Repository navigation
Publish to package managers #25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Publish to package managers | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| release_tag: | |
| description: "GitHub release tag to publish. Leave empty to use the latest release." | |
| required: false | |
| type: string | |
| permissions: | |
| contents: read | |
| jobs: | |
| publish: | |
| name: Publish gitmun-bin | |
| runs-on: ubuntu-22.04 | |
| steps: | |
| - name: Resolve release tag | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| GH_REPO: ${{ github.repository }} | |
| INPUT_RELEASE_TAG: ${{ inputs.release_tag }} | |
| run: | | |
| set -euo pipefail | |
| if [[ -n "${INPUT_RELEASE_TAG}" ]]; then | |
| RELEASE_TAG="${INPUT_RELEASE_TAG}" | |
| else | |
| RELEASE_TAG="$(gh release view --json tagName --jq '.tagName')" | |
| fi | |
| if [[ -z "${RELEASE_TAG}" ]]; then | |
| echo "Could not resolve a release tag." >&2 | |
| exit 1 | |
| fi | |
| echo "RELEASE_TAG=${RELEASE_TAG}" >> "${GITHUB_ENV}" | |
| echo "Publishing AUR package from ${RELEASE_TAG}" | |
| - name: Download AUR bundle | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| GH_REPO: ${{ github.repository }} | |
| run: | | |
| set -euo pipefail | |
| mkdir -p release-aur | |
| gh release download "${RELEASE_TAG}" \ | |
| --pattern 'gitmun-bin-aur-*.zip' \ | |
| --dir release-aur | |
| mapfile -t bundles < <(find release-aur -maxdepth 1 -type f -name 'gitmun-bin-aur-*.zip' | sort) | |
| if [[ "${#bundles[@]}" -ne 1 ]]; then | |
| echo "Expected exactly one gitmun-bin AUR bundle, found ${#bundles[@]}." >&2 | |
| printf '%s\n' "${bundles[@]}" >&2 | |
| exit 1 | |
| fi | |
| echo "AUR_BUNDLE=${bundles[0]}" >> "${GITHUB_ENV}" | |
| - name: Extract and validate AUR files | |
| run: | | |
| set -euo pipefail | |
| mkdir -p aur-files | |
| unzip -q "${AUR_BUNDLE}" -d aur-files | |
| grep -qx "pkgname=gitmun-bin" aur-files/PKGBUILD | |
| grep -qx "pkgname = gitmun-bin" aur-files/.SRCINFO | |
| expected_prefix="download.opensuse.org/repositories/home:/cst8t:/gitmun/" | |
| if ! grep -q "${expected_prefix}" aur-files/PKGBUILD; then | |
| echo "PKGBUILD source_x86_64 does not point to OBS download URL." >&2 | |
| exit 1 | |
| fi | |
| if ! grep -q "${expected_prefix}" aur-files/.SRCINFO; then | |
| echo ".SRCINFO source_x86_64 does not point to OBS download URL." >&2 | |
| exit 1 | |
| fi | |
| - name: Configure SSH | |
| env: | |
| AUR_SSH_PRIVATE_KEY: ${{ secrets.AUR_SSH_PRIVATE_KEY }} | |
| run: | | |
| set -euo pipefail | |
| if [[ -z "${AUR_SSH_PRIVATE_KEY}" ]]; then | |
| echo "Missing AUR_SSH_PRIVATE_KEY secret." >&2 | |
| exit 1 | |
| fi | |
| mkdir -p "${HOME}/.ssh" | |
| chmod 700 "${HOME}/.ssh" | |
| printf '%s\n' "${AUR_SSH_PRIVATE_KEY}" > "${HOME}/.ssh/aur" | |
| chmod 600 "${HOME}/.ssh/aur" | |
| ssh-keyscan aur.archlinux.org >> "${HOME}/.ssh/known_hosts" | |
| cat > "${HOME}/.ssh/config" <<'EOF' | |
| Host aur.archlinux.org | |
| User aur | |
| IdentityFile ~/.ssh/aur | |
| IdentitiesOnly yes | |
| StrictHostKeyChecking yes | |
| EOF | |
| chmod 600 "${HOME}/.ssh/config" | |
| - name: Clone AUR repository | |
| run: git clone ssh://aur@aur.archlinux.org/gitmun-bin.git aur-repo | |
| - name: Update AUR repository | |
| env: | |
| AUR_COMMIT_NAME: ${{ vars.AUR_COMMIT_NAME }} | |
| AUR_COMMIT_EMAIL: ${{ vars.AUR_COMMIT_EMAIL }} | |
| run: | | |
| set -euo pipefail | |
| cp aur-files/PKGBUILD \ | |
| aur-files/.SRCINFO \ | |
| aur-files/gitmun.install \ | |
