Release 0.4.0 #4
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| # Push a tag such as v0.2.0 to release. The tag must match the version in pyproject.toml. | |
| on: | |
| push: | |
| tags: ["v*.*.*"] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: release-${{ github.ref }} | |
| cancel-in-progress: false | |
| jobs: | |
| ci: | |
| name: Lint and Test | |
| uses: ./.github/workflows/ci.yml | |
| # The images are built, scanned and pushed before the release is created, so a release | |
| # never exists without its images. | |
| container: | |
| name: Container images | |
| needs: [ci] | |
| uses: ./.github/workflows/container.yml | |
| with: | |
| ref: ${{ github.ref_name }} | |
| permissions: | |
| contents: read | |
| packages: write | |
| id-token: write | |
| attestations: write | |
| security-events: write | |
| release: | |
| name: Publish the GitHub release | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| needs: [ci, container] | |
| permissions: | |
| # Creating a release and attaching its files is the only write this workflow makes. | |
| contents: write | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7 | |
| # The files the gate built and tested, not a fresh build. | |
| - name: Fetch the build | |
| uses: actions/download-artifact@v8 | |
| with: | |
| name: dist | |
| path: dist/ | |
| - name: Check the tag matches the version | |
| env: | |
| TAG: ${{ github.ref_name }} | |
| run: | | |
| version="$(python3 -c 'import tomllib; print(tomllib.load(open("pyproject.toml", "rb"))["project"]["version"])')" | |
| if [ "v${version}" != "${TAG}" ]; then | |
| echo "::error::tag ${TAG} does not match pyproject.toml version ${version}" | |
| exit 1 | |
| fi | |
| ls dist/*"${version}"*.whl dist/*"${version}"*.tar.gz | |
| - name: Write checksums | |
| run: cd dist && sha256sum -- * > SHA256SUMS | |
| - name: Create the release | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| TAG: ${{ github.ref_name }} | |
| run: gh release create "${TAG}" dist/* --verify-tag --generate-notes --title "${TAG}" |