two/.forgejo/workflows/release.yml
GnomeZworc 78492d11e7
main: ci: update release jobs
Signed-off-by: GnomeZworc <nicolas.boufidjeline@g3e.fr>
2026-08-17 21:15:30 +02:00

94 lines
3.4 KiB
YAML

on:
workflow_call:
inputs:
tag:
required: true
type: string
prerelease:
required: true
type: string
jobs:
release:
runs-on: docker
env:
TOKEN: ${{ secrets.RELEASE }}
TAG: ${{ inputs.tag }}
PRERELEASE: ${{ inputs.prerelease }}
steps:
- uses: actions/checkout@v3
- name: Download all build artifacts
uses: actions/download-artifact@v3
with:
path: dist/
- name: Publier tous les binaires
run: ls -lR dist/
- name: Install jq
run: |
apt-get update
apt-get install -y jq
- name: Préparer les notes de version
run: |
NOTES="release_notes/${TAG}.md"
if [[ -f "${NOTES}" ]]
then
echo "notes trouvées : ${NOTES}"
cp "${NOTES}" body.md
elif [[ "${PRERELEASE}" == "true" ]]
then
echo "aucune note pour ${TAG}, texte générique (préversion)"
echo "Prerelease automatique générée par la CI" > body.md
else
echo "release finale ${TAG} sans notes de version" >&2
echo "créer ${NOTES} avant de pousser le tag" >&2
exit 1
fi
echo "--- body ---"; cat body.md
- name: Create release
run: |
jq -n \
--arg tag "${TAG}" \
--rawfile body body.md \
--argjson prerelease "${PRERELEASE}" \
'{
tag_name: $tag,
name: $tag,
body: $body,
draft: false,
prerelease: $prerelease,
hide_archive_links: true
}' > payload.json
cat payload.json | jq -c '.body |= (.[0:60] + "…")'
# Code HTTP vérifié explicitement plutôt qu'avec --fail-with-body, qui
# exige curl >= 7.76 : sans ça un échec (409 tag déjà publié, 401 token
# invalide) passerait inaperçu et la release resterait sans assets.
HTTP=$(curl -sS -o resp.json -w '%{http_code}' -X POST \
-H "Authorization: token ${TOKEN}" \
-H "Content-Type: application/json" \
"https://git.g3e.fr/api/v1/repos/${{ github.repository }}/releases" \
-d @payload.json)
echo "HTTP ${HTTP}"
cat resp.json; echo
[[ "${HTTP}" == 2* ]] || { echo "création de la release échouée" >&2; exit 1; }
- name: Upload asset
run: |
RELEASE_ID=$(curl -s \
-H "Authorization: token ${TOKEN}" \
https://git.g3e.fr/api/v1/repos/${{ github.repository }}/releases/tags/${TAG} \
| jq -r .id)
echo ${RELEASE_ID}
# Sans ce garde-fou, un id absent (null) enverrait chaque asset sur
# .../releases/null/assets : une cascade de 404 silencieux et une
# release publiée sans aucun binaire.
[[ "${RELEASE_ID}" =~ ^[0-9]+$ ]] || { echo "id de release introuvable pour ${TAG}" >&2; exit 1; }
ls dist | while read tmp
do
FILE=$(ls "./dist/${tmp}")
echo ${FILE}
curl -X POST \
-H "Authorization: token ${TOKEN}" \
-H "Content-Type: application/octet-stream" \
--data-binary @dist/${tmp}/${FILE} \
"https://git.g3e.fr/api/v1/repos/${{ github.repository }}/releases/${RELEASE_ID}/assets?name=${FILE}"
done