Repository navigation
Expand file tree
/
Copy pathaction.yml
More file actions
148 lines (141 loc) · 6.02 KB
/
Copy pathaction.yml
File metadata and controls
148 lines (141 loc) · 6.02 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
name: releaser
description: Run the bombfork/releaser CLI in a workflow. Downloads the binary matching this action's version and invokes it.
author: bombfork
inputs:
command:
description: Releaser subcommand to invoke (e.g. "release", "release --dry-run").
required: true
version:
description: |
Release tag of bombfork/releaser to consume (e.g. "v0.9.0"). Required when
the workflow pins this action to a commit SHA — at runtime the action
cannot recover the tag from a SHA, and the release-asset download URL is
tag-based. When unset, the action falls back to deriving the tag from
its checkout path's basename, which works only when `uses:` references a
tag directly.
required: false
default: ''
app-id:
description: |
GitHub App ID. Pair with `app-installation-id` and `app-private-key`
to authenticate as a GitHub App installation. The App must be
installed on the target repository with contents:write and
pull-requests:write permissions. App auth is required: commits
created with the installation token are attributed to the App bot
and signed by GitHub.
required: true
app-installation-id:
description: GitHub App installation ID for the target repository.
required: true
app-private-key:
description: GitHub App private key in PEM format. Pass via a secret.
required: true
working-directory:
description: Directory in which to run the releaser command.
required: false
default: ${{ github.workspace }}
runs:
using: composite
steps:
- name: Validate authentication inputs
shell: bash
env:
APP_ID: ${{ inputs.app-id }}
APP_INST_ID: ${{ inputs.app-installation-id }}
APP_PEM: ${{ inputs.app-private-key }}
run: |
set -euo pipefail
# `required: true` on the inputs does not fail the run when a
# caller passes an empty expression (e.g. an unset var/secret),
# so enforce non-empty values here.
if [[ -z "${APP_ID}" || -z "${APP_INST_ID}" || -z "${APP_PEM}" ]]; then
echo "::error::releaser: all of app-id, app-installation-id, and app-private-key must be set (GitHub App auth is required; token auth was removed in v0.14.0)" >&2
exit 1
fi
- name: Resolve action version
id: version
shell: bash
env:
VERSION_INPUT: ${{ inputs.version }}
run: |
# Prefer the explicit `version` input — required when the caller
# pins this action by SHA, since the SHA can't be reverse-mapped
# to a release tag at runtime. Fall back to the basename of
# github.action_path (the ref the action was checked out at),
# which works for tag-pinned callers. github.action_ref is
# unreliable inside composite actions and shows as empty in some
# runner contexts, so it's not used here.
if [[ -n "${VERSION_INPUT}" ]]; then
ref="${VERSION_INPUT}"
else
ref="$(basename "${{ github.action_path }}")"
fi
if [[ -z "${ref}" ]]; then
echo "could not resolve action version: pass with: version: or use tag-pinned uses:" >&2
exit 1
fi
echo "version=${ref}" >> "${GITHUB_OUTPUT}"
- name: Resolve platform
id: platform
shell: bash
run: |
case "${RUNNER_OS}" in
Linux) os=linux ;;
macOS) os=darwin ;;
Windows) os=windows ;;
*) echo "unsupported runner OS: ${RUNNER_OS}" >&2; exit 1 ;;
esac
case "${RUNNER_ARCH}" in
X64) arch=amd64 ;;
ARM64) arch=arm64 ;;
*) echo "unsupported runner arch: ${RUNNER_ARCH}" >&2; exit 1 ;;
esac
echo "os=${os}" >> "${GITHUB_OUTPUT}"
echo "arch=${arch}" >> "${GITHUB_OUTPUT}"
- name: Restore releaser binary from cache
id: cache
uses: actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5
with:
path: ${{ runner.tool_cache }}/releaser/${{ steps.version.outputs.version }}
key: releaser-${{ steps.version.outputs.version }}-${{ steps.platform.outputs.os }}-${{ steps.platform.outputs.arch }}
- name: Download releaser binary
if: steps.cache.outputs.cache-hit != 'true'
shell: bash
env:
VERSION: ${{ steps.version.outputs.version }}
OS: ${{ steps.platform.outputs.os }}
ARCH: ${{ steps.platform.outputs.arch }}
TOOL_CACHE: ${{ runner.tool_cache }}
run: |
set -euo pipefail
dest="${TOOL_CACHE}/releaser/${VERSION}"
mkdir -p "${dest}"
url="https://github.com/bombfork/releaser/releases/download/${VERSION}/releaser_${OS}_${ARCH}.tar.gz"
echo "Downloading ${url}"
curl --fail --location --silent --show-error --output /tmp/releaser.tgz "${url}"
tar -xzf /tmp/releaser.tgz -C "${dest}"
rm -f /tmp/releaser.tgz
chmod +x "${dest}/releaser"
- name: Run releaser
shell: bash
working-directory: ${{ inputs.working-directory }}
env:
GH_TKN_APP_ID: ${{ inputs.app-id }}
GH_TKN_APP_INST_ID: ${{ inputs.app-installation-id }}
GH_TKN_APP_PRIVATE_KEY: ${{ inputs.app-private-key }}
RELEASER_BIN: ${{ runner.tool_cache }}/releaser/${{ steps.version.outputs.version }}/releaser
RELEASER_ARGS: ${{ inputs.command }}
run: |
set -euo pipefail
# Drop empty auth env vars before invoking the binary. GitHub Actions
# materializes every `env:` mapping even when the source input is unset,
# so the GH_TKN_APP_* vars are always present here. gh-token-go uses
# os.LookupEnv (which sees "" as set) and prefers the App branch when
# any of GH_TKN_APP_* are set — an empty value would then be parsed as
# an int and fail. Unsetting empties surfaces the real problem instead.
for var in GH_TKN_APP_ID GH_TKN_APP_INST_ID GH_TKN_APP_PRIVATE_KEY; do
if [[ -z "${!var:-}" ]]; then
unset "${var}"
fi
done
eval "${RELEASER_BIN} ${RELEASER_ARGS}"