-
Notifications
You must be signed in to change notification settings - Fork 1
153 lines (141 loc) · 4.53 KB
/
publish-version.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
name: Publish version
on:
push:
branches:
- main
permissions:
contents: read
jobs:
get-current-version:
name: Get version
runs-on: ubuntu-latest
outputs:
doTag: ${{ steps.checkTag.outputs.doTag }}
newVersion: ${{ steps.checkTag.outputs.newVersion }}
steps:
- uses: actions/checkout@v4
- name: Use Python 3.10
uses: actions/setup-python@v5
with:
python-version: "3.10"
- name: Check current tag
id: checkTag
run: |
pip install --disable-pip-version-check -e "."[cicd,client,server,developer]
VERSION=$(python -c "import murfey; print(murfey.__version__)")
echo "newVersion=v$VERSION" >> $GITHUB_OUTPUT
git fetch --tags
if [ $(git tag -l v$VERSION) ]; then
echo "Version is up to date at $VERSION"
echo "doTag=false" >> $GITHUB_OUTPUT
else
echo "Version needs to be updated to $VERSION"
echo "doTag=true" >> $GITHUB_OUTPUT
fi
make-tag:
name: Create a new tag
runs-on: ubuntu-latest
permissions:
contents: write
needs:
- get-current-version
if: ${{ needs.get-current-version.outputs.doTag == 'true' }}
steps:
- uses: actions/checkout@v4
- name: Push the new tag
run: |
git config --global user.name "DiamondLightSource-build-server"
git config --global user.email "[email protected]"
git config credential.helper "store --file=.git/credentials"
echo "https://${GITHUB_TOKEN}:@github.com" > .git/credentials
git tag ${{ needs.get-current-version.outputs.newVersion }}
git push origin ${{ needs.get-current-version.outputs.newVersion }}
build:
name: Build package
runs-on: ubuntu-latest
needs:
- get-current-version
if: ${{ needs.get-current-version.outputs.doTag == 'true' }}
steps:
- uses: actions/checkout@v4
- name: Set up Python 3.10
uses: actions/setup-python@v5
with:
python-version: "3.10"
- name: Install pypa/build
run: >-
python3 -m
pip install
build
--user
- name: Build python package
run: python3 -m build
- name: Store built package artifact
uses: actions/upload-artifact@v4
with:
name: package-distributions
path: dist/
publish-to-pypi:
name: >-
Publish Python distribution to PyPI
needs:
- get-current-version
- build
- make-tag
if: ${{ needs.get-current-version.outputs.doTag == 'true' }}
runs-on: ubuntu-latest
environment:
name: pypi
url: https://pypi.org/p/murfey
permissions:
id-token: write # IMPORTANT: mandatory for trusted publishing
steps:
- name: Download all the dists
uses: actions/download-artifact@v4
with:
name: package-distributions
path: dist/
- name: Publish distribution to PyPI
uses: pypa/gh-action-pypi-publish@release/v1
github-release:
name: >-
Sign the Python distribution with Sigstore
and upload them to GitHub Release
needs:
- get-current-version
- publish-to-pypi
if: ${{ needs.get-current-version.outputs.doTag == 'true' }}
runs-on: ubuntu-latest
permissions:
contents: write # IMPORTANT: mandatory for making GitHub Releases
id-token: write # IMPORTANT: mandatory for sigstore
steps:
- name: Download all the dists
uses: actions/download-artifact@v4
with:
name: package-distributions
path: dist/
- name: Sign the dists with Sigstore
uses: sigstore/[email protected]
with:
inputs: >-
./dist/*.tar.gz
./dist/*.whl
- name: Create GitHub Release
env:
GITHUB_TOKEN: ${{ github.token }}
run: >-
gh release create
'${{ needs.get-current-version.outputs.newVersion }}'
--repo '${{ github.repository }}'
--notes ""
- name: Upload artifact signatures to GitHub Release
env:
GITHUB_TOKEN: ${{ github.token }}
# Upload to GitHub Release using the `gh` CLI.
# `dist/` contains the built packages, and the
# sigstore-produced signatures and certificates.
run: >-
gh release upload
'${{ needs.get-current-version.outputs.newVersion }}' dist/**
--repo '${{ github.repository }}'