Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
89 changes: 89 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
name: Release

on:
workflow_dispatch:
push:
tags:
- "v*"

permissions:
contents: write

jobs:
release-windows:
environment: release
runs-on: windows-latest

steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
fetch-depth: 0

- uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
with:
targets: wasm32-unknown-unknown

- uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
workspaces: ". -> target"

- name: Validate release ref and version
shell: pwsh
run: |
$manifest = Get-Content Cargo.toml -Raw
if ($manifest -notmatch '(?ms)^\[workspace\.package\]\s*.*?^version\s*=\s*"([^"]+)"') {
throw "Unable to read the workspace version from Cargo.toml."
}
$version = $Matches[1]
$tauriVersion = (Get-Content src-tauri\tauri.conf.json -Raw | ConvertFrom-Json).version
if ($version -ne $tauriVersion) {
throw "Cargo.toml version '$version' does not match tauri.conf.json version '$tauriVersion'."
}

if ($env:GITHUB_EVENT_NAME -eq "push") {
$expectedTag = "v$version"
if ($env:GITHUB_REF_NAME -ne $expectedTag) {
throw "Release tag '$env:GITHUB_REF_NAME' must match application version '$expectedTag'."
}
git merge-base --is-ancestor $env:GITHUB_SHA origin/master
if ($LASTEXITCODE -ne 0) {
throw "Release tag '$env:GITHUB_REF_NAME' must point to a commit on master."
}
} elseif ($env:GITHUB_REF_NAME -ne "master") {
throw "Manual releases must run from the master branch."
}

- name: Validate updater signing configuration
shell: pwsh
env:
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_UPDATER_PUBLIC_KEY: ${{ vars.TAURI_UPDATER_PUBLIC_KEY }}
run: |
if (-not $env:TAURI_SIGNING_PRIVATE_KEY) {
throw "Release environment secret TAURI_SIGNING_PRIVATE_KEY is required."
}
if (-not $env:TAURI_UPDATER_PUBLIC_KEY) {
throw "Repository variable TAURI_UPDATER_PUBLIC_KEY is required."
}

- name: Prepare toolchain and bundled Everything runtime
shell: pwsh
run: .\scripts\setup.ps1 -SkipFormat

- name: Build and publish GitHub release
uses: tauri-apps/tauri-action@1deb371b0cd8bd54025b384f1cd735e725c4060f # action-v1.0.0
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
TAURI_UPDATER_PUBLIC_KEY: ${{ vars.TAURI_UPDATER_PUBLIC_KEY }}
with:
tagName: v__VERSION__
releaseName: "Everything Next v__VERSION__"
generateReleaseNotes: true
releaseDraft: false
prerelease: false
uploadUpdaterJson: true
updaterJsonPreferNsis: true
uploadUpdaterSignatures: true
args: --config src-tauri/tauri.release.conf.json
Loading