Repository object · automation

Release

Accepted automation in the public catalog.

Source path
.github/workflows/release.yml
Media type
application/yaml
Object ID
em:automation:sha256:23fcd49d215a563699c42cfe25161d9c1de3adbf942038b9a142c9fe36a9f167
Content digest
4546b4d89e0c67bf2337091d3ac349dfac62496dd202e25914f4de9f6b86379a

Source content

name: release

on:

workflow_dispatch:

inputs:

tag:

description: Existing accepted release tag to build.

required: true

type: string

publish_github_release:

description: Create the permanent GitHub Release.

required: true

default: false

type: boolean

publish_pypi:

description: Publish the immutable package version to PyPI.

required: true

default: false

type: boolean

permissions: {}

jobs:

build:

if: github.ref == 'refs/heads/main'

permissions:

contents: read

runs-on: ubuntu-latest

timeout-minutes: 20

env:

RELEASE_TAG: ${{ inputs.tag }}

steps:

- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6

with:

ref: ${{ inputs.tag }}

fetch-depth: 0

persist-credentials: false

- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6

with:

python-version: "3.12"

- name: Verify accepted release tag and package version

run: |

if [[ ! "$RELEASE_TAG" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]; then

echo 'Release tag must have the exact form vMAJOR.MINOR.PATCH.'

exit 1

fi

RELEASE_SHA="$(git rev-parse "refs/tags/${RELEASE_TAG}^{commit}")"

test "$(git rev-parse HEAD)" = "$RELEASE_SHA"

git fetch origin main --no-tags

git merge-base --is-ancestor "$RELEASE_SHA" origin/main

PACKAGE_VERSION="$(python -c 'import pathlib, tomllib; print(tomllib.loads(pathlib.Path("pyproject.toml").read_text())["project"]["version"])')"

test "$RELEASE_TAG" = "v$PACKAGE_VERSION"

- run: python -m pip install build==1.5.0

- run: python -m pip install -e '.[dev]'

- run: make check

- run: python -m build

- name: Create source and catalog bundles

run: |

RELEASE_SHA="$(git rev-parse "refs/tags/${RELEASE_TAG}^{commit}")"

git archive --format=tar.gz --prefix="epistemedia-${RELEASE_TAG}/" --output=/tmp/epistemedia-${RELEASE_TAG}-source.tar.gz "$RELEASE_SHA"

python -m epistemedia build --output generated/public

tar -C generated/public -czf /tmp/epistemedia-${RELEASE_TAG}-public-catalog.tar.gz .

mv /tmp/epistemedia-${RELEASE_TAG}-source.tar.gz .

mv /tmp/epistemedia-${RELEASE_TAG}-public-catalog.tar.gz .

sha256sum dist/* epistemedia-${RELEASE_TAG}-*.tar.gz > SHA256SUMS

- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4

with:

name: release-artifacts

path: |

dist/*

epistemedia-*.tar.gz

SHA256SUMS

github-release:

if: inputs.publish_github_release

needs: build

runs-on: ubuntu-latest

environment: github-release

permissions:

contents: write

steps:

- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4

with:

name: release-artifacts

path: artifacts

- name: Create permanent GitHub Release

env:

GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}

RELEASE_TAG: ${{ inputs.tag }}

run: gh release create "$RELEASE_TAG" artifacts/dist/* artifacts/epistemedia-*.tar.gz artifacts/SHA256SUMS --generate-notes --verify-tag --repo "$GITHUB_REPOSITORY"

pypi:

if: inputs.publish_pypi

needs: build

runs-on: ubuntu-latest

environment:

name: pypi

url: https://pypi.org/p/epistemedia

permissions:

id-token: write

steps:

- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4

with:

name: release-artifacts

path: artifacts

- uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # release/v1

with:

packages-dir: artifacts/dist

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0