Repository navigation
ci: automated signed release on version tags - #541
Merged
Merged
Conversation
- Extract the platform build/package matrix into a reusable workflow (build-artifacts.yml) shared by continuous and release pipelines. - continuos-release.yml now calls the reusable build instead of inlining it. - Add release.yml: on a semver tag push (e.g. 4.0.0) it builds at the tag, GPG-signs every artifact with a dedicated CI signing subkey, and publishes a versioned release (auto-generated notes, source tarball + binaries + .asc, no .sha256). Requires GPG_PRIVATE_KEY and GPG_PASSPHRASE secrets.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds tag-triggered release automation so cutting a release is just
git tag -s X.Y.Z && git push --tags.What this does
build-artifacts.yml(new, reusable): the existing platform build/package matrix, extracted so it's shared.continuos-release.yml: now calls the reusable build instead of inlining ~250 lines (behaviour unchanged — still updates thecontinuouspre-release on master).release.yml(new): on a semver tag push ([0-9]+.[0-9]+.[0-9]+, novprefix) it builds at the tag, GPG-signs every artifact, and publishes a versioned release with auto-generated notes + source tarball + binaries +.asc(no.sha256).Requires two secrets (dedicated signing subkey — NOT the master key)
GPG_PRIVATE_KEY— armored export of a dedicated signing subkeyGPG_PASSPHRASE— its passphraseTesting before trusting it
Continuous Build & Releasefrom this branch to confirm the reusable-workflow refactor still builds/publishescontinuous.workflow_dispatchRelease with tag4.0.0to dry-run signing/publishing against the existing release (allowUpdates: true).Draft until validated.