Skip to content

chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.1 #38

chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.1

chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.1 #38

Workflow file for this run

name: Release publish
on:
pull_request:
types: [closed]
permissions:
contents: read
concurrency:
group: release-publish-${{ github.event.pull_request.number }}
cancel-in-progress: false
env:
CARGO_INCREMENTAL: "0"
RUST_BACKTRACE: "1"
jobs:
validate-release-pr:
name: Validate release change
if: >-
github.event.pull_request.merged == true &&
github.event.pull_request.base.ref == github.event.repository.default_branch &&
github.event.pull_request.head.repo.full_name == github.repository &&
startsWith(github.event.pull_request.head.ref, 'release/v') &&
contains(github.event.pull_request.labels.*.name, 'release')
runs-on: ubuntu-24.04
timeout-minutes: 20
permissions:
contents: read
pull-requests: read
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 0
- name: Install pinned Rust toolchain
shell: bash
run: |
set -euo pipefail
rustup toolchain install 1.97.1 --profile minimal
rustup default 1.97.1
- name: Install pinned git-cliff
uses: taiki-e/install-action@b20dedce73af6905cdc30d6611090c9b67557c8d # v2
with:
tool: git-cliff@2.9.1
- name: Verify the merged change is release-only
id: release-change
shell: bash
env:
GH_TOKEN: ${{ github.token }}
MERGE_SHA: ${{ github.event.pull_request.merge_commit_sha }}
PULL_NUMBER: ${{ github.event.pull_request.number }}
RELEASE_BRANCH: ${{ github.event.pull_request.head.ref }}
INITIAL_RELEASE: ${{ contains(github.event.pull_request.labels.*.name, 'initial-release') }}
run: bash scripts/release/validate-release-change.sh
- name: Verify the generated changelog matches the release commit
shell: bash
env:
TAG: v${{ steps.release-change.outputs.version }}
run: |
set -euo pipefail
expected="${RUNNER_TEMP}/expected-changelog.md"
git cliff --config .config/cliff.toml --tag "$TAG" -o "$expected"
if ! cmp --silent "$expected" CHANGELOG.md; then
echo "::error::CHANGELOG.md is stale; refresh the release PR against main and regenerate it."
exit 1
fi
wait-ci:
name: Wait for merge CI
needs: validate-release-pr
runs-on: ubuntu-24.04
timeout-minutes: 65
permissions:
actions: read
contents: read
outputs:
run_id: ${{ steps.find.outputs.run_id }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 0
- name: Wait for successful CI on the release commit
id: find
shell: bash
env:
GH_TOKEN: ${{ github.token }}
SHA: ${{ github.event.pull_request.merge_commit_sha }}
run: bash scripts/release/wait-for-merge-ci.sh
hosted-e2e:
name: Run release hosted WSL E2E
needs: wait-ci
uses: ./.github/workflows/hosted-wsl-e2e.yml
with:
checkout_ref: ${{ github.event.pull_request.merge_commit_sha }}
permissions:
actions: write
contents: read
sign-package-publish:
name: Sign and publish
needs: [validate-release-pr, wait-ci, hosted-e2e]
runs-on: windows-2022
environment: release
timeout-minutes: 45
permissions:
actions: read
artifact-metadata: write
attestations: write
contents: write
id-token: write
steps:
- name: Mint release publication token
id: app-token
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3
with:
app-id: ${{ secrets.RELEASE_APP_ID }}
private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }}
permission-contents: write
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ github.event.pull_request.merge_commit_sha }}
fetch-depth: 0
- name: Install pinned git-cliff
uses: taiki-e/install-action@b20dedce73af6905cdc30d6611090c9b67557c8d # v2
with:
tool: git-cliff@2.9.1
- name: Validate package version and release tag
id: version
shell: pwsh
env:
RELEASE_SHA: ${{ github.event.pull_request.merge_commit_sha }}
run: .\scripts\release\Get-ReleasePackageTag.ps1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: windows-release
path: artifacts/Release
run-id: ${{ needs.wait-ci.outputs.run_id }}
github-token: ${{ github.token }}
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: linux-release
path: artifacts/Release/linux
run-id: ${{ needs.wait-ci.outputs.run_id }}
github-token: ${{ github.token }}
- name: Restore pinned WiX v5 tool
shell: pwsh
run: dotnet tool restore
- name: Prepare unsigned package stage
shell: pwsh
run: .\scripts\package.ps1 -Configuration Release -SkipBuild -PrepareOnly
- name: Validate Azure Artifact Signing configuration
env:
AZURE_CLIENT_ID: ${{ vars.AZURE_CLIENT_ID }}
AZURE_TENANT_ID: ${{ vars.AZURE_TENANT_ID }}
AZURE_SUBSCRIPTION_ID: ${{ vars.AZURE_SUBSCRIPTION_ID }}
AZURE_ARTIFACT_SIGNING_ENDPOINT: ${{ vars.AZURE_ARTIFACT_SIGNING_ENDPOINT }}
AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME: ${{ vars.AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME }}
AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME: ${{ vars.AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME }}
