Repository navigation
chore: Upgrade Python requirements (#951) #32
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| branches: [master] | |
| jobs: | |
| run_tests: | |
| uses: ./.github/workflows/ci.yml | |
| release: | |
| runs-on: ubuntu-latest | |
| needs: run_tests | |
| if: github.ref_name == 'master' | |
| concurrency: | |
| group: ${{ github.workflow }}-release-${{ github.ref_name }} | |
| cancel-in-progress: false | |
| permissions: | |
| contents: write | |
| outputs: | |
| released: ${{ steps.release.outputs.released || 'false' }} | |
| version: ${{ steps.release.outputs.version }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| ref: ${{ github.ref_name }} | |
| fetch-depth: 0 | |
| - run: git reset --hard ${{ github.sha }} | |
| - name: Python Semantic Release | |
| id: release | |
| uses: python-semantic-release/python-semantic-release@9a026e9303981c866c3425723009becb2437c757 # v10.6.2 | |
| with: | |
| github_token: ${{ secrets.OPENEDX_SEMANTIC_RELEASE_GITHUB_TOKEN }} | |
| git_committer_name: "github-actions" | |
| git_committer_email: "github-actions@github.com" | |
| changelog: "false" | |
| # Commit, tag, push and build, but don't create the GitHub release. | |
| # We create it ourselves in the next step so that the distributions | |
| # are attached before the release is published. See that step for why. | |
| vcs_release: "false" | |
| # This repo has immutable releases enabled, which freezes a release's | |
| # assets the moment it is published, so assets cannot be attached | |
| # afterwards. `gh release create` handles this by creating the release as | |
| # a draft, uploading the assets, and only then publishing it: | |
| # https://docs.github.com/en/code-security/supply-chain-security/understanding-your-software-supply-chain/immutable-releases | |
| - name: Publish | Create GitHub Release with Assets | |
| if: steps.release.outputs.released == 'true' | |
| env: | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| # Reuse the release notes python-semantic-release generated for us. | |
| RELEASE_NOTES: ${{ steps.release.outputs.release_notes }} | |
| TAG: ${{ steps.release.outputs.tag }} | |
| run: | | |
| # Output the release notes to a file | |
| printf '%s' "$RELEASE_NOTES" > "$RUNNER_TEMP/release_notes.md" | |
| # Creates the release as a draft, uploads the assets, and then | |
| # publishes it -- all within this one command. | |
| gh release create "$TAG" \ | |
| --verify-tag \ | |
| --title "$TAG" \ | |
| --notes-file "$RUNNER_TEMP/release_notes.md" \ | |
| dist/* | |
| - name: Upload dist artifacts | |
| if: steps.release.outputs.released == 'true' | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: dist | |
| path: dist/ | |
| if-no-files-found: error | |
| publish_to_pypi: | |
| runs-on: ubuntu-latest | |
| needs: release | |
| if: github.ref_name == 'master' && needs.release.outputs.released == 'true' | |
| permissions: | |
| contents: read | |
| id-token: write | |
| steps: | |
| - name: Download dist artifacts | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: dist | |
| path: dist/ | |
| - name: Publish to PyPI | |
| uses: pypa/gh-action-pypi-publish@dc37677b2e1c63e2034f94d8a5b11f265b73ba33 # v1.14.2 |