-
Notifications
You must be signed in to change notification settings - Fork 0
95 lines (85 loc) · 3.45 KB
/
Copy pathrelease.yml
File metadata and controls
95 lines (85 loc) · 3.45 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
# Canonical release workflow for GrayCodeAI Go binary repos.
# Triggered by release-please when it pushes a v* tag.
# Source of truth: .shared-templates/workflows/go-release.yml.tmpl
name: release
on:
push:
tags: ["v*"]
permissions:
contents: write
packages: write
id-token: write # for cosign keyless signing if enabled later
jobs:
goreleaser:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0 # goreleaser needs full history for changelog
# Releases must use Gitlink pins only — never a branch head fallback.
- uses: ./.github/actions/checkout-eyrie
with:
allow_branch_fallback: "false"
- name: Verify Gitlink pins present
run: |
set -euo pipefail
missing=0
for repo in hawk-core-contracts eyrie inspect sight tok trace yaad; do
commit=$(git ls-tree HEAD "external/${repo}" | awk '{print $3}' || true)
if [ -z "$commit" ]; then
echo "::error::Release requires Gitlink for external/${repo}"
missing=1
else
head=$(git -C "external/${repo}" rev-parse HEAD)
if [ "$head" != "$commit" ]; then
echo "::error::external/${repo} checked out $head, Gitlink wants $commit"
missing=1
else
echo "OK external/${repo} @ ${commit:0:12}"
fi
fi
done
if [ "$missing" -ne 0 ]; then
exit 1
fi
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: "1.26.5"
cache: true
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7.2.1
with:
distribution: goreleaser
# Must match a real goreleaser release — verify at
# https://github.com/goreleaser/goreleaser/releases before bumping.
version: "v2.17.0"
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Optional secrets used by some repos' goreleaser configs:
HOMEBREW_TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}
TAP_GITHUB_TOKEN: ${{ secrets.TAP_GITHUB_TOKEN }}
# Sign release artifacts with cosign keyless signing. The
# id-token: write permission above enables OIDC federation with
# Fulcio's root CA — no long-lived signing keys to manage.
- name: Install cosign
uses: sigstore/cosign-installer@d8a3f51ef971a853e51de6231a89f4483c5a7a0e # v3.4.0
- name: Sign release checksums with cosign
run: |
set -euo pipefail
# Download the checksums artifact produced by goreleaser.
gh release download "${GITHUB_REF_NAME}" --pattern "checksums.txt" -D dist/
# Sign with keyless OIDC — output is dist/checksums.txt.sig (bundle).
cosign sign-blob \
--yes \
--output-signature dist/checksums.txt.sig \
--output-certificate dist/checksums.txt.cert \
dist/checksums.txt
# Upload the signature and certificate back to the release.
gh release upload "${GITHUB_REF_NAME}" \
dist/checksums.txt.sig \
dist/checksums.txt.cert
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}