build(deps): Bump github.com/blinklabs-io/gouroboros (#178) #141
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: publish | |
| on: | |
| push: | |
| branches: ['main'] | |
| tags: | |
| - 'v*.*.*' | |
| concurrency: ${{ github.ref }} | |
| jobs: | |
| create-draft-release: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| outputs: | |
| RELEASE_ID: ${{ steps.create-release.outputs.result }} | |
| steps: | |
| - run: "echo \"RELEASE_TAG=${GITHUB_REF#refs/tags/}\" >> $GITHUB_ENV" | |
| - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 https://github.com/actions/github-script/releases/tag/v8.0.0 | |
| id: create-release | |
| if: startsWith(github.ref, 'refs/tags/') | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| result-encoding: string | |
| script: | | |
| try { | |
| const response = await github.rest.repos.createRelease({ | |
| draft: true, | |
| generate_release_notes: true, | |
| name: process.env.RELEASE_TAG, | |
| owner: context.repo.owner, | |
| prerelease: false, | |
| repo: context.repo.repo, | |
| tag_name: process.env.RELEASE_TAG, | |
| }); | |
| return response.data.id; | |
| } catch (error) { | |
| core.setFailed(error.message); | |
| } | |
| build-binaries: | |
| strategy: | |
| matrix: | |
| os: [linux, darwin] | |
| arch: [amd64, arm64] | |
| runs-on: ubuntu-latest | |
| needs: [create-draft-release] | |
| permissions: | |
| actions: write | |
| attestations: write | |
| checks: write | |
| contents: write | |
| id-token: write | |
| packages: write | |
| statuses: write | |
| steps: | |
| - run: "echo \"RELEASE_TAG=${GITHUB_REF#refs/tags/}\" >> $GITHUB_ENV" | |
| - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 https://github.com/actions/checkout/releases/tag/v5.0.0 | |
| with: | |
| fetch-depth: '0' | |
| - uses: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00 # v6.0.0 https://github.com/actions/setup-go/releases/tag/v6.0.0 | |
| with: | |
| go-version: 1.24.x | |
| - name: Build binary | |
| run: GOOS=${{ matrix.os }} GOARCH=${{ matrix.arch }} make build | |
| - name: Upload release asset | |
| if: startsWith(github.ref, 'refs/tags/') | |
| run: | | |
| _filename=vpn-indexer-${{ env.RELEASE_TAG }}-${{ matrix.os }}-${{ matrix.arch }} | |
| if [[ ${{ matrix.os }} == windows ]]; then | |
| _filename=${_filename}.exe | |
| fi | |
| cp vpn-indexer ${_filename} | |
| curl \ | |
| -H "Authorization: token ${{ secrets.GITHUB_TOKEN }}" \ | |
| -H "Content-Type: application/octet-stream" \ | |
| --data-binary @${_filename} \ | |
| https://uploads.github.com/repos/${{ github.repository_owner }}/vpn-indexer/releases/${{ needs.create-draft-release.outputs.RELEASE_ID }}/assets?name=${_filename} | |
| - name: Attest binary | |
| uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3.0.0 https://github.com/actions/attest-build-provenance/releases/tag/v3.0.0 | |
| with: | |
| subject-path: 'vpn-indexer' | |
| build-images: | |
| needs: [create-draft-release] | |
| permissions: | |
| actions: write | |
| attestations: write | |
| checks: write | |
| contents: write | |
| id-token: write | |
| packages: write | |
| statuses: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - os: ubuntu-latest | |
| arch: amd64 | |
| - os: ubuntu-24.04-arm | |
| arch: arm64 | |
| runs-on: ${{ matrix.os }} | |
| steps: | |
| - run: "echo \"RELEASE_TAG=${GITHUB_REF#refs/tags/}\" >> $GITHUB_ENV" | |
| - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 https://github.com/actions/checkout/releases/tag/v5.0.0 | |
| with: | |
| fetch-depth: '0' | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@e468171a9de216ec08956ac3ada2f0791b6bd435 # v3.11.1 https://github.com/docker/setup-buildx-action/releases/tag/v3.11.1 | |
