-
-
Notifications
You must be signed in to change notification settings - Fork 0
125 lines (113 loc) · 4.92 KB
/
Copy pathrelease.yml
File metadata and controls
125 lines (113 loc) · 4.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
# Builds `agentiloop` for macOS, Linux and Windows.
#
# - Push a tag like `v0.0.1` → builds everything and publishes a GitHub Release.
# - "Run workflow" on the Actions tab → builds everything; download from the run's Artifacts.
#
# macOS binaries are always signed with the Developer ID and notarized; the
# build fails if any of these repo secrets is missing or Apple rejects it:
# MACOS_CERT_P12 base64 of a "Developer ID Application" .p12
# MACOS_CERT_PASSWORD password of that .p12
# MACOS_SIGN_IDENTITY e.g. "Developer ID Application: Your Name (TEAMID)"
# APPLE_ID, APPLE_TEAM_ID, APPLE_APP_PASSWORD for notarization (app-specific password)
name: Release
on:
push:
tags: ["v*"]
workflow_dispatch:
permissions:
contents: write
jobs:
build:
name: ${{ matrix.name }}
runs-on: ${{ matrix.os }}
env:
CGO_ENABLED: "0"
GOOS: ${{ matrix.goos }}
GOARCH: ${{ matrix.goarch }}
strategy:
fail-fast: false
matrix:
include:
- { name: macos-arm64, os: macos-latest, goos: darwin, goarch: arm64 }
- { name: macos-x86_64, os: macos-latest, goos: darwin, goarch: amd64 }
- { name: linux-x86_64, os: ubuntu-latest, goos: linux, goarch: amd64 }
- { name: linux-arm64, os: ubuntu-latest, goos: linux, goarch: arm64 }
- { name: windows-x86_64, os: windows-latest, goos: windows, goarch: amd64 }
steps:
- uses: actions/checkout@v4
- uses: actions/setup-go@v5
with:
go-version-file: go.mod
- name: Build
shell: bash
run: |
EXT=""; [ "$GOOS" = windows ] && EXT=".exe"
go build -trimpath -ldflags "-s -w" -o "dist/agentiloop${EXT}" ./cmd/agentiloop
- name: Sign and notarize (macOS)
if: runner.os == 'macOS'
env:
MACOS_CERT_P12: ${{ secrets.MACOS_CERT_P12 }}
MACOS_CERT_PASSWORD: ${{ secrets.MACOS_CERT_PASSWORD }}
MACOS_SIGN_IDENTITY: ${{ secrets.MACOS_SIGN_IDENTITY }}
APPLE_ID: ${{ secrets.APPLE_ID }}
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
APPLE_APP_PASSWORD: ${{ secrets.APPLE_APP_PASSWORD }}
run: |
# Required: never ship an unsigned or un-notarized mac binary.
for v in MACOS_CERT_P12 MACOS_CERT_PASSWORD MACOS_SIGN_IDENTITY APPLE_ID APPLE_TEAM_ID APPLE_APP_PASSWORD; do
[ -n "${!v}" ] || { echo "::error::secret $v is not set"; exit 1; }
done
BIN=dist/agentiloop
KC=$RUNNER_TEMP/build.keychain
echo "$MACOS_CERT_P12" | base64 --decode > "$RUNNER_TEMP/cert.p12"
security create-keychain -p ci "$KC"
security set-keychain-settings -lut 3600 "$KC"
security unlock-keychain -p ci "$KC"
security import "$RUNNER_TEMP/cert.p12" -k "$KC" -P "$MACOS_CERT_PASSWORD" -T /usr/bin/codesign
security set-key-partition-list -S apple-tool:,apple: -s -k ci "$KC"
security list-keychains -d user -s "$KC"
codesign --force --timestamp --options runtime --sign "$MACOS_SIGN_IDENTITY" "$BIN"
codesign --verify --strict --verbose=2 "$BIN"
ditto -c -k "$BIN" "$RUNNER_TEMP/notarize.zip"
# --wait returns 0 even when Apple rejects; check the status explicitly.
xcrun notarytool submit "$RUNNER_TEMP/notarize.zip" --wait \
--apple-id "$APPLE_ID" --team-id "$APPLE_TEAM_ID" --password "$APPLE_APP_PASSWORD" \
| tee "$RUNNER_TEMP/notary.log"
grep -q "status: Accepted" "$RUNNER_TEMP/notary.log" || { echo "::error::notarization was not accepted"; exit 1; }
- name: Package (macOS / Linux)
if: runner.os != 'Windows'
run: |
NAME=agentiloop-${{ matrix.name }}
mkdir -p "pkg/$NAME"
cp dist/agentiloop README.md LICENSE "pkg/$NAME/"
tar -C pkg -czf "pkg/$NAME.tar.gz" "$NAME"
- name: Package (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
$name = "agentiloop-${{ matrix.name }}"
New-Item -ItemType Directory -Force pkg/$name | Out-Null
Copy-Item dist/agentiloop.exe, README.md, LICENSE pkg/$name/
Compress-Archive -Path pkg/$name -DestinationPath pkg/$name.zip
- uses: actions/upload-artifact@v4
with:
name: agentiloop-${{ matrix.name }}
path: |
pkg/*.tar.gz
pkg/*.zip
release:
name: Publish release
needs: build
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
steps:
- uses: actions/download-artifact@v4
with:
path: dist
merge-multiple: true
- uses: softprops/action-gh-release@v2
with:
files: dist/*
generate_release_notes: true
# 0.x versions and tags like v1.0.0-beta.1 are published as pre-releases.
prerelease: ${{ startsWith(github.ref_name, 'v0.') || contains(github.ref_name, '-') }}