@@ -15,6 +15,8 @@ name: Release
1515
1616permissions :
1717 contents : write
18+ id-token : write
19+ attestations : write
1820
1921# This task will run whenever you push a git tag that looks like a version
2022# like "1.0.0", "v0.1.0-prerelease.1", "my-app/0.1.0", "releases/v1.0.0", etc.
6264 # we specify bash to get pipefail; it guards against the `curl` command
6365 # failing. otherwise `sh` won't catch that `curl` returned non-0
6466 shell : bash
65- run : " curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.15 .0/cargo-dist-installer.sh | sh"
67+ run : " curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.16 .0/cargo-dist-installer.sh | sh"
6668 # sure would be cool if github gave us proper conditionals...
6769 # so here's a doubly-nested ternary-via-truthiness to try to provide the best possible
6870 # functionality based on whether this is a pull_request, and whether it's from a fork.
@@ -114,6 +116,7 @@ jobs:
114116 - uses : swatinem/rust-cache@v2
115117 with :
116118 key : ${{ join(matrix.targets, '-') }}
119+ cache-provider : ${{ matrix.cache_provider }}
117120 - name : Install cargo-dist
118121 run : ${{ matrix.install_dist }}
119122 # Get the dist-manifest
@@ -131,6 +134,10 @@ jobs:
131134 # Actually do builds and make zips and whatnot
132135 cargo dist build ${{ needs.plan.outputs.tag-flag }} --print=linkage --output-format=json ${{ matrix.dist_args }} > dist-manifest.json
133136 echo "cargo dist ran successfully"
137+ - name : Attest
138+ uses : actions/attest-build-provenance@v1
139+ with :
140+ subject-path : " target/distrib/*${{ join(matrix.targets, ', ') }}*"
134141 - id : cargo-dist
135142 name : Post-build
136143 # We force bash here just because github makes it really hard to get values up
@@ -167,7 +174,7 @@ jobs:
167174 submodules : recursive
168175 - name : Install cargo-dist
169176 shell : bash
170- run : " curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.15 .0/cargo-dist-installer.sh | sh"
177+ run : " curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.16 .0/cargo-dist-installer.sh | sh"
171178 # Get all the local artifacts for the global tasks to use (for e.g. checksums)
172179 - name : Fetch local artifacts
173180 uses : actions/download-artifact@v4
@@ -212,7 +219,7 @@ jobs:
212219 with :
213220 submodules : recursive
214221 - name : Install cargo-dist
215- run : " curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.15 .0/cargo-dist-installer.sh | sh"
222+ run : " curl --proto '=https' --tlsv1.2 -LsSf https://github.com/axodotdev/cargo-dist/releases/download/v0.16 .0/cargo-dist-installer.sh | sh"
216223 # Fetch artifacts from scratch-storage
217224 - name : Fetch artifacts
218225 uses : actions/download-artifact@v4
@@ -262,10 +269,13 @@ jobs:
262269 # Remove the granular manifests
263270 rm -f artifacts/*-dist-manifest.json
264271 - name : Create GitHub Release
265- uses : ncipollo/release-action@v1
266- with :
267- tag : ${{ needs.plan.outputs.tag }}
268- name : ${{ fromJson(needs.host.outputs.val).announcement_title }}
269- body : ${{ fromJson(needs.host.outputs.val).announcement_github_body }}
270- prerelease : ${{ fromJson(needs.host.outputs.val).announcement_is_prerelease }}
271- artifacts : " artifacts/*"
272+ env :
273+ PRERELEASE_FLAG : " ${{ fromJson(needs.host.outputs.val).announcement_is_prerelease && '--prerelease' || '' }}"
274+ ANNOUNCEMENT_TITLE : " ${{ fromJson(needs.host.outputs.val).announcement_title }}"
275+ ANNOUNCEMENT_BODY : " ${{ fromJson(needs.host.outputs.val).announcement_github_body }}"
276+ run : |
277+ # Write and read notes from a file to avoid quoting breaking things
278+ echo "$ANNOUNCEMENT_BODY" > $RUNNER_TEMP/notes.txt
279+
280+ gh release create "${{ needs.plan.outputs.tag }}" --title "$ANNOUNCEMENT_TITLE" --notes-file "$RUNNER_TEMP/notes.txt" $PRERELEASE_FLAG
281+ gh release upload "${{ needs.plan.outputs.tag }}" artifacts/*
0 commit comments