Repository navigation
chore(deps): Bump github/codeql-action/analyze from 4.37.6 to 4.38.1 #38
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release publish | |
| on: | |
| pull_request: | |
| types: [closed] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: release-publish-${{ github.event.pull_request.number }} | |
| cancel-in-progress: false | |
| env: | |
| CARGO_INCREMENTAL: "0" | |
| RUST_BACKTRACE: "1" | |
| jobs: | |
| validate-release-pr: | |
| name: Validate release change | |
| if: >- | |
| github.event.pull_request.merged == true && | |
| github.event.pull_request.base.ref == github.event.repository.default_branch && | |
| github.event.pull_request.head.repo.full_name == github.repository && | |
| startsWith(github.event.pull_request.head.ref, 'release/v') && | |
| contains(github.event.pull_request.labels.*.name, 'release') | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.pull_request.merge_commit_sha }} | |
| fetch-depth: 0 | |
| - name: Install pinned Rust toolchain | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| rustup toolchain install 1.97.1 --profile minimal | |
| rustup default 1.97.1 | |
| - name: Install pinned git-cliff | |
| uses: taiki-e/install-action@b20dedce73af6905cdc30d6611090c9b67557c8d # v2 | |
| with: | |
| tool: git-cliff@2.9.1 | |
| - name: Verify the merged change is release-only | |
| id: release-change | |
| shell: bash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| MERGE_SHA: ${{ github.event.pull_request.merge_commit_sha }} | |
| PULL_NUMBER: ${{ github.event.pull_request.number }} | |
| RELEASE_BRANCH: ${{ github.event.pull_request.head.ref }} | |
| INITIAL_RELEASE: ${{ contains(github.event.pull_request.labels.*.name, 'initial-release') }} | |
| run: bash scripts/release/validate-release-change.sh | |
| - name: Verify the generated changelog matches the release commit | |
| shell: bash | |
| env: | |
| TAG: v${{ steps.release-change.outputs.version }} | |
| run: | | |
| set -euo pipefail | |
| expected="${RUNNER_TEMP}/expected-changelog.md" | |
| git cliff --config .config/cliff.toml --tag "$TAG" -o "$expected" | |
| if ! cmp --silent "$expected" CHANGELOG.md; then | |
| echo "::error::CHANGELOG.md is stale; refresh the release PR against main and regenerate it." | |
| exit 1 | |
| fi | |
| wait-ci: | |
| name: Wait for merge CI | |
| needs: validate-release-pr | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 65 | |
| permissions: | |
| actions: read | |
| contents: read | |
| outputs: | |
| run_id: ${{ steps.find.outputs.run_id }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.pull_request.merge_commit_sha }} | |
| fetch-depth: 0 | |
| - name: Wait for successful CI on the release commit | |
| id: find | |
| shell: bash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| SHA: ${{ github.event.pull_request.merge_commit_sha }} | |
| run: bash scripts/release/wait-for-merge-ci.sh | |
| hosted-e2e: | |
| name: Run release hosted WSL E2E | |
| needs: wait-ci | |
| uses: ./.github/workflows/hosted-wsl-e2e.yml | |
| with: | |
| checkout_ref: ${{ github.event.pull_request.merge_commit_sha }} | |
| permissions: | |
| actions: write | |
| contents: read | |
| sign-package-publish: | |
| name: Sign and publish | |
| needs: [validate-release-pr, wait-ci, hosted-e2e] | |
| runs-on: windows-2022 | |
| environment: release | |
| timeout-minutes: 45 | |
| permissions: | |
| actions: read | |
| artifact-metadata: write | |
| attestations: write | |
| contents: write | |
| id-token: write | |
| steps: | |
| - name: Mint release publication token | |
| id: app-token | |
| uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3 | |
