Repository navigation
85 lines (73 loc) · 3.46 KB
/
Copy pathrelease.yml
File metadata and controls
85 lines (73 loc) · 3.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
# Release workflow for rho. A maintainer pushes a v<VERSION> tag after the
# release PR (VERSION + CHANGELOG) has merged; creating v* tags is restricted by
# the repository ruleset "protect-release-tags". See docs/RELEASING.md.
# Source of truth: .shared-templates/workflows/go-release.yml.tmpl
name: release
on:
push:
tags: ["v*"]
permissions:
contents: write # create the GitHub release and upload its assets
id-token: write # cosign keyless signing (GitHub OIDC -> Sigstore Fulcio)
concurrency:
group: release-${{ github.ref }}
cancel-in-progress: false
jobs:
goreleaser:
runs-on: ubuntu-latest
env:
GOPROXY: "https://proxy.golang.org,direct"
# Release builds resolve every dependency (including flux) from
# go.mod/go.sum through the public proxy — never from sibling checkouts.
GOWORK: "off"
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0 # goreleaser needs full history for changelog
persist-credentials: false
# Refuses a tag that disagrees with VERSION or has no CHANGELOG section,
# and extracts that section as the release notes.
- name: Check tag against VERSION and CHANGELOG
run: bash ./scripts/check-release-tag.sh --notes "${RUNNER_TEMP}/release-notes.md" "${GITHUB_REF_NAME}"
- name: Set up Go
uses: actions/setup-go@4a3601121dd01d1626a1e23e37211e3254c1c06c # v6.4.0
with:
go-version: "1.26.6"
cache: true
- name: Refuse local replace directives
run: bash ./scripts/check-no-replace-directives.sh
# GoReleaser shells out to syft for the `sboms:` stanza; the runner image
# does not ship it.
- name: Install syft
uses: anchore/sbom-action/download-syft@3ad7283483fc7af8ff2b4ea19663c2d5ca935e26 # v0.24.2
# GoReleaser shells out to cosign for the `signs:` stanza (keyless
# signature over checksums.txt, uploaded as checksums.txt.sigstore.json).
- name: Install cosign
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7.2.1
with:
distribution: goreleaser
# Must match a real goreleaser release — verify at
# https://github.com/goreleaser/goreleaser/releases before bumping.
version: "v2.17.0"
args: release --clean --release-notes=${{ runner.temp }}/release-notes.md
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Verify the published signature
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
# Re-download what users will download and verify it the way
# install.sh does, so a broken signature fails this run loudly.
verify_dir="$(mktemp -d)"
gh release download "${GITHUB_REF_NAME}" --repo "${GITHUB_REPOSITORY}" \
--pattern checksums.txt --pattern checksums.txt.sigstore.json \
--dir "${verify_dir}"
cosign verify-blob \
--bundle "${verify_dir}/checksums.txt.sigstore.json" \
--certificate-identity "https://github.com/${GITHUB_REPOSITORY}/.github/workflows/release.yml@${GITHUB_REF}" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
"${verify_dir}/checksums.txt"