shell: pwsh
run: .\scripts\release\Assert-AzureArtifactSigningConfiguration.ps1
- name: Azure login for Artifact Signing
uses: azure/login@f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca # v3.0.1
with:
client-id: ${{ vars.AZURE_CLIENT_ID }}
tenant-id: ${{ vars.AZURE_TENANT_ID }}
subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }}
- name: Sign staged Windows payload with Azure Artifact Signing
uses: Azure/artifact-signing-action@c7ab2a863ab5f9a846ddb8265964877ef296ee82 # v2.0.0
with:
endpoint: ${{ vars.AZURE_ARTIFACT_SIGNING_ENDPOINT }}
signing-account-name: ${{ vars.AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME }}
certificate-profile-name: ${{ vars.AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME }}
files: |
${{ github.workspace }}\packages\stage\Release\windows\wincred-libsecret-wsl-plugin.dll
${{ github.workspace }}\packages\stage\Release\windows\wincred-libsecret.exe
${{ github.workspace }}\packages\stage\Release\windows\wincred-libsecret-broker.exe
file-digest: SHA256
timestamp-digest: SHA256
exclude-environment-credential: true
exclude-workload-identity-credential: true
exclude-managed-identity-credential: true
exclude-shared-token-cache-credential: true
exclude-visual-studio-credential: true
exclude-visual-studio-code-credential: true
exclude-azure-cli-credential: false
exclude-azure-powershell-credential: true
exclude-azure-developer-cli-credential: true
exclude-interactive-browser-credential: true
- name: Build MSI from the Azure-signed package stage
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'
.\scripts\package.ps1 -Configuration Release -SkipBuild -UsePreparedStage
- name: Sign MSI with Azure Artifact Signing
uses: Azure/artifact-signing-action@c7ab2a863ab5f9a846ddb8265964877ef296ee82 # v2.0.0
with:
endpoint: ${{ vars.AZURE_ARTIFACT_SIGNING_ENDPOINT }}
signing-account-name: ${{ vars.AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME }}
certificate-profile-name: ${{ vars.AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME }}
files: ${{ github.workspace }}\packages\Release\wincred-libsecret-wsl-plugin.msi
file-digest: SHA256
timestamp-digest: SHA256
exclude-environment-credential: true
exclude-workload-identity-credential: true
exclude-managed-identity-credential: true
exclude-shared-token-cache-credential: true
exclude-visual-studio-credential: true
exclude-visual-studio-code-credential: true
exclude-azure-cli-credential: false
exclude-azure-powershell-credential: true
exclude-azure-developer-cli-credential: true
exclude-interactive-browser-credential: true
- name: Validate Azure-signed artifacts
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'
.\scripts\Test-Packaging.ps1 `
-StageDirectory .\packages\stage\Release `
-MsiPath .\packages\Release\wincred-libsecret-wsl-plugin.msi `
-SigningPath @(
'.\packages\stage\Release\windows\wincred-libsecret-wsl-plugin.dll',
'.\packages\stage\Release\windows\wincred-libsecret.exe',
'.\packages\stage\Release\windows\wincred-libsecret-broker.exe',
'.\packages\Release\wincred-libsecret-wsl-plugin.msi'
) `
-RequireValidSignatures
- name: Write release signing metadata
shell: pwsh
run: .\scripts\release\Write-ReleaseSigningMetadata.ps1
- name: Generate SBOM and release checksums
shell: pwsh
run: .\scripts\New-ReleaseMetadata.ps1 -OutputDirectory .\packages\Release
- name: Attest public release assets
if: github.event.repository.visibility == 'public'
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: "packages/Release/*"
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: signed-release-${{ steps.version.outputs.tag }}
path: |
packages/Release
packages/stage/Release
if-no-files-found: error
retention-days: 30
- name: Create annotated release tag
shell: pwsh
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
RELEASE_SHA: ${{ github.event.pull_request.merge_commit_sha }}
TAG: ${{ steps.version.outputs.tag }}
run: .\scripts\release\New-ReleaseTag.ps1 -Repository $env:GITHUB_REPOSITORY -Tag $env:TAG -ReleaseSha $env:RELEASE_SHA
- name: Generate conventional release notes
shell: pwsh
env:
RELEASE_NOTES_PATH: ${{ runner.temp }}\release-notes.md
run: |
$ErrorActionPreference = 'Stop'
& git cliff --config .config/cliff.toml --latest --strip all -o $env:RELEASE_NOTES_PATH
if ($LASTEXITCODE -ne 0) { throw 'Could not generate conventional release notes.' }
if (!(Test-Path -LiteralPath $env:RELEASE_NOTES_PATH -PathType Leaf)) {
throw 'git-cliff did not create release notes.'
}
- name: Publish release assets
shell: pwsh
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ steps.version.outputs.tag }}
PRERELEASE: ${{ contains(github.event.pull_request.labels.*.name, 'prerelease') }}
RELEASE_NOTES_PATH: ${{ runner.temp }}\release-notes.md
run: .\scripts\release\Publish-ReleaseAssets.ps1