-
Notifications
You must be signed in to change notification settings - Fork 0
176 lines (153 loc) · 5.72 KB
/
Copy pathrelease.yml
File metadata and controls
176 lines (153 loc) · 5.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
name: Release
# A release is cut whenever the `version` in Cargo.toml on `main` doesn't yet
# have a matching `v<version>` git tag. The `gate` job below detects that,
# creates the tag, and lets the build/release/crates jobs run in the SAME run.
#
# Why not a separate "auto-tag" workflow? Tags pushed with the default
# GITHUB_TOKEN do NOT trigger other workflows (GitHub blocks this to avoid
# recursion), so a tag-triggered release.yml would never fire. Keeping the
# detection + release in one workflow sidesteps that without needing a PAT.
#
# Pushing a `v*` tag by hand or running this manually still works:
# - tag push -> release that exact tag
# - workflow_dispatch / main push -> release Cargo.toml's version if untagged
on:
push:
branches: [main]
tags:
- "v*"
workflow_dispatch:
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
# Decide whether there's anything to release, and what tag to release.
gate:
runs-on: ubuntu-latest
permissions:
contents: write # push the version tag
outputs:
should_release: ${{ steps.decide.outputs.should_release }}
tag: ${{ steps.decide.outputs.tag }}
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # need full tag list to know what's already released
- name: Decide whether to release
id: decide
shell: bash
run: |
set -euo pipefail
if [ "${{ github.ref_type }}" = "tag" ]; then
# Triggered by an explicit tag push: release exactly that tag.
tag="${{ github.ref_name }}"
echo "Tag push detected: releasing ${tag}."
echo "tag=${tag}" >> "$GITHUB_OUTPUT"
echo "should_release=true" >> "$GITHUB_OUTPUT"
exit 0
fi
# Branch push or manual dispatch: derive the tag from Cargo.toml.
version="$(grep -m1 '^version = ' Cargo.toml | sed -E 's/^version = "([^"]+)".*/\1/')"
tag="v${version}"
echo "tag=${tag}" >> "$GITHUB_OUTPUT"
if git rev-parse "refs/tags/${tag}" >/dev/null 2>&1; then
echo "Tag ${tag} already exists; nothing to release."
echo "should_release=false" >> "$GITHUB_OUTPUT"
else
echo "New version ${version} with no ${tag} tag; tagging + releasing."
echo "should_release=true" >> "$GITHUB_OUTPUT"
fi
- name: Create version tag
# Only when we derived a brand-new tag from Cargo.toml (not on tag push,
# where the tag already exists).
if: steps.decide.outputs.should_release == 'true' && github.ref_type != 'tag'
env:
TAG: ${{ steps.decide.outputs.tag }}
run: |
set -euo pipefail
git tag "$TAG"
git push origin "$TAG"
build:
needs: gate
if: needs.gate.outputs.should_release == 'true'
strategy:
fail-fast: false
matrix:
include:
- { os: macos-14, name: macos-arm64, asset: webview-macos-arm64, bin: webview }
- { os: ubuntu-22.04, name: linux-x64, asset: webview-linux-x64, bin: webview }
- { os: ubuntu-22.04-arm, name: linux-arm64, asset: webview-linux-arm64, bin: webview }
- { os: windows-latest, name: windows-x64, asset: webview-windows-x64.exe, bin: webview.exe }
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v4
- name: Install webview build deps (Linux)
if: runner.os == 'Linux'
run: |
sudo apt-get update
sudo apt-get install -y libwebkit2gtk-4.1-dev libgtk-3-dev
- name: Install tools via mise
uses: jdx/mise-action@6d1e696aa24c1aa1bcc1adea0212707c71ab78a8 # v3.6.1
with:
version: 2026.5.3
- name: Cache cargo build
uses: Swatinem/rust-cache@98c8021b550208e191a6a3145459bfc9fb29c4c0 # v2.8.0
- name: Build release binary
run: cargo build --release
- name: Stage artifact
shell: bash
run: |
mkdir -p dist
cp "target/release/${{ matrix.bin }}" "dist/${{ matrix.asset }}"
- name: Upload ${{ matrix.name }}
uses: actions/upload-artifact@v4
with:
name: ${{ matrix.asset }}
path: dist/${{ matrix.asset }}
if-no-files-found: error
release:
needs: [gate, build]
if: needs.gate.outputs.should_release == 'true'
runs-on: ubuntu-latest
permissions:
contents: write # create the GitHub Release and upload assets
steps:
- name: Download artifacts
uses: actions/download-artifact@v4
with:
path: artifacts
merge-multiple: true
- name: Generate checksums
working-directory: artifacts
run: sha256sum webview-* > SHA256SUMS
- name: Create GitHub Release
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
TAG: ${{ needs.gate.outputs.tag }}
run: |
gh release create "$TAG" \
--title "$TAG" \
--generate-notes \
artifacts/webview-* \
artifacts/SHA256SUMS
crates:
needs: [gate, build]
if: needs.gate.outputs.should_release == 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install webview build deps (Linux)
run: |
sudo apt-get update
sudo apt-get install -y libwebkit2gtk-4.1-dev libgtk-3-dev
- name: Install tools via mise
uses: jdx/mise-action@6d1e696aa24c1aa1bcc1adea0212707c71ab78a8 # v3.6.1
with:
version: 2026.5.3
- name: Publish to crates.io
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
run: cargo publish