Release automation #17
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
name: Release automation | |
on: | |
workflow_dispatch: | |
inputs: | |
commit_id: | |
description: 'Commit ID to tag and create a release for' | |
required: true | |
version_number: | |
description: 'Release Version Number (Eg, v1.0.0)' | |
required: true | |
jobs: | |
tag-commit: | |
name: Tag commit | |
runs-on: ubuntu-latest | |
steps: | |
- name: Checkout code | |
uses: actions/checkout@v4 | |
with: | |
ref: ${{ github.event.inputs.commit_id }} | |
- name: Configure git identity | |
run: | | |
git config --global user.name ${{ github.actor }} | |
git config --global user.email ${{ github.actor }}@users.noreply.github.com | |
- name: create a new branch that references commit id | |
run: git checkout -b ${{ github.event.inputs.version_number }} ${{ github.event.inputs.commit_id }} | |
- name: Generate SBOM | |
uses: FreeRTOS/CI-CD-Github-Actions/sbom-generator@main | |
with: | |
repo_path: ./ | |
source_path: ./source | |
- name: commit SBOM file | |
run: | | |
git add . | |
git commit -m 'Update SBOM' | |
git push -u origin ${{ github.event.inputs.version_number }} | |
- name: Tag Commit and Push to remote | |
run: | | |
git tag ${{ github.event.inputs.version_number }} -a -m "corePKCS11 Library ${{ github.event.inputs.version_number }}" | |
git push origin --tags | |
- name: Verify tag on remote | |
run: | | |
git tag -d ${{ github.event.inputs.version_number }} | |
git remote update | |
git checkout tags/${{ github.event.inputs.version_number }} | |
git diff ${{ github.event.inputs.commit_id }} tags/${{ github.event.inputs.version_number }} | |
create-zip: | |
needs: tag-commit | |
name: Create ZIP and verify package for release asset. | |
runs-on: ubuntu-latest | |
steps: | |
- name: Install ZIP tools | |
run: sudo apt-get install zip unzip | |
- name: Checkout code | |
uses: actions/checkout@v4 | |
with: | |
ref: ${{ github.event.inputs.commit_id }} | |
path: corePKCS11 | |
submodules: recursive | |
- name: Checkout disabled submodules | |
run: | | |
cd corePKCS11 | |
git submodule update --init --checkout --recursive | |
- name: Create ZIP | |
run: | | |
zip -r corePKCS11-${{ github.event.inputs.version_number }}.zip corePKCS11 -x "*.git*" | |
ls ./ | |
- name: Validate created ZIP | |
run: | | |
mkdir zip-check | |
mv corePKCS11-${{ github.event.inputs.version_number }}.zip zip-check | |
cd zip-check | |
unzip corePKCS11-${{ github.event.inputs.version_number }}.zip -d corePKCS11-${{ github.event.inputs.version_number }} | |
ls corePKCS11-${{ github.event.inputs.version_number }} | |
diff -r -x "*.git*" corePKCS11-${{ github.event.inputs.version_number }}/corePKCS11/ ../corePKCS11/ | |
cd ../ | |
- name: Build | |
run: | | |
cd zip-check/corePKCS11-${{ github.event.inputs.version_number }}/corePKCS11 | |
sudo apt-get install -y lcov | |
cmake -S test -B build/ \ | |
-G "Unix Makefiles" \ | |
-DCMAKE_BUILD_TYPE=Debug \ | |
-DBUILD_CLONE_SUBMODULES=ON \ | |
-DCMAKE_C_FLAGS='--coverage -Wall -Wextra -DNDEBUG' | |
make -C build/ all | |
- name: Test | |
run: | | |
cd zip-check/corePKCS11-${{ github.event.inputs.version_number }}/corePKCS11/build/ | |
ctest -E system --output-on-failure | |
cd .. | |
- name: Create artifact of ZIP | |
uses: actions/upload-artifact@v4 | |
with: | |
name: corePKCS11-${{ github.event.inputs.version_number }}.zip | |
path: zip-check/corePKCS11-${{ github.event.inputs.version_number }}.zip | |
deploy-doxygen: | |
needs: tag-commit | |
name: Deploy doxygen documentation | |
runs-on: ubuntu-latest | |
steps: | |
- name: Doxygen generation | |
uses: FreeRTOS/CI-CD-Github-Actions/doxygen-generation@main | |
with: | |
ref: ${{ github.event.inputs.version_number }} | |
add_release: "true" | |
create-release: | |
needs: | |
- create-zip | |
- deploy-doxygen | |
name: Create Release and Upload Release Asset | |
runs-on: ubuntu-latest | |
steps: | |
- name: Create Release | |
id: create_release | |
uses: actions/create-release@v1 | |
env: | |
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
with: | |
tag_name: ${{ github.event.inputs.version_number }} | |
release_name: ${{ github.event.inputs.version_number }} | |
body: Release ${{ github.event.inputs.version_number }} of the corePKCS11 Library. | |
draft: false | |
prerelease: false | |
- name: Download ZIP artifact | |
uses: actions/download-artifact@v4 | |
with: | |
name: corePKCS11-${{ github.event.inputs.version_number }}.zip | |
- name: Upload Release Asset | |
id: upload-release-asset | |
uses: actions/upload-release-asset@v1 | |
env: | |
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
with: | |
upload_url: ${{ steps.create_release.outputs.upload_url }} | |
asset_path: ./corePKCS11-${{ github.event.inputs.version_number }}.zip | |
asset_name: corePKCS11-${{ github.event.inputs.version_number }}.zip | |
asset_content_type: application/zip |