 workflow_dispatch :
8- inputs :
9- tag :
10- description : " Existing tag to package and release"
11- required : true
12- type : string
138
149permissions :
15- contents : write
10+ contents : read
1611 id-token : write
1712 attestations : write
1813
1914jobs :
20- package-and-release :
15+ archive-main :
2116 runs-on : ubuntu-latest
2217 steps :
23- - name : Check out release ref
18+ - name : Check out main
2419 uses : actions/checkout@v4
2520 with :
26- ref : ${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref }}
21+ ref : main
2722 fetch-depth : 0
2823
29- - name : Select release tag
30- id : release
31- shell : bash
32- run : |
33- if [[ "${GITHUB_EVENT_NAME}" == "workflow_dispatch" ]]; then
34- tag="${{ inputs.tag }}"
35- else
36- tag="${GITHUB_REF_NAME}"
37- fi
38- if [[ ! "$tag" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([-.].*)?$ ]]; then
39- echo "Tag must match vMAJOR.MINOR.PATCH[-suffix]: $tag" >&2
40- exit 1
41- fi
42- echo "tag=$tag" >> "$GITHUB_OUTPUT"
43-
4424 - name : Verify module payload
4525 shell : bash
4626 run : |
@@ -52,32 +32,30 @@ jobs:
5232 test "$(find semantic -type f -name '*.spz' | wc -l)" -gt 0
5333 test "$(find source -type f | wc -l)" -gt 0
5434
55- - name : Create release archive
35+ - name : Create main archive
5636 shell : bash
57- env :
58- RELEASE_TAG : ${{ steps.release.outputs.tag }}
5937 run : |
6038 rm -rf dist staging
6139 mkdir -p staging/semantic-webview2 dist
62- git archive --format=tar "$GITHUB_SHA" | tar -xf - -C staging/semantic-webview2
63- (cd staging && zip -qr "../dist/semantic-webview2-${RELEASE_TAG }.zip" semantic-webview2)
64- sha256sum "dist/semantic-webview2-${RELEASE_TAG }.zip" > " dist/SHA256SUMS.txt"
65- echo "Archive: dist/semantic-webview2-${RELEASE_TAG}.zip"
66- du -h "dist/semantic-webview2-${RELEASE_TAG }.zip"
40+ git archive --format=tar HEAD | tar -xf - -C staging/semantic-webview2
41+ (cd staging && zip -qr "../dist/semantic-webview2-main-${GITHUB_SHA }.zip" semantic-webview2)
42+ sha256sum "dist/semantic-webview2-main-${GITHUB_SHA }.zip" > dist/SHA256SUMS.txt
43+ printf 'commit=%s\n' "$GITHUB_SHA" > dist/MAIN_COMMIT.txt
44+ du -h "dist/semantic-webview2-main-${GITHUB_SHA }.zip"
6745 cat dist/SHA256SUMS.txt
6846
69- - name : Attest release archive
47+ - name : Attest main archive
7048 uses : actions/attest-build-provenance@v2
7149 with :
72- subject-path : dist/semantic-webview2-${{ steps.release.outputs.tag }}.zip
50+ subject-path : dist/semantic-webview2-main- ${{ github.sha }}.zip
7351
74- - name : Publish GitHub release
75- uses : softprops/action-gh-release@v2
52+ - name : Upload attested main archive
53+ uses : actions/upload-artifact@v4
7654 with :
77- tag_name : ${{ steps.release.outputs.tag }}
78- name : Semantic WebView2 ${{ steps.release.outputs.tag }}
79- generate_release_notes : true
80- files : |
81- dist/semantic-webview2-${{ steps.release.outputs.tag }}.zip
82- dist/SHA256SUMS.txt
83-
55+ name : semantic-webview2-main- ${{ github.sha }}
56+ path : |
57+ dist/semantic-webview2-main-${{ github.sha }}.zip
58+ dist/SHA256SUMS.txt
59+ dist/MAIN_COMMIT.txt
60+ if-no-files-found : error
61+ retention-days : 90
0 commit comments