* Initial plan * Restrict GitHub workflow token permissions Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com> --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
90 lines
2.9 KiB
YAML
90 lines
2.9 KiB
YAML
name: Build Release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- v*
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build-releases:
|
|
strategy:
|
|
matrix:
|
|
arch: ["linux/amd64 x86_64", "linux/arm/v7 armv7h", "linux/arm64 aarch64"]
|
|
name: Build ${{ matrix.arch }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Set up QEMU
|
|
uses: docker/setup-qemu-action@ce360397dd3f832beb865e1373c09c0e9f86d70a # v4.0.0
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5 # v4.1.0
|
|
|
|
- name: Read info
|
|
id: tags
|
|
run: |
|
|
echo "VERSION=${GITHUB_REF#refs/tags/v}" >> $GITHUB_OUTPUT
|
|
echo "TAG=${GITHUB_REF#refs/tags/}" >> $GITHUB_OUTPUT
|
|
arch="${{ matrix.arch }}"
|
|
echo "PLATFORM=${arch%% *}" >> $GITHUB_OUTPUT
|
|
echo "ARCH=${arch##* }" >> $GITHUB_OUTPUT
|
|
|
|
- name: Build ${{ matrix.arch }} release
|
|
run: |
|
|
mkdir artifacts
|
|
docker buildx build --platform ${{ steps.tags.outputs.platform }} \
|
|
--build-arg VERSION=${{ steps.tags.outputs.version }} \
|
|
--build-arg ARCH=${{ steps.tags.outputs.arch }} \
|
|
--build-arg PREFIX="/usr" \
|
|
-t yay:${{ steps.tags.outputs.arch }} . --load
|
|
make docker-release ARCH=${{ steps.tags.outputs.arch }} VERSION=${{ steps.tags.outputs.version }} PREFIX="/usr"
|
|
mv *.tar.gz artifacts
|
|
|
|
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: yay_${{ steps.tags.outputs.arch }}
|
|
path: artifacts
|
|
|
|
create_release:
|
|
name: Create release from this build
|
|
needs: [build-releases]
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Read info
|
|
id: tags
|
|
run: |
|
|
echo "VERSION=${GITHUB_REF#refs/tags/v}" >> $GITHUB_OUTPUT
|
|
echo "TAG=${GITHUB_REF#refs/tags/}" >> $GITHUB_OUTPUT
|
|
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
pattern: yay_*
|
|
merge-multiple: true
|
|
|
|
- name: Create Release
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
run: |
|
|
gh release create ${{ steps.tags.outputs.tag }} \
|
|
--title "${{ steps.tags.outputs.tag }}" \
|
|
--generate-notes \
|
|
./yay_${{ steps.tags.outputs.version }}_*.tar.gz
|
|
|
|
- name: Release Notary Action
|
|
uses: docker://aevea/release-notary@sha256:690915bf87458fd8eb1e1ff0be34b33377f920eda3f38b96c62ecbf897c831f4
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |