-
Notifications
You must be signed in to change notification settings - Fork 2
91 lines (82 loc) · 2.72 KB
/
Copy pathrelease.yml
File metadata and controls
91 lines (82 loc) · 2.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
name: Release
on:
push:
tags: ["v*"]
workflow_dispatch:
inputs:
tag:
description: Tag to build binaries for
required: true
# Least privilege by default; only the job that uploads assets asks for write.
permissions:
contents: read
jobs:
binaries:
name: ${{ matrix.target }}
runs-on: ${{ matrix.os }}
permissions:
contents: write
strategy:
fail-fast: false
matrix:
include:
- target: x86_64-unknown-linux-gnu
os: ubuntu-latest
- target: aarch64-apple-darwin
os: macos-latest
- target: x86_64-apple-darwin
os: macos-latest
- target: x86_64-pc-windows-msvc
os: windows-latest
steps:
- uses: actions/checkout@v6
- uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- uses: Swatinem/rust-cache@v2
- run: cargo build --release --target ${{ matrix.target }}
- name: Package (unix)
if: runner.os != 'Windows'
run: |
tar -czf backcheck-${{ matrix.target }}.tar.gz \
-C target/${{ matrix.target }}/release backcheck
- name: Package (windows)
if: runner.os == 'Windows'
run: |
Compress-Archive -Path target/${{ matrix.target }}/release/backcheck.exe `
-DestinationPath backcheck-${{ matrix.target }}.zip
- uses: softprops/action-gh-release@v2
with:
tag_name: ${{ github.event.inputs.tag || github.ref_name }}
files: |
backcheck-${{ matrix.target }}.tar.gz
backcheck-${{ matrix.target }}.zip
fail_on_unmatched_files: false
generate_release_notes: true
crates-io:
name: publish to crates.io
needs: binaries
runs-on: ubuntu-latest
# Only a v* tag can reach this job. The `crates-io` environment additionally restricts
# itself to v* tags and requires a reviewer to approve, so the publish token is
# unreachable from a branch, a pull request, or a fork.
if: startsWith(github.ref, 'refs/tags/v')
environment: crates-io
permissions:
contents: read
steps:
- uses: actions/checkout@v6
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@stable
# Cargo reads CARGO_REGISTRY_TOKEN from the environment. Passing it as a `--token`
# argument instead would expose it in the process list of the runner.
- name: cargo publish
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
run: |
if [ -z "${CARGO_REGISTRY_TOKEN:-}" ]; then
echo "No publish token available; skipping."
exit 0
fi
cargo publish