Skip to content

Commit 4aaa511

Browse files
committed
chore: Upgrade cargo-dist and enable gh-attestations
1 parent fc3d578 commit 4aaa511

File tree

2 files changed

+25
-13
lines changed

2 files changed

+25
-13
lines changed

.github/workflows/release.yml

+22-12
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,8 @@ name: Release
1515

1616
permissions:
1717
contents: write
18+
id-token: write
19+
attestations: write
1820

1921
# This task will run whenever you push a git tag that looks like a version
2022
# like "1.0.0", "v0.1.0-prerelease.1", "my-app/0.1.0", "releases/v1.0.0", etc.
@@ -38,15 +40,15 @@ permissions:
3840
# If there's a prerelease-style suffix to the version, then the release(s)
3941
# will be marked as a prerelease.
4042
on:
43+
pull_request:
4144
push:
4245
tags:
4346
- '**[0-9]+.[0-9]+.[0-9]+*'
44-
pull_request:
4547

4648
jobs:
4749
# Run 'cargo dist plan' (or host) to determine what tasks we need to do
4850
plan:
49-
runs-on: ubuntu-latest
51+
runs-on: "ubuntu-20.04"
5052
outputs:
5153
val: ${{ steps.plan.outputs.manifest }}
5254
tag: ${{ !github.event.pull_request && github.ref_name || '' }}
@@ -62,7 +64,7 @@ jobs:
6264
# we specify bash to get pipefail; it guards against the `curl` command
6365
# failing. otherwise `sh` won't catch that `curl` returned non-0
6466
shell: bash
65-
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.14.1/cargo-dist-installer.sh | sh"
67+
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.16.0/cargo-dist-installer.sh | sh"
6668
# sure would be cool if github gave us proper conditionals...
6769
# so here's a doubly-nested ternary-via-truthiness to try to provide the best possible
6870
# functionality based on whether this is a pull_request, and whether it's from a fork.
@@ -114,6 +116,7 @@ jobs:
114116
- uses: swatinem/rust-cache@v2
115117
with:
116118
key: ${{ join(matrix.targets, '-') }}
119+
cache-provider: ${{ matrix.cache_provider }}
117120
- name: Install cargo-dist
118121
run: ${{ matrix.install_dist }}
119122
# Get the dist-manifest
@@ -131,6 +134,10 @@ jobs:
131134
# Actually do builds and make zips and whatnot
132135
cargo dist build ${{ needs.plan.outputs.tag-flag }} --print=linkage --output-format=json ${{ matrix.dist_args }} > dist-manifest.json
133136
echo "cargo dist ran successfully"
137+
- name: Attest
138+
uses: actions/attest-build-provenance@v1
139+
with:
140+
subject-path: "target/distrib/*${{ join(matrix.targets, ', ') }}*"
134141
- id: cargo-dist
135142
name: Post-build
136143
# We force bash here just because github makes it really hard to get values up
@@ -167,7 +174,7 @@ jobs:
167174
submodules: recursive
168175
- name: Install cargo-dist
169176
shell: bash
170-
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.14.1/cargo-dist-installer.sh | sh"
177+
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.16.0/cargo-dist-installer.sh | sh"
171178
# Get all the local artifacts for the global tasks to use (for e.g. checksums)
172179
- name: Fetch local artifacts
173180
uses: actions/download-artifact@v4
@@ -212,7 +219,7 @@ jobs:
212219
with:
213220
submodules: recursive
214221
- name: Install cargo-dist
215-
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.14.1/cargo-dist-installer.sh | sh"
222+
run: "curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.16.0/cargo-dist-installer.sh | sh"
216223
# Fetch artifacts from scratch-storage
217224
- name: Fetch artifacts
218225
uses: actions/download-artifact@v4
@@ -303,10 +310,13 @@ jobs:
303310
# Remove the granular manifests
304311
rm -f artifacts/*-dist-manifest.json
305312
- name: Create GitHub Release
306-
uses: ncipollo/release-action@v1
307-
with:
308-
tag: ${{ needs.plan.outputs.tag }}
309-
name: ${{ fromJson(needs.host.outputs.val).announcement_title }}
310-
body: ${{ fromJson(needs.host.outputs.val).announcement_github_body }}
311-
prerelease: ${{ fromJson(needs.host.outputs.val).announcement_is_prerelease }}
312-
artifacts: "artifacts/*"
313+
env:
314+
PRERELEASE_FLAG: "${{ fromJson(needs.host.outputs.val).announcement_is_prerelease && '--prerelease' || '' }}"
315+
ANNOUNCEMENT_TITLE: "${{ fromJson(needs.host.outputs.val).announcement_title }}"
316+
ANNOUNCEMENT_BODY: "${{ fromJson(needs.host.outputs.val).announcement_github_body }}"
317+
run: |
318+
# Write and read notes from a file to avoid quoting breaking things
319+
echo "$ANNOUNCEMENT_BODY" > $RUNNER_TEMP/notes.txt
320+
321+
gh release create "${{ needs.plan.outputs.tag }}" --title "$ANNOUNCEMENT_TITLE" --notes-file "$RUNNER_TEMP/notes.txt" $PRERELEASE_FLAG
322+
gh release upload "${{ needs.plan.outputs.tag }}" artifacts/*

Cargo.toml

+3-1
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ dist = true
4242
# Config for 'cargo dist'
4343
[workspace.metadata.dist]
4444
# The preferred cargo-dist version to use in CI (Cargo.toml SemVer syntax)
45-
cargo-dist-version = "0.14.1"
45+
cargo-dist-version = "0.16.0"
4646
# CI backends to support
4747
ci = "github"
4848
# The installers to generate for each app
@@ -62,3 +62,5 @@ publish-prerelease = true
6262
pr-run-mode = "plan"
6363
# Whether to install an updater program
6464
install-updater = false
65+
# Whether to enable GitHub Attestations
66+
github-attestations = true

0 commit comments

Comments
 (0)