Skip to content

Release 0.4.0

Release 0.4.0 #4

Workflow file for this run

name: Release
# Push a tag such as v0.2.0 to release. The tag must match the version in pyproject.toml.
on:
push:
tags: ["v*.*.*"]
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
ci:
name: Lint and Test
uses: ./.github/workflows/ci.yml
# The images are built, scanned and pushed before the release is created, so a release
# never exists without its images.
container:
name: Container images
needs: [ci]
uses: ./.github/workflows/container.yml
with:
ref: ${{ github.ref_name }}
permissions:
contents: read
packages: write
id-token: write
attestations: write
security-events: write
release:
name: Publish the GitHub release
runs-on: ubuntu-latest
timeout-minutes: 10
needs: [ci, container]
permissions:
# Creating a release and attaching its files is the only write this workflow makes.
contents: write
steps:
- name: Checkout
uses: actions/checkout@v7
# The files the gate built and tested, not a fresh build.
- name: Fetch the build
uses: actions/download-artifact@v8
with:
name: dist
path: dist/
- name: Check the tag matches the version
env:
TAG: ${{ github.ref_name }}
run: |
version="$(python3 -c 'import tomllib; print(tomllib.load(open("pyproject.toml", "rb"))["project"]["version"])')"
if [ "v${version}" != "${TAG}" ]; then
echo "::error::tag ${TAG} does not match pyproject.toml version ${version}"
exit 1
fi
ls dist/*"${version}"*.whl dist/*"${version}"*.tar.gz
- name: Write checksums
run: cd dist && sha256sum -- * > SHA256SUMS
- name: Create the release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ github.ref_name }}
run: gh release create "${TAG}" dist/* --verify-tag --generate-notes --title "${TAG}"