Repository navigation
127 lines (121 loc) · 5.27 KB
/
Copy pathrelease.yml
File metadata and controls
127 lines (121 loc) · 5.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
# Copyright (c) 2026 devlive-community/grantforge
#
# Licensed under the MIT License. See the LICENSE file in the
# project root for full license text.
name: Release
# A release is a pushed tag v<version>, which script/release/tag.sh makes (D-83, D-90): script/ci/release.sh builds the
# distribution, its SBOM and checksums and writes the notes from the commits since the previous release; this
# workflow then publishes the image to GHCR, the Maven artifacts to GitHub Packages and, when the CENTRAL_USERNAME,
# CENTRAL_PASSWORD, GPG_PRIVATE_KEY and GPG_PASSPHRASE secrets are set, to Maven Central, and last the GitHub release.
# Versions with -rc.N are pre-releases and do not move the image's latest tag.
on:
push:
tags: ['v*']
permissions:
contents: read
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
env:
IMAGE: ghcr.io/${{ github.repository }}
jobs:
release:
name: Build and publish the release
runs-on: ubuntu-latest
timeout-minutes: 60
permissions:
contents: write
packages: write
env:
CENTRAL_CONFIGURED: ${{ secrets.CENTRAL_USERNAME != '' && secrets.GPG_PRIVATE_KEY != '' }}
steps:
- uses: actions/checkout@v6
with:
# The notes list the commits since the previous release tag.
fetch-depth: 0
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: '21'
cache: maven
- uses: pnpm/action-setup@v4
with:
version: 8.10.2
- uses: actions/setup-node@v6
with:
node-version: '22'
cache: pnpm
cache-dependency-path: core/grantforge-web/pnpm-lock.yaml
- name: Build the distribution, SBOM, checksums and notes
id: build
run: |
bash script/ci/release.sh "${GITHUB_REF_NAME}"
version="${GITHUB_REF_NAME#v}"
echo "version=${version}" >> "${GITHUB_OUTPUT}"
if [[ "${version}" == *-rc.* ]]; then echo "prerelease=true" >> "${GITHUB_OUTPUT}"; else echo "prerelease=false" >> "${GITHUB_OUTPUT}"; fi
- uses: docker/setup-qemu-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Publish the image
env:
VERSION: ${{ steps.build.outputs.version }}
PRERELEASE: ${{ steps.build.outputs.prerelease }}
run: |
tags=(--tag "${IMAGE}:${VERSION}")
if [[ "${PRERELEASE}" == "false" ]]; then tags+=(--tag "${IMAGE}:latest"); fi
docker buildx build --platform linux/amd64,linux/arm64 --push "${tags[@]}" \
--label "org.opencontainers.image.version=${VERSION}" \
--label "org.opencontainers.image.source=${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}" \
--label "org.opencontainers.image.revision=${GITHUB_SHA}" \
--label "org.opencontainers.image.licenses=MIT" \
--build-arg "RELEASE=grantforge-${VERSION}.tar.gz" \
-f deploy/docker/Dockerfile target/release
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: '21'
server-id: github
server-username: GITHUB_ACTOR
server-password: GITHUB_TOKEN
- name: Publish the Maven artifacts to GitHub Packages
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
./mvnw --batch-mode --no-transfer-progress -Prelease -Dgpg.skip -DskipTests deploy \
"-DaltDeploymentRepository=github::https://maven.pkg.github.com/${GITHUB_REPOSITORY}"
- uses: actions/setup-java@v6
if: env.CENTRAL_CONFIGURED == 'true'
with:
distribution: temurin
java-version: '21'
server-id: central
server-username: CENTRAL_USERNAME
server-password: CENTRAL_PASSWORD
gpg-private-key: ${{ secrets.GPG_PRIVATE_KEY }}
gpg-passphrase: MAVEN_GPG_PASSPHRASE
- name: Publish the Maven artifacts to Maven Central
if: env.CENTRAL_CONFIGURED == 'true'
env:
CENTRAL_USERNAME: ${{ secrets.CENTRAL_USERNAME }}
CENTRAL_PASSWORD: ${{ secrets.CENTRAL_PASSWORD }}
MAVEN_GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }}
run: ./mvnw --batch-mode --no-transfer-progress -Prelease,central -Dcentral.skip=false -DskipTests deploy
- name: Skip Maven Central
if: env.CENTRAL_CONFIGURED != 'true'
run: echo "::notice::Maven Central skipped; set CENTRAL_USERNAME, CENTRAL_PASSWORD, GPG_PRIVATE_KEY and GPG_PASSPHRASE to publish there"
- name: Publish the GitHub release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
VERSION: ${{ steps.build.outputs.version }}
PRERELEASE: ${{ steps.build.outputs.prerelease }}
run: |
flags=()
if [[ "${PRERELEASE}" == "true" ]]; then flags+=(--prerelease); else flags+=(--latest); fi
gh release create "${GITHUB_REF_NAME}" --verify-tag --title "GrantForge ${VERSION}" \
--notes-file target/release/notes.md "${flags[@]}" \
"target/release/grantforge-${VERSION}.tar.gz" "target/release/grantforge-${VERSION}.sbom.json" \
target/release/SHA256SUMS