|
38 | 38 | service_account: ${{ vars.DEPLOYER_SA_EMAIL }} |
39 | 39 | - uses: google-github-actions/setup-gcloud@v2 |
40 | 40 |
|
| 41 | + # goreleaser's `sboms` block shells out to syft; install it so the SBOM step succeeds. |
| 42 | + - name: install syft (SBOM) |
| 43 | + uses: anchore/sbom-action/download-syft@v0 |
| 44 | + |
41 | 45 | # google-github-actions/auth writes gha-creds-*.json into the workspace; exclude it so |
42 | 46 | # goreleaser's clean-tree check does not fail with "git is in a dirty state". |
43 | 47 | - name: keep the tree clean for goreleaser |
|
61 | 65 | - name: publish binaries -> Artifact Registry (generic) |
62 | 66 | run: | |
63 | 67 | set -euo pipefail |
64 | | - VER="${GITHUB_REF_NAME}" |
| 68 | + VER="${GITHUB_REF_NAME#v}" # strip the leading v; goreleaser archives are named without it |
65 | 69 | for f in dist/interlock_*.tar.gz dist/interlock_*.zip dist/checksums.txt; do |
66 | 70 | [ -e "$f" ] || continue |
67 | 71 | gcloud artifacts generic upload \ |
|
73 | 77 | - name: update latest channel manifest |
74 | 78 | run: | |
75 | 79 | set -euo pipefail |
76 | | - printf '{"version":"%s"}\n' "${GITHUB_REF_NAME}" > latest.json |
| 80 | + printf '{"version":"%s"}\n' "${GITHUB_REF_NAME#v}" > latest.json |
77 | 81 | gcloud artifacts generic upload \ |
78 | 82 | --project="${{ vars.AR_PROJECT }}" --location="${{ vars.AR_LOCATION }}" \ |
79 | 83 | --repository="${{ vars.AR_GENERIC_REPO }}" \ |
|
83 | 87 | working-directory: clients/typescript |
84 | 88 | run: | |
85 | 89 | set -euo pipefail |
| 90 | + npm version "${GITHUB_REF_NAME#v}" --no-git-tag-version --allow-same-version |
86 | 91 | gcloud artifacts print-settings npm \ |
87 | 92 | --project="${{ vars.AR_PROJECT }}" --location="${{ vars.AR_LOCATION }}" \ |
88 | 93 | --repository="${{ vars.AR_NPM_REPO }}" --scope=@operatorstack > .npmrc |
|
93 | 98 | working-directory: clients/python |
94 | 99 | run: | |
95 | 100 | set -euo pipefail |
| 101 | + sed -i "s/^version = .*/version = \"${GITHUB_REF_NAME#v}\"/" pyproject.toml |
96 | 102 | pip install --quiet build twine keyrings.google-artifactregistry-auth |
97 | 103 | python -m build |
98 | 104 | twine upload \ |
|
0 commit comments