| aur-files/LICENSE \ | |
| aur-files/LICENSE.gitmun \ | |
| aur-files/REUSE.toml \ | |
| aur-repo/ | |
| sed -i 's/\r$//' aur-repo/PKGBUILD aur-repo/.SRCINFO aur-repo/gitmun.install aur-repo/LICENSE aur-repo/LICENSE.gitmun aur-repo/REUSE.toml | |
| cd aur-repo | |
| if [[ -z "${AUR_COMMIT_NAME}" || -z "${AUR_COMMIT_EMAIL}" ]]; then | |
| echo "AUR_COMMIT_NAME and AUR_COMMIT_EMAIL variables must be set." >&2 | |
| exit 1 | |
| fi | |
| git config user.name "${AUR_COMMIT_NAME}" | |
| git config user.email "${AUR_COMMIT_EMAIL}" | |
| git add PKGBUILD .SRCINFO gitmun.install LICENSE LICENSE.gitmun REUSE.toml | |
| if git diff --cached --quiet --exit-code; then | |
| echo "AUR repository is already up to date." | |
| exit 0 | |
| fi | |
| pkgver="$(sed -n 's/^pkgver=//p' PKGBUILD)" | |
| git commit -m "Update to ${pkgver}" | |
| git push origin HEAD:master | |
| winget: | |
| name: Update WinGet manifest | |
| runs-on: ubuntu-22.04 | |
| steps: | |
| - name: Resolve release tag | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| GH_REPO: ${{ github.repository }} | |
| INPUT_RELEASE_TAG: ${{ inputs.release_tag }} | |
| run: | | |
| set -euo pipefail | |
| if [[ -n "${INPUT_RELEASE_TAG}" ]]; then | |
| RELEASE_TAG="${INPUT_RELEASE_TAG}" | |
| else | |
| RELEASE_TAG="$(gh release view --json tagName --jq '.tagName')" | |
| fi | |
| if [[ -z "${RELEASE_TAG}" ]]; then | |
| echo "Could not resolve a release tag." >&2 | |
| exit 1 | |
| fi | |
| PACKAGE_VERSION="${RELEASE_TAG#v}" | |
| RELEASE_URL="${{ github.server_url }}/${{ github.repository }}/releases/download/${RELEASE_TAG}" | |
| echo "RELEASE_TAG=${RELEASE_TAG}" >> "${GITHUB_ENV}" | |
| echo "PACKAGE_VERSION=${PACKAGE_VERSION}" >> "${GITHUB_ENV}" | |
| echo "NSIS_URL=${RELEASE_URL}/Gitmun_${PACKAGE_VERSION}_x64-setup.exe" >> "${GITHUB_ENV}" | |
| echo "MSI_URL=${RELEASE_URL}/Gitmun_${PACKAGE_VERSION}_x64.msi" >> "${GITHUB_ENV}" | |
| echo "Updating WinGet manifest for ${PACKAGE_VERSION}" | |
| - name: Check WinGet token | |
| env: | |
| WINGET_TOKEN: ${{ secrets.WINGET_TOKEN }} | |
| run: | | |
| set -euo pipefail | |
| if [[ -z "${WINGET_TOKEN}" ]]; then | |
| echo "Missing WINGET_TOKEN secret." >&2 | |
| exit 1 | |
| fi | |
| - name: Sync WinGet fork | |
| uses: michidk/run-komac@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.WINGET_TOKEN }} | |
| with: | |
| custom-fork-owner: ${{ github.repository_owner }} | |
| args: sync | |
| - name: Generate WinGet manifests | |
| uses: michidk/run-komac@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.WINGET_TOKEN }} | |
| with: | |
| custom-fork-owner: ${{ github.repository_owner }} | |
| custom-tool: Gitmun package manager workflow | |
| custom-tool-url: ${{ github.server_url }}/${{ github.repository }}/actions/workflows/publish-aur.yml | |
| args: >- | |
| update cst8t.gitmun | |
| --version ${PACKAGE_VERSION} | |
| --urls ${NSIS_URL} ${MSI_URL} | |
| --release-notes-url ${{ github.server_url }}/${{ github.repository }}/releases/tag/${RELEASE_TAG} | |
| --dry-run | |
| --output ./winget-manifests | |
| - name: Remove InstallerLocale from manifests | |
| run: | | |
| set -euo pipefail | |
| find ./winget-manifests -name '*.yaml' -exec sed -i '/^[[:space:]]*InstallerLocale:/d' {} + | |
| - name: Submit WinGet update | |
| uses: michidk/run-komac@v2 | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.WINGET_TOKEN }} | |
| with: | |
| custom-fork-owner: ${{ github.repository_owner }} | |
| args: >- | |
| submit ./winget-manifests | |
| --yes |