Skip to content

Decouple release publishing from signing workflow #8

Decouple release publishing from signing workflow

Decouple release publishing from signing workflow #8

Workflow file for this run

name: Release
on:
push:
tags:
- "v*"
permissions:
contents: write
id-token: write
jobs:
build-binary:
name: Build darwin-arm64
runs-on: macos-14
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "20"
cache: npm
cache-dependency-path: web/package-lock.json
- name: Install frontend dependencies
run: |
cd web
npm ci
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
with:
targets: aarch64-apple-darwin
- name: Cache Rust
uses: Swatinem/rust-cache@v2
- name: Build production binary
run: cargo build --release --features production --target aarch64-apple-darwin --locked
- name: Prepare release assets
env:
TAG: ${{ github.ref_name }}
run: |
VERSION="${TAG#v}"
mkdir -p dist
cp "target/aarch64-apple-darwin/release/attn" "dist/attn-v${VERSION}-darwin-arm64"
chmod +x "dist/attn-v${VERSION}-darwin-arm64"
shasum -a 256 "dist/attn-v${VERSION}-darwin-arm64" > "dist/attn-v${VERSION}-darwin-arm64.sha256"
- name: Upload build artifacts
uses: actions/upload-artifact@v4
with:
name: release-darwin-arm64
path: dist/*
retention-days: 7
publish-release:
name: Publish GitHub Release
runs-on: ubuntu-latest
needs: build-binary
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.ref_name }}
- name: Download artifacts
uses: actions/download-artifact@v4
with:
path: dist
- name: Flatten artifact directories
run: |
mkdir -p release-assets
find dist -type f -maxdepth 3 -exec cp {} release-assets/ \;
- name: Create or update release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.ref_name }}
run: |
if gh release view "$TAG" >/dev/null 2>&1; then
echo "Release $TAG already exists; uploading updated assets."
else
gh release create "$TAG" \
--title "$TAG" \
--notes "Automated release for $TAG."
fi
gh release upload "$TAG" release-assets/* --clobber
publish-crates:
name: Publish crates.io
runs-on: ubuntu-latest
needs: publish-release
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.ref_name }}
- name: Install system dependencies
run: |
sudo apt-get update
sudo apt-get install -y libgtk-3-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "24"
cache: npm
cache-dependency-path: web/package-lock.json
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Publish crate
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
run: cargo publish --locked
publish-npm:
name: Publish npm
runs-on: ubuntu-latest
needs: publish-release
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ github.ref_name }}
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: "24"
registry-url: "https://registry.npmjs.org"
- name: Set package version from tag
run: npm version "${GITHUB_REF_NAME#v}" --no-git-tag-version --allow-same-version
- name: Publish package
run: npm publish --access public --provenance