| with: | |
| app-id: ${{ secrets.RELEASE_APP_ID }} | |
| private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} | |
| permission-contents: write | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.event.pull_request.merge_commit_sha }} | |
| fetch-depth: 0 | |
| - name: Install pinned git-cliff | |
| uses: taiki-e/install-action@b20dedce73af6905cdc30d6611090c9b67557c8d # v2 | |
| with: | |
| tool: git-cliff@2.9.1 | |
| - name: Validate package version and release tag | |
| id: version | |
| shell: pwsh | |
| env: | |
| RELEASE_SHA: ${{ github.event.pull_request.merge_commit_sha }} | |
| run: .\scripts\release\Get-ReleasePackageTag.ps1 | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: windows-release | |
| path: artifacts/Release | |
| run-id: ${{ needs.wait-ci.outputs.run_id }} | |
| github-token: ${{ github.token }} | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: linux-release | |
| path: artifacts/Release/linux | |
| run-id: ${{ needs.wait-ci.outputs.run_id }} | |
| github-token: ${{ github.token }} | |
| - name: Restore pinned WiX v5 tool | |
| shell: pwsh | |
| run: dotnet tool restore | |
| - name: Prepare unsigned package stage | |
| shell: pwsh | |
| run: .\scripts\package.ps1 -Configuration Release -SkipBuild -PrepareOnly | |
| - name: Validate Azure Artifact Signing configuration | |
| env: | |
| AZURE_CLIENT_ID: ${{ vars.AZURE_CLIENT_ID }} | |
| AZURE_TENANT_ID: ${{ vars.AZURE_TENANT_ID }} | |
| AZURE_SUBSCRIPTION_ID: ${{ vars.AZURE_SUBSCRIPTION_ID }} | |
| AZURE_ARTIFACT_SIGNING_ENDPOINT: ${{ vars.AZURE_ARTIFACT_SIGNING_ENDPOINT }} | |
| AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME: ${{ vars.AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME }} | |
| AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME: ${{ vars.AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME }} | |
| shell: pwsh | |
| run: .\scripts\release\Assert-AzureArtifactSigningConfiguration.ps1 | |
| - name: Azure login for Artifact Signing | |
| uses: azure/login@f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca # v3.0.1 | |
| with: | |
| client-id: ${{ vars.AZURE_CLIENT_ID }} | |
| tenant-id: ${{ vars.AZURE_TENANT_ID }} | |
| subscription-id: ${{ vars.AZURE_SUBSCRIPTION_ID }} | |
| - name: Sign staged Windows payload with Azure Artifact Signing | |
| uses: Azure/artifact-signing-action@c7ab2a863ab5f9a846ddb8265964877ef296ee82 # v2.0.0 | |
| with: | |
| endpoint: ${{ vars.AZURE_ARTIFACT_SIGNING_ENDPOINT }} | |
| signing-account-name: ${{ vars.AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME }} | |
| certificate-profile-name: ${{ vars.AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME }} | |
| files: | | |
| ${{ github.workspace }}\packages\stage\Release\windows\wincred-libsecret-wsl-plugin.dll | |
| ${{ github.workspace }}\packages\stage\Release\windows\wincred-libsecret.exe | |
| ${{ github.workspace }}\packages\stage\Release\windows\wincred-libsecret-broker.exe | |
| file-digest: SHA256 | |
| timestamp-digest: SHA256 | |
| exclude-environment-credential: true | |
| exclude-workload-identity-credential: true | |
| exclude-managed-identity-credential: true | |
| exclude-shared-token-cache-credential: true | |
| exclude-visual-studio-credential: true | |
| exclude-visual-studio-code-credential: true | |
| exclude-azure-cli-credential: false | |
| exclude-azure-powershell-credential: true | |
| exclude-azure-developer-cli-credential: true | |
| exclude-interactive-browser-credential: true | |
| - name: Build MSI from the Azure-signed package stage | |
| shell: pwsh | |
| run: | | |
| $ErrorActionPreference = 'Stop' | |
