Repository navigation
172 lines (163 loc) · 6.23 KB
/
Copy pathvscode-extension-release.yml
File metadata and controls
172 lines (163 loc) · 6.23 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
name: Release VS Code extension
on:
workflow_dispatch:
inputs:
candidate_sha:
description: Exact 40-character branch-head commit SHA to release
required: true
type: string
dry_run:
description: Validate full CI and VSIX artifacts without tagging or publishing
required: false
default: false
type: boolean
concurrency:
group: ${{ github.workflow }}-${{ github.run_id }}
cancel-in-progress: false
permissions:
contents: read
actions: read
jobs:
full-coverage:
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.candidate_sha }}
- name: Require exact-SHA full release CI before tagging
env:
GH_TOKEN: ${{ github.token }}
EXPECTED_SHA: ${{ inputs.candidate_sha }}
run: |
[[ "$EXPECTED_SHA" =~ ^[0-9a-f]{40}$ ]]
[[ "$GITHUB_REF" == refs/heads/* ]]
test "$EXPECTED_SHA" = "$GITHUB_SHA"
test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"
python ci/verify_full_coverage.py --sha "$EXPECTED_SHA"
validate-version:
needs: [full-coverage]
runs-on: ubuntu-24.04
outputs:
version: ${{ steps.version.outputs.version }}
tag: ${{ steps.version.outputs.tag }}
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.candidate_sha }}
- id: version
env:
EXPECTED_SHA: ${{ inputs.candidate_sha }}
run: |
test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"
VERSION=$(node -p "require('./vscode-plugin/package.json').version")
TAG="vscode-v${VERSION}"
if git ls-remote --exit-code --tags origin "refs/tags/${TAG}" >/dev/null 2>&1; then
git fetch --no-tags origin "refs/tags/${TAG}:refs/tags/${TAG}"
test "$(git rev-parse "${TAG}^{commit}")" = "$EXPECTED_SHA" || {
echo "Existing tag ${TAG} points to another commit" >&2
exit 1
}
fi
echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
echo "tag=${TAG}" >> "$GITHUB_OUTPUT"
build:
needs: [full-coverage, validate-version]
if: needs.full-coverage.result == 'success' && needs.validate-version.result == 'success'
uses: ./.github/workflows/vscode-extension.yml
with:
release_build: true
artifact-preflight:
needs: [full-coverage, validate-version, build]
if: needs.full-coverage.result == 'success' && needs.validate-version.result == 'success' && needs.build.result == 'success'
runs-on: ubuntu-24.04
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.candidate_sha }}
- uses: actions/download-artifact@v4
with: { pattern: vscode-*, path: artifacts, merge-multiple: true }
- name: Validate the seven VSIX packages before tagging
env:
VERSION: ${{ needs.validate-version.outputs.version }}
EXPECTED_SHA: ${{ inputs.candidate_sha }}
run: |
test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"
python ci/vscode_release_artifact_lint.py --artifacts artifacts --version "$VERSION"
create-tag:
needs: [full-coverage, validate-version, artifact-preflight]
if: >-
!cancelled() &&
inputs.dry_run != true &&
needs.full-coverage.result == 'success' &&
needs.validate-version.result == 'success' &&
needs.artifact-preflight.result == 'success'
runs-on: ubuntu-24.04
permissions:
contents: write
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.candidate_sha }}
- name: Create release tag from the verified commit
env:
EXPECTED_SHA: ${{ inputs.candidate_sha }}
TAG: ${{ needs.validate-version.outputs.tag }}
run: |
test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"
git config --local user.email "action@github.com"
git config --local user.name "GitHub Action"
if git ls-remote --exit-code --tags origin "refs/tags/${TAG}" >/dev/null 2>&1; then
git fetch --no-tags origin "refs/tags/${TAG}:refs/tags/${TAG}"
test "$(git rev-parse "${TAG}^{commit}")" = "$EXPECTED_SHA" || {
echo "Existing tag ${TAG} points to another commit" >&2
exit 1
}
else
git tag -a "$TAG" -m "Release VS Code ${{ needs.validate-version.outputs.version }}"
git push origin "refs/tags/${TAG}"
fi
publish:
needs: [full-coverage, validate-version, artifact-preflight, create-tag]
if: >-
!cancelled() &&
inputs.dry_run != true &&
needs.full-coverage.result == 'success' &&
needs.artifact-preflight.result == 'success' &&
needs.create-tag.result == 'success'
runs-on: ubuntu-24.04
permissions:
contents: write
id-token: write
attestations: write
steps:
- uses: actions/checkout@v4
with:
ref: ${{ inputs.candidate_sha }}
- uses: actions/download-artifact@v4
with: { pattern: vscode-*, path: artifacts, merge-multiple: true }
- name: Verify release artifacts again
env:
VERSION: ${{ needs.validate-version.outputs.version }}
EXPECTED_SHA: ${{ inputs.candidate_sha }}
run: |
test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"
python ci/vscode_release_artifact_lint.py --artifacts artifacts --version "$VERSION"
- name: Produce checksums
run: |
cd artifacts
sha256sum *.vsix > SHA256SUMS.txt
- uses: actions/attest-build-provenance@v2
with:
subject-path: artifacts/*.vsix
- name: Create GitHub release from the verified package bytes
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ needs.validate-version.outputs.tag }}
VERSION: ${{ needs.validate-version.outputs.version }}
run: gh release create "$TAG" artifacts/* --title "FastLED VS Code $VERSION" --generate-notes
- name: Publish those same prebuilt VSIX files to Marketplace
env:
VSCE_PAT: ${{ secrets.VSCE_PAT }}
run: |
test -n "$VSCE_PAT"
for vsix in artifacts/*.vsix; do npx --yes @vscode/vsce@3.6.2 publish --packagePath "$vsix" --pat "$VSCE_PAT"; done