# This workflow is main release, needs to be manually tagged & pushed. on: push: paths-ignore: - "documentation/**" tags: - "v1.*" name: Release permissions: id-token: write # Required for Sigstore OIDC signing and AWS OIDC (Windows signing) contents: write # Required for creating releases and by actions/checkout actions: read # May be needed for some workflows pull-requests: write # Required for npm publish workflow attestations: write # Required for SLSA build provenance attestations concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true jobs: # ------------------------------------ # 1) Build CLI for multiple OS/Arch # ------------------------------------ build-cli: uses: ./.github/workflows/build-cli.yml # ------------------------------------ # 2) Upload Install CLI Script # ------------------------------------ install-script: name: Upload Install Script runs-on: ubuntu-latest needs: [build-cli] steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - uses: actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6.0.0 with: name: download_cli.sh path: download_cli.sh # ------------------------------------------------------------ # 3) Bundle Desktop App (macOS) # ------------------------------------------------------------ bundle-desktop: uses: ./.github/workflows/bundle-desktop.yml permissions: id-token: write contents: read with: signing: true environment: signing secrets: inherit # ------------------------------------------------------------ # 4) Bundle Desktop App (macOS) # ------------------------------------------------------------ bundle-desktop-intel: uses: ./.github/workflows/bundle-desktop-intel.yml permissions: id-token: write contents: read with: signing: true environment: signing secrets: inherit # ------------------------------------------------------------ # 5) Bundle Desktop App (Linux) # ------------------------------------------------------------ bundle-desktop-linux: uses: ./.github/workflows/bundle-desktop-linux.yml # # ------------------------------------------------------------ # # 6) Bundle Desktop App (Windows) # # ------------------------------------------------------------ bundle-desktop-windows: uses: ./.github/workflows/bundle-desktop-windows.yml permissions: id-token: write contents: read actions: read with: signing: true secrets: inherit bundle-desktop-windows-cuda: uses: ./.github/workflows/bundle-desktop-windows.yml permissions: id-token: write contents: read actions: read with: signing: true windows_variant: cuda secrets: inherit # ------------------------------------ # 7) Create/Update GitHub Release # ------------------------------------ release: name: Release runs-on: ubuntu-latest needs: [build-cli, install-script, bundle-desktop, bundle-desktop-intel, bundle-desktop-linux, bundle-desktop-windows, bundle-desktop-windows-cuda] permissions: contents: write id-token: write # Required for Sigstore OIDC signing attestations: write # Required for SLSA build provenance attestations steps: - name: Download all artifacts uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: merge-multiple: true - name: Attest build provenance uses: actions/attest-build-provenance@a2bbfa25375fe432b6a289bc6b6cd05ecd0c4c32 # v4.1.0 with: subject-path: | goose-*.tar.bz2 goose-*.tar.gz goose-*.zip Goose*.zip *.deb *.rpm *.flatpak download_cli.sh # Create/update the versioned release - name: Release versioned uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1.21.0 with: token: ${{ secrets.GITHUB_TOKEN }} artifacts: | goose-*.tar.bz2 goose-*.tar.gz goose-*.zip Goose*.zip *.deb *.rpm *.flatpak download_cli.sh allowUpdates: true omitBody: true omitPrereleaseDuringUpdate: true # Create/update the stable release - name: Release stable uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1.21.0 with: tag: stable name: Stable token: ${{ secrets.GITHUB_TOKEN }} artifacts: | goose-*.tar.bz2 goose-*.tar.gz goose-*.zip Goose*.zip *.deb *.rpm *.flatpak download_cli.sh allowUpdates: true omitBody: true omitPrereleaseDuringUpdate: true