Skip to content

Publish to package managers #13

Publish to package managers

Publish to package managers #13

Workflow file for this run

name: Publish to package managers
on:
workflow_dispatch:
inputs:
release_tag:
description: "GitHub release tag to publish. Leave empty to use the latest release."
required: false
type: string
permissions:
contents: read
jobs:
publish:
name: Publish gitmun-bin
runs-on: ubuntu-22.04
steps:
- name: Resolve release tag
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
INPUT_RELEASE_TAG: ${{ inputs.release_tag }}
run: |
set -euo pipefail
if [[ -n "${INPUT_RELEASE_TAG}" ]]; then
RELEASE_TAG="${INPUT_RELEASE_TAG}"
else
RELEASE_TAG="$(gh release view --json tagName --jq '.tagName')"
fi
if [[ -z "${RELEASE_TAG}" ]]; then
echo "Could not resolve a release tag." >&2
exit 1
fi
echo "RELEASE_TAG=${RELEASE_TAG}" >> "${GITHUB_ENV}"
echo "Publishing AUR package from ${RELEASE_TAG}"
- name: Download AUR bundle
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
run: |
set -euo pipefail
mkdir -p release-aur
gh release download "${RELEASE_TAG}" \
--pattern 'gitmun-bin-aur-*.zip' \
--dir release-aur
mapfile -t bundles < <(find release-aur -maxdepth 1 -type f -name 'gitmun-bin-aur-*.zip' | sort)
if [[ "${#bundles[@]}" -ne 1 ]]; then
echo "Expected exactly one gitmun-bin AUR bundle, found ${#bundles[@]}." >&2
printf '%s\n' "${bundles[@]}" >&2
exit 1
fi
echo "AUR_BUNDLE=${bundles[0]}" >> "${GITHUB_ENV}"
- name: Extract and validate AUR files
run: |
set -euo pipefail
mkdir -p aur-files
unzip -q "${AUR_BUNDLE}" -d aur-files
grep -qx "pkgname=gitmun-bin" aur-files/PKGBUILD
grep -qx "pkgname = gitmun-bin" aur-files/.SRCINFO
expected_prefix="download.opensuse.org/repositories/home:/cst8t:/gitmun/"
if ! grep -q "${expected_prefix}" aur-files/PKGBUILD; then
echo "PKGBUILD source_x86_64 does not point to OBS download URL." >&2
exit 1
fi
if ! grep -q "${expected_prefix}" aur-files/.SRCINFO; then
echo ".SRCINFO source_x86_64 does not point to OBS download URL." >&2
exit 1
fi
- name: Configure SSH
env:
AUR_SSH_PRIVATE_KEY: ${{ secrets.AUR_SSH_PRIVATE_KEY }}
run: |
set -euo pipefail
if [[ -z "${AUR_SSH_PRIVATE_KEY}" ]]; then
echo "Missing AUR_SSH_PRIVATE_KEY secret." >&2
exit 1
fi
mkdir -p "${HOME}/.ssh"
chmod 700 "${HOME}/.ssh"
printf '%s\n' "${AUR_SSH_PRIVATE_KEY}" > "${HOME}/.ssh/aur"
chmod 600 "${HOME}/.ssh/aur"
ssh-keyscan aur.archlinux.org >> "${HOME}/.ssh/known_hosts"
cat > "${HOME}/.ssh/config" <<'EOF'
Host aur.archlinux.org
User aur
IdentityFile ~/.ssh/aur
IdentitiesOnly yes
StrictHostKeyChecking yes
EOF
chmod 600 "${HOME}/.ssh/config"
- name: Clone AUR repository
run: git clone ssh://aur@aur.archlinux.org/gitmun-bin.git aur-repo
- name: Update AUR repository
env:
AUR_COMMIT_NAME: ${{ vars.AUR_COMMIT_NAME }}
AUR_COMMIT_EMAIL: ${{ vars.AUR_COMMIT_EMAIL }}
run: |
set -euo pipefail
cp aur-files/PKGBUILD \
aur-files/.SRCINFO \
aur-files/gitmun.install \
