Repository navigation
43.0.0 #58
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Cut a release whenever a new tag is pushed or via workflow_dispatch. | |
| # Uses bazel-contrib release ruleset: build, attest, and publish to GitHub Releases. | |
| # A separate matrix job attaches host-native Rust CLI binaries to the draft release. | |
| name: Release | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| tag_name: | |
| description: Git tag being released | |
| required: true | |
| type: string | |
| push: | |
| tags: | |
| - "v*.*.*" | |
| permissions: | |
| id-token: write | |
| attestations: write | |
| contents: write | |
| jobs: | |
| release: | |
| uses: bazel-contrib/.github/.github/workflows/release_ruleset.yaml@v7.4.0 | |
| with: | |
| release_files: archives/*.* | |
| prerelease: false | |
| draft: true | |
| tag_name: ${{ inputs.tag_name || github.ref_name }} | |
| permissions: | |
| id-token: write # Needed to attest provenance | |
| attestations: write # Needed to attest provenance | |
| contents: write # Needed to upload release files | |
| secrets: {} | |
| publish: | |
| needs: release | |
| uses: ./.github/workflows/publish.yaml | |
| with: | |
| tag_name: ${{ inputs.tag_name || github.ref_name }} | |
| secrets: | |
| BCR_PUBLISH_TOKEN: ${{ secrets.BCR_PUBLISH_TOKEN }} | |
| rust-binaries: | |
| needs: release | |
| runs-on: ${{ matrix.os }} | |
| permissions: | |
| contents: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # bazel_startup_flags shortens the output root on Windows because MSVC's | |
| # link.exe is MAX_PATH-bound (260): under the default root the Rust | |
| # stdlib rlib ...\librustc_std_workspace_alloc-<hash>.rlib comes to 263 | |
| # characters and the link fails with LNK1181. Keep in sync with the | |
| # `release-artifacts` job in ci.yaml, which is where this gets exercised | |
| # per-PR -- including release_config, which builds the Linux asset | |
| # statically against musl so it runs on any distribution rather than | |
| # requiring the runner's glibc or newer. | |
| include: | |
| - os: ubuntu-latest | |
| asset: bazel-diff-rust-linux-amd64 | |
| release_config: release-musl | |
| bazel_startup_flags: "" | |
| bazel_extra_flags: "" | |
| - os: macos-latest | |
| asset: bazel-diff-rust-macos-arm64 | |
| release_config: release | |
| bazel_startup_flags: "" | |
| bazel_extra_flags: "" | |
| - os: windows-latest | |
| asset: bazel-diff-rust-windows-amd64.exe | |
| release_config: release | |
| bazel_startup_flags: "--output_user_root=C:/b" | |
| bazel_extra_flags: "--legacy_external_runfiles" | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ inputs.tag_name || github.ref_name }} | |
| - name: Setup Java JDK | |
| uses: actions/setup-java@v4 | |
| with: | |
| distribution: temurin | |
| java-version: "21" | |
| - name: Setup Go environment | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: ^1.17 | |
| - name: Setup Bazelisk (Linux/macOS) | |
| if: runner.os != 'Windows' | |
| run: | | |
| go install github.com/bazelbuild/bazelisk@latest | |
| echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" | |
| - name: Setup Bazelisk (Windows) | |
| if: runner.os == 'Windows' | |
| shell: pwsh | |
| run: | | |
| go install github.com/bazelbuild/bazelisk@latest | |
| echo "$(go env GOPATH)\bin" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append | |
| # //release:bazel-diff-rust names the binary for the platform Bazel built | |
| # it for, so nothing here renames or relocates it: bazel-bin/release/ holds | |
| # the published asset, and `gh release upload` keeps that file name. The | |
| # build flags live in .bazelrc under matrix.release_config. | |
| - name: Build Rust binary | |
| shell: bash | |
| env: | |
| # Windows runs this under Git bash, whose MSYS runtime rewrites any | |
| # argument starting with `//package` into a `/package` Windows path -- | |
| # Bazel then rejects "invalid package name '/release'". (`//:target` | |
| # survived only because it has no path-like segment to convert.) | |
| MSYS2_ARG_CONV_EXCL: '//' | |
| run: bazelisk ${{ matrix.bazel_startup_flags }} build //release:bazel-diff-rust --config=${{ matrix.release_config }} ${{ matrix.bazel_extra_flags }} | |
| # Last gate before the asset is published: a glibc-linked binary here | |
| # would strand every user on an older distribution than the runner. | |
| - name: Assert Linux binary is statically linked | |
| if: runner.os == 'Linux' | |
| run: .github/workflows/assert_static_binary.sh "bazel-bin/release/${{ matrix.asset }}" | |
| - name: Upload release asset | |
| shell: bash | |
| env: | |
| TAG: ${{ inputs.tag_name || github.ref_name }} | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| gh release upload "$TAG" "bazel-bin/release/${{ matrix.asset }}" \ | |
| --clobber \ | |
| --repo "$GITHUB_REPOSITORY" | |
| finalize: | |
| needs: [publish, rust-binaries] | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - run: gh release edit "$TAG" --draft=false --repo "$GITHUB_REPOSITORY" | |
| env: | |
| TAG: ${{ inputs.tag_name || github.ref_name }} | |
| GH_TOKEN: ${{ github.token }} |