Skip to content

Commit 296ac45

Browse files
authored
Merge pull request #83 from bastelfreak/perms
Add CI workflow and set token permissions
2 parents 4e410c5 + 03f976c commit 296ac45

3 files changed

Lines changed: 95 additions & 21 deletions

File tree

.github/workflows/ci.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,8 @@ on:
77
branches:
88
- master
99

10-
env:
11-
BUNDLE_WITHOUT: release
10+
permissions:
11+
contents: read # minimal required permissions to clone repo
1212

1313
jobs:
1414
rubocop:

.github/workflows/release.yml

Lines changed: 90 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,32 +1,106 @@
1-
name: Release
1+
---
2+
name: Gem Release
23

34
on:
45
push:
56
tags:
67
- '*'
78

9+
permissions: {}
10+
811
jobs:
9-
release:
10-
runs-on: ubuntu-latest
12+
build-release:
13+
# Prevent releases from forked repositories
1114
if: github.repository_owner == 'voxpupuli'
15+
name: Build the gem
16+
runs-on: ubuntu-24.04
1217
steps:
1318
- uses: actions/checkout@v4
14-
- name: Install Ruby 3.2
19+
- name: Install Ruby
1520
uses: ruby/setup-ruby@v1
1621
with:
17-
ruby-version: '3.2'
18-
env:
19-
BUNDLE_WITHOUT: release
22+
ruby-version: 'ruby'
2023
- name: Build gem
21-
run: gem build *.gemspec
24+
shell: bash
25+
run: gem build --verbose *.gemspec
26+
- name: Upload gem to GitHub cache
27+
uses: actions/upload-artifact@v4
28+
with:
29+
name: gem-artifact
30+
path: '*.gem'
31+
retention-days: 1
32+
compression-level: 0
33+
34+
create-github-release:
35+
needs: build-release
36+
name: Create GitHub release
37+
runs-on: ubuntu-24.04
38+
permissions:
39+
contents: write # clone repo and create release
40+
steps:
41+
- name: Download gem from GitHub cache
42+
uses: actions/download-artifact@v5
43+
with:
44+
name: gem-artifact
45+
- name: Create Release
46+
shell: bash
47+
env:
48+
GH_TOKEN: ${{ github.token }}
49+
run: gh release create --repo ${{ github.repository }} ${{ github.ref_name }} --generate-notes *.gem
50+
51+
release-to-github:
52+
needs: build-release
53+
name: Release to GitHub
54+
runs-on: ubuntu-24.04
55+
permissions:
56+
packages: write # publish to rubygems.pkg.github.com
57+
steps:
58+
- name: Download gem from GitHub cache
59+
uses: actions/download-artifact@v5
60+
with:
61+
name: gem-artifact
62+
- name: Publish gem to GitHub packages
63+
run: gem push --host https://rubygems.pkg.github.com/${{ github.repository_owner }} *.gem
64+
env:
65+
GEM_HOST_API_KEY: ${{ secrets.GITHUB_TOKEN }}
66+
67+
release-to-rubygems:
68+
needs: build-release
69+
name: Release gem to rubygems.org
70+
runs-on: ubuntu-24.04
71+
environment: release # recommended by rubygems.org
72+
permissions:
73+
id-token: write # rubygems.org authentication
74+
steps:
75+
- name: Download gem from GitHub cache
76+
uses: actions/download-artifact@v5
77+
with:
78+
name: gem-artifact
79+
- uses: rubygems/configure-rubygems-credentials@v1.0.0
2280
- name: Publish gem to rubygems.org
81+
shell: bash
2382
run: gem push *.gem
24-
env:
25-
GEM_HOST_API_KEY: '${{ secrets.RUBYGEMS_AUTH_TOKEN }}'
26-
- name: Setup GitHub packages access
83+
84+
release-verification:
85+
name: Check that all releases are done
86+
runs-on: ubuntu-24.04
87+
permissions:
88+
contents: read # minimal permissions that we have to grant
89+
needs:
90+
- create-github-release
91+
- release-to-github
92+
- release-to-rubygems
93+
steps:
94+
- name: Download gem from GitHub cache
95+
uses: actions/download-artifact@v5
96+
with:
97+
name: gem-artifact
98+
- name: Install Ruby
99+
uses: ruby/setup-ruby@v1
100+
with:
101+
ruby-version: 'ruby'
102+
- name: Wait for release to propagate
103+
shell: bash
27104
run: |
28-
mkdir -p ~/.gem
29-
echo ":github: Bearer ${{ secrets.GITHUB_TOKEN }}" >> ~/.gem/credentials
30-
chmod 0600 ~/.gem/credentials
31-
- name: Publish gem to GitHub packages
32-
run: gem push --key github --host https://rubygems.pkg.github.com/voxpupuli *.gem
105+
gem install rubygems-await
106+
gem await *.gem

Gemfile

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ source ENV['GEM_SOURCE'] || 'https://rubygems.org'
44

55
gemspec
66

7-
group :release do
8-
gem 'faraday-retry', require: false
9-
gem 'github_changelog_generator', require: false
7+
group :release, optional: true do
8+
gem 'faraday-retry', '~> 2.1', require: false
9+
gem 'github_changelog_generator', '~> 1.16.4', require: false
1010
end

0 commit comments

Comments
 (0)