Repository navigation
123 lines (110 loc) · 4.81 KB
/
Copy pathrelease.yml
File metadata and controls
123 lines (110 loc) · 4.81 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
name: Release
# A version tag — v1.2.0 — publishes the image and the GitHub Release.
#
# The image goes to two registries under the same tags: GitHub's own
# (ghcr.io/changenode/notemesh, no account needed beyond this repo) and Docker
# Hub (wiverson/notemesh, which the Docker MCP registry requires). The Release
# carries that version's section of CHANGELOG.md as its notes, so the notes
# are written once, in the file the changelog's own preamble says people
# decide from.
#
# Two guards before anything is pushed: the tag must match package.json —
# the catalog test already holds package.json, the version the server reports
# at initialize, and the changelog heading together, so the tag is the one
# thing left to check — and the changelog must have a dated section for it.
#
# The Railway template keeps building from source; this is an additional
# channel for pinning a version, for other Docker hosts, and for the
# registry listings. The image is what the CI image job already builds and
# checks on every push, for two architectures.
on:
push:
tags: ["v*"]
permissions:
contents: write # the Release
packages: write # ghcr.io
id-token: write # provenance attestation: signing
attestations: write # provenance attestation: storing it (the 1.2.0 run lacked this and stopped here)
jobs:
release:
runs-on: ubuntu-latest
timeout-minutes: 30
env:
VERSION: ${{ github.ref_name }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: The tag names the version package.json carries
run: |
expected="v$(node -p "require('./package.json').version")"
echo "tag: $VERSION package.json: $expected"
test "$VERSION" = "$expected"
- name: The changelog has a dated section for it
run: node scripts/release-notes.mjs "$VERSION" > release-notes.md && wc -l release-notes.md
- uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4.3.0
- uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
- name: Log in to ghcr.io
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Log in to Docker Hub
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
# 1.2.0, 1.2 and latest, on both registries. `latest` follows the newest
# tag pushed, which is the release just made; a patch to an older line
# would need the `latest` flavor turned off for that run.
- name: Image tags
id: meta
uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0
with:
images: |
ghcr.io/changenode/notemesh
docker.io/wiverson/notemesh
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
labels: |
org.opencontainers.image.title=NoteMesh
org.opencontainers.image.description=Your Obsidian vault, served to Claude, ChatGPT and Codex over MCP
org.opencontainers.image.source=https://github.com/ChangeNode/notemesh
org.opencontainers.image.licenses=AGPL-3.0-or-later
- name: Build and push
id: build
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
platforms: linux/amd64,linux/arm64
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
provenance: true
sbom: true
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Attest the provenance of the ghcr.io image
uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: ghcr.io/changenode/notemesh
subject-digest: ${{ steps.build.outputs.digest }}
push-to-registry: true
- name: Create the GitHub Release
env:
GH_TOKEN: ${{ github.token }}
run: |
{
cat release-notes.md
echo
echo "## Image"
echo
echo '```'
echo "docker pull ghcr.io/changenode/notemesh:${VERSION#v}"
echo "docker pull wiverson/notemesh:${VERSION#v}"
echo '```'
echo
echo "Digest: \`${{ steps.build.outputs.digest }}\`"
} > release-body.md
gh release create "$VERSION" --title "NoteMesh ${VERSION#v}" --notes-file release-body.md --verify-tag