diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 4de17ab..cf6b166 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,15 +1,32 @@ name: publish +# Publish an existing release tag to the Bend hub as shake@X.Y.Z.0 by hand, +# e.g. to retry a release whose automatic publish failed. Releases are +# published automatically by release-please.yml. dry-run runs every check +# (proof gate, LICENSE, the hub's name check) and stops before the upload. + on: workflow_dispatch: inputs: tag: - description: "Existing tag to publish, e.g. v0.4.0" + description: "The existing tag to publish, e.g. v1.2.0" required: true type: string + dry-run: + description: "Check everything, upload nothing" + required: false + type: boolean + default: false + +permissions: + contents: read jobs: publish: - uses: Emerging-Patterns/actions/.github/workflows/publish.yml@9523e8b294ae014fade5861c32d5ab911866acb2 + uses: Emerging-Patterns/actions/.github/workflows/publish.yml@0fb03f81b72096c8db54be388d09ef5ab75fed3f with: tag: ${{ inputs.tag }} + hub-name: shake + dry-run: ${{ inputs.dry-run }} + secrets: + bend-key: ${{ secrets.BEND_HUB_KEY }} diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index d087722..2f09159 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -1,5 +1,12 @@ name: release-please +# release-please opens the release PR from conventional commits; merging it +# tags vX.Y.Z and creates the GitHub release. The publish job then sends that +# tag to the Bend hub as shake@X.Y.Z.0: the shared publish workflow runs the +# proof gate and refuses a package with no LICENSE beside its entry before it +# uploads, since an upload is public and permanent. BEND_HUB_KEY is the Bender +# login of the account that owns the hub name. + on: push: branches: [main] @@ -15,7 +22,19 @@ jobs: contents: write pull-requests: write issues: write - uses: Emerging-Patterns/actions/.github/workflows/release-please.yml@a7b5322fe88c4974e06405cdf33b1aa00aa8d92a + uses: Emerging-Patterns/actions/.github/workflows/release-please.yml@0fb03f81b72096c8db54be388d09ef5ab75fed3f with: config-file: .github/release-please-config.json manifest-file: .github/release-please-manifest.json + + publish: + needs: release-please + if: needs.release-please.outputs.release_created == 'true' + permissions: + contents: read + uses: Emerging-Patterns/actions/.github/workflows/publish.yml@0fb03f81b72096c8db54be388d09ef5ab75fed3f + with: + tag: ${{ needs.release-please.outputs.tag_name }} + hub-name: shake + secrets: + bend-key: ${{ secrets.BEND_HUB_KEY }}