From b1e456bcb009642b4de3822be52983b9e5588cb0 Mon Sep 17 00:00:00 2001 From: David Perl Date: Thu, 2 Jul 2026 16:37:57 +0200 Subject: [PATCH] feat: add release workflow --- .gitea/workflows/ci.yml | 2 +- .gitea/workflows/publish.yml | 93 ++++++++++++++++++++++++++++++++++++ 2 files changed, 94 insertions(+), 1 deletion(-) create mode 100644 .gitea/workflows/publish.yml diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 45adec3..7289d28 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -1,4 +1,4 @@ -name: Full CI +name: CI on: push: pull_request: diff --git a/.gitea/workflows/publish.yml b/.gitea/workflows/publish.yml new file mode 100644 index 0000000..98317df --- /dev/null +++ b/.gitea/workflows/publish.yml @@ -0,0 +1,93 @@ +name: Build and Publish +on: + workflow_run: + workflows: ["CI"] + # branches: + # - main + types: + - completed + +jobs: + release: + runs-on: ubuntu-latest + concurrency: + group: ${{ github.workflow }}-release-${{ github.ref_name }} + cancel-in-progress: false + if: ${{ github.event.workflow_run.conclusion == 'success' }} + outputs: + release_made: ${{ steps.release_step.outputs.release_made }} + permissions: + contents: write + steps: + # Note: We checkout the repository at the branch that triggered the workflow + # with the entire history to ensure to match PSR's release branch detection + # and history evaluation. + # However, we forcefully reset the branch to the workflow sha because it is + # possible that the branch was updated while the workflow was running. This + # prevents accidentally releasing un-evaluated changes. + - name: Setup | Checkout Repository on Release Branch + uses: actions/checkout@v6 + with: + ref: ${{ github.ref_name }} + fetch-depth: 0 + + - name: Set up Python + uses: actions/setup-python@v6 + with: + python-version: "3.11" + + - name: Setup | Force release branch to be at workflow sha + run: | + git reset --hard ${{ github.sha }} + - name: Evaluate | Verify upstream has NOT changed + # Last chance to abort before causing an error as another PR/push was applied to + # the upstream branch while this workflow was running. This is important + # because we are committing a version change (--commit). You may omit this step + # if you have 'commit: false' in your configuration. + # + # You may consider moving this to a repo script and call it from this step instead + # of writing it in-line. + shell: bash + run: | + set +o pipefail + + UPSTREAM_BRANCH_NAME="$(git status -sb | head -n 1 | cut -d' ' -f2 | grep -E '\.{3}' | cut -d'.' -f4)" + printf '%s\n' "Upstream branch name: $UPSTREAM_BRANCH_NAME" + + set -o pipefail + + if [ -z "$UPSTREAM_BRANCH_NAME" ]; then + printf >&2 '%s\n' "::error::Unable to determine upstream branch name!" + exit 1 + fi + + git fetch "${UPSTREAM_BRANCH_NAME%%/*}" + + if ! UPSTREAM_SHA="$(git rev-parse "$UPSTREAM_BRANCH_NAME")"; then + printf >&2 '%s\n' "::error::Unable to determine upstream branch sha!" + exit 1 + fi + + HEAD_SHA="$(git rev-parse HEAD)" + + if [ "$HEAD_SHA" != "$UPSTREAM_SHA" ]; then + printf >&2 '%s\n' "[HEAD SHA] $HEAD_SHA != $UPSTREAM_SHA [UPSTREAM SHA]" + printf >&2 '%s\n' "::error::Upstream has changed, aborting release..." + exit 1 + fi + + printf '%s\n' "Verified upstream branch has not changed, continuing with release..." + + - name: Semantic Version Release + id: release_step + env: + TWINE_USERNAME: "__token__" # Username for Twine when using token-based auth + TWINE_PASSWORD: ${{ secrets.PIP_REPOSITORY_API_TOKEN }} # Use the secret for authentication + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + pip install python-semantic-release==9.* wheel build twine + semantic-release --config ./ci/semantic_release.toml version + if [ ! -d dist ]; then echo No release will be made; echo "release_made=false" >> "$GITHUB_OUTPUT"; exit 0; fi + echo "release_made=true" >> "$GITHUB_OUTPUT" + twine upload dist/* --repository-url https://gitea.psi.ch/api/packages/mx/pypi -u __token__ -p ${{ secrets.CI_PYPI_TOKEN }} --skip-existing + semantic-release publish -- 2.54.0