Add explicit token inputs to the checkout and softprops/action-gh-release steps so the GitHub token is wired through instead of relying on implicit defaults. The workflow-level contents: write permission already scopes the token correctly for tag/release creation.
64 lines
1.6 KiB
YAML
64 lines
1.6 KiB
YAML
name: Release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v*'
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: 'Tag to release (e.g. v0.1.0). The tag must already exist.'
|
|
required: true
|
|
type: string
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Resolve ref
|
|
id: ref
|
|
run: |
|
|
if [[ "${{ github.event_name }}" == "workflow_dispatch" ]]; then
|
|
echo "ref=${{ inputs.tag }}" >> "$GITHUB_OUTPUT"
|
|
echo "tag=${{ inputs.tag }}" >> "$GITHUB_OUTPUT"
|
|
else
|
|
echo "ref=${{ github.ref }}" >> "$GITHUB_OUTPUT"
|
|
echo "tag=${GITHUB_REF#refs/tags/}" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
ref: ${{ steps.ref.outputs.ref }}
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
- name: Setup Go
|
|
uses: actions/setup-go@v5
|
|
with:
|
|
go-version-file: go.mod
|
|
check-latest: true
|
|
|
|
- name: Build all targets
|
|
run: make build-all
|
|
|
|
- name: Generate SHA256SUMS
|
|
working-directory: dist
|
|
run: |
|
|
sha256sum bootstrap_environment-* > SHA256SUMS
|
|
cat SHA256SUMS
|
|
|
|
- name: Create release
|
|
uses: softprops/action-gh-release@v2
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
tag_name: ${{ steps.ref.outputs.tag }}
|
|
name: ${{ steps.ref.outputs.tag }}
|
|
generate_release_notes: true
|
|
fail_on_unmatched_files: true
|
|
files: |
|
|
dist/bootstrap_environment-*
|
|
dist/SHA256SUMS
|