Repository navigation
61 lines (49 loc) · 1.88 KB
/
Copy pathrelease.yml
File metadata and controls
61 lines (49 loc) · 1.88 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
name: Release
on:
push:
tags: [ 'v*' ]
permissions:
contents: write
jobs:
release:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
with:
# goreleaser derives the release version from the tag history, which a
# shallow clone does not carry.
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@v7
with:
go-version-file: go.mod
- name: Install just
uses: extractions/setup-just@v4
- name: Install govulncheck
run: go install golang.org/x/vuln/cmd/govulncheck@latest
# A tag can be cut from any commit, not only one that master already proved
# green. Rechecking both the library and binary here is cheaper than a
# published artifact that does not work and a version that cannot be reused.
- name: Run unit tests with the race detector
run: just test-race
- name: Run end-to-end tests
run: just test-e2e
- name: Scan Go dependencies for known vulnerabilities
run: govulncheck ./...
# The release body is the tag's section of CHANGELOG.md, nothing else. This
# fails when that section is missing or empty, which stops the release
# before a single artifact is published -- the recoverable moment to find
# out that a tag was cut without its entry.
#
# Not into dist/: `release --clean` deletes that directory before it reads
# anything, so a notes file written there would be gone by the time
# goreleaser looked for it.
- name: Extract the release notes from CHANGELOG.md
run: just release-notes "${{ github.ref_name }}" > "${{ runner.temp }}/release-notes.md"
- name: Publish the release
uses: goreleaser/goreleaser-action@v7
with:
version: '~> v2'
args: release --clean --release-notes=${{ runner.temp }}/release-notes.md
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}