| .\scripts\package.ps1 -Configuration Release -SkipBuild -UsePreparedStage | |
| - name: Sign MSI with Azure Artifact Signing | |
| uses: Azure/artifact-signing-action@c7ab2a863ab5f9a846ddb8265964877ef296ee82 # v2.0.0 | |
| with: | |
| endpoint: ${{ vars.AZURE_ARTIFACT_SIGNING_ENDPOINT }} | |
| signing-account-name: ${{ vars.AZURE_ARTIFACT_SIGNING_ACCOUNT_NAME }} | |
| certificate-profile-name: ${{ vars.AZURE_ARTIFACT_SIGNING_CERTIFICATE_PROFILE_NAME }} | |
| files: ${{ github.workspace }}\packages\Release\wincred-libsecret-wsl-plugin.msi | |
| file-digest: SHA256 | |
| timestamp-digest: SHA256 | |
| exclude-environment-credential: true | |
| exclude-workload-identity-credential: true | |
| exclude-managed-identity-credential: true | |
| exclude-shared-token-cache-credential: true | |
| exclude-visual-studio-credential: true | |
| exclude-visual-studio-code-credential: true | |
| exclude-azure-cli-credential: false | |
| exclude-azure-powershell-credential: true | |
| exclude-azure-developer-cli-credential: true | |
| exclude-interactive-browser-credential: true | |
| - name: Validate Azure-signed artifacts | |
| shell: pwsh | |
| run: | | |
| $ErrorActionPreference = 'Stop' | |
| .\scripts\Test-Packaging.ps1 ` | |
| -StageDirectory .\packages\stage\Release ` | |
| -MsiPath .\packages\Release\wincred-libsecret-wsl-plugin.msi ` | |
| -SigningPath @( | |
| '.\packages\stage\Release\windows\wincred-libsecret-wsl-plugin.dll', | |
| '.\packages\stage\Release\windows\wincred-libsecret.exe', | |
| '.\packages\stage\Release\windows\wincred-libsecret-broker.exe', | |
| '.\packages\Release\wincred-libsecret-wsl-plugin.msi' | |
| ) ` | |
| -RequireValidSignatures | |
| - name: Write release signing metadata | |
| shell: pwsh | |
| run: .\scripts\release\Write-ReleaseSigningMetadata.ps1 | |
| - name: Generate SBOM and release checksums | |
| shell: pwsh | |
| run: .\scripts\New-ReleaseMetadata.ps1 -OutputDirectory .\packages\Release | |
| - name: Attest public release assets | |
| if: github.event.repository.visibility == 'public' | |
| uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2 | |
| with: | |
| subject-path: "packages/Release/*" | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: signed-release-${{ steps.version.outputs.tag }} | |
| path: | | |
| packages/Release | |
| packages/stage/Release | |
| if-no-files-found: error | |
| retention-days: 30 | |
| - name: Create annotated release tag | |
| shell: pwsh | |
| env: | |
| GH_TOKEN: ${{ steps.app-token.outputs.token }} | |
| RELEASE_SHA: ${{ github.event.pull_request.merge_commit_sha }} | |
| TAG: ${{ steps.version.outputs.tag }} | |
| run: .\scripts\release\New-ReleaseTag.ps1 -Repository $env:GITHUB_REPOSITORY -Tag $env:TAG -ReleaseSha $env:RELEASE_SHA | |
| - name: Generate conventional release notes | |
| shell: pwsh | |
| env: | |
| RELEASE_NOTES_PATH: ${{ runner.temp }}\release-notes.md | |
| run: | | |
| $ErrorActionPreference = 'Stop' | |
| & git cliff --config .config/cliff.toml --latest --strip all -o $env:RELEASE_NOTES_PATH | |
| if ($LASTEXITCODE -ne 0) { throw 'Could not generate conventional release notes.' } | |
| if (!(Test-Path -LiteralPath $env:RELEASE_NOTES_PATH -PathType Leaf)) { | |
| throw 'git-cliff did not create release notes.' | |
| } | |
| - name: Publish release assets | |
| shell: pwsh | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| TAG: ${{ steps.version.outputs.tag }} | |
| PRERELEASE: ${{ contains(github.event.pull_request.labels.*.name, 'prerelease') }} | |
| RELEASE_NOTES_PATH: ${{ runner.temp }}\release-notes.md | |
| run: .\scripts\release\Publish-ReleaseAssets.ps1 |