aur-files/LICENSE \
aur-files/LICENSE.gitmun \
aur-files/REUSE.toml \
aur-repo/
sed -i 's/\r$//' aur-repo/PKGBUILD aur-repo/.SRCINFO aur-repo/gitmun.install aur-repo/LICENSE aur-repo/LICENSE.gitmun aur-repo/REUSE.toml
cd aur-repo
if [[ -z "${AUR_COMMIT_NAME}" || -z "${AUR_COMMIT_EMAIL}" ]]; then
echo "AUR_COMMIT_NAME and AUR_COMMIT_EMAIL variables must be set." >&2
exit 1
fi
git config user.name "${AUR_COMMIT_NAME}"
git config user.email "${AUR_COMMIT_EMAIL}"
git add PKGBUILD .SRCINFO gitmun.install LICENSE LICENSE.gitmun REUSE.toml
if git diff --cached --quiet --exit-code; then
echo "AUR repository is already up to date."
exit 0
fi
pkgver="$(sed -n 's/^pkgver=//p' PKGBUILD)"
git commit -m "Update to ${pkgver}"
git push origin HEAD:master
winget:
name: Update WinGet manifest
runs-on: ubuntu-22.04
steps:
- name: Resolve release tag
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
INPUT_RELEASE_TAG: ${{ inputs.release_tag }}
run: |
set -euo pipefail
if [[ -n "${INPUT_RELEASE_TAG}" ]]; then
RELEASE_TAG="${INPUT_RELEASE_TAG}"
else
RELEASE_TAG="$(gh release view --json tagName --jq '.tagName')"
fi
if [[ -z "${RELEASE_TAG}" ]]; then
echo "Could not resolve a release tag." >&2
exit 1
fi
PACKAGE_VERSION="${RELEASE_TAG#v}"
RELEASE_URL="${{ github.server_url }}/${{ github.repository }}/releases/download/${RELEASE_TAG}"
echo "RELEASE_TAG=${RELEASE_TAG}" >> "${GITHUB_ENV}"
echo "PACKAGE_VERSION=${PACKAGE_VERSION}" >> "${GITHUB_ENV}"
echo "NSIS_URL=${RELEASE_URL}/Gitmun_${PACKAGE_VERSION}_x64-setup.exe" >> "${GITHUB_ENV}"
echo "MSI_URL=${RELEASE_URL}/Gitmun_${PACKAGE_VERSION}_x64.msi" >> "${GITHUB_ENV}"
echo "Updating WinGet manifest for ${PACKAGE_VERSION}"
- name: Check WinGet token
env:
WINGET_TOKEN: ${{ secrets.WINGET_TOKEN }}
run: |
set -euo pipefail
if [[ -z "${WINGET_TOKEN}" ]]; then
echo "Missing WINGET_TOKEN secret." >&2
exit 1
fi
- name: Sync WinGet fork
uses: michidk/run-komac@v2
env:
GITHUB_TOKEN: ${{ secrets.WINGET_TOKEN }}
with:
custom-fork-owner: ${{ github.repository_owner }}
args: sync
- name: Generate WinGet manifests
uses: michidk/run-komac@v2
env:
GITHUB_TOKEN: ${{ secrets.WINGET_TOKEN }}
with:
custom-fork-owner: ${{ github.repository_owner }}
custom-tool: Gitmun package manager workflow
custom-tool-url: ${{ github.server_url }}/${{ github.repository }}/actions/workflows/publish-aur.yml
args: >-
update cst8t.gitmun
--version ${PACKAGE_VERSION}
--urls ${NSIS_URL} ${MSI_URL}
--release-notes-url ${{ github.server_url }}/${{ github.repository }}/releases/tag/${RELEASE_TAG}
--dry-run
--output ./winget-manifests
- name: Remove InstallerLocale from manifests
run: |
set -euo pipefail
find ./winget-manifests -name '*.yaml' -exec sed -i '/^[[:space:]]*InstallerLocale:/d' {} +
- name: Submit WinGet update
uses: michidk/run-komac@v2
env:
GITHUB_TOKEN: ${{ secrets.WINGET_TOKEN }}
with:
custom-fork-owner: ${{ github.repository_owner }}
args: >-
submit ./winget-manifests
--yes