| - name: Login to Docker Hub | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 https://github.com/docker/login-action/releases/tag/v3.6.0 | |
| with: | |
| username: blinklabs | |
| password: ${{ secrets.DOCKER_PASSWORD }} # uses token | |
| - name: Login to GHCR | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 https://github.com/docker/login-action/releases/tag/v3.6.0 | |
| with: | |
| username: ${{ github.repository_owner }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| registry: ghcr.io | |
| - id: meta | |
| uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f # v5.8.0 https://github.com/docker/metadata-action/releases/tag/v5.8.0 | |
| with: | |
| images: | | |
| blinklabs/vpn-indexer | |
| ghcr.io/${{ github.repository }} | |
| flavor: | | |
| latest=false | |
| suffix=-${{ matrix.arch }} | |
| tags: | | |
| # Only version, no revision | |
| type=match,pattern=v(.*)-(.*),group=1 | |
| # branch | |
| type=ref,event=branch | |
| # semver | |
| type=semver,pattern={{version}} | |
| - name: Build images | |
| uses: docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6.18.0 https://github.com/docker/build-push-action/releases/tag/v6.18.0 | |
| id: push | |
| with: | |
| outputs: "type=registry,push=true" | |
| platforms: linux/${{ matrix.arch }} | |
| tags: ${{ steps.meta.outputs.tags }} | |
| labels: ${{ steps.meta.outputs.labels }} | |
| - name: Attest Docker Hub image | |
| uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3.0.0 https://github.com/actions/attest-build-provenance/releases/tag/v3.0.0 | |
| with: | |
| subject-name: index.docker.io/blinklabs/vpn-indexer | |
| subject-digest: ${{ steps.push.outputs.digest }} | |
| push-to-registry: true | |
| - name: Attest GHCR image | |
| uses: actions/attest-build-provenance@977bb373ede98d70efdf65b84cb5f73e068dcc2a # v3.0.0 https://github.com/actions/attest-build-provenance/releases/tag/v3.0.0 | |
| with: | |
| subject-name: ghcr.io/${{ github.repository }} | |
| subject-digest: ${{ steps.push.outputs.digest }} | |
| push-to-registry: true | |
| build-image-manifest: | |
| needs: [build-images] | |
| permissions: | |
| contents: read | |
| packages: write | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Login to Docker Hub | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 https://github.com/docker/login-action/releases/tag/v3.6.0 | |
| with: | |
| username: blinklabs | |
| password: ${{ secrets.DOCKER_PASSWORD }} # uses token | |
| - name: Login to GHCR | |
| uses: docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3.6.0 https://github.com/docker/login-action/releases/tag/v3.6.0 | |
| with: | |
| username: ${{ github.repository_owner }} | |
| password: ${{ secrets.GITHUB_TOKEN }} | |
| registry: ghcr.io | |
| - id: meta | |
| uses: docker/metadata-action@c1e51972afc2121e065aed6d45c65596fe445f3f # v5.8.0 https://github.com/docker/metadata-action/releases/tag/v5.8.0 | |
| with: | |
| images: | | |
| blinklabs/vpn-indexer | |
| ghcr.io/${{ github.repository }} | |
| flavor: | | |
| latest=false | |
| tags: | | |
| # Only version, no revision | |
| type=match,pattern=v(.*)-(.*),group=1 | |
| # branch | |
| type=ref,event=branch | |
| # semver | |
| type=semver,pattern={{version}} | |
| - name: manifest-create | |
| shell: bash | |
| run: | | |
| for t in `echo '${{ steps.meta.outputs.tags }}'`; do | |
| # Extract the underlying manifests from each manifests list and create a new single manifest list | |
| docker manifest create ${t} \ | |
| $(docker manifest inspect ${t}-amd64 | jq -r '.manifests[] | .digest' | sed -e "s|^|${t%:*}@|") \ | |
| $(docker manifest inspect ${t}-arm64 | jq -r '.manifests[] | .digest' | sed -e "s|^|${t%:*}@|") | |
| docker manifest push ${t} | |
| done | |
| # Checkout repo so README.md is available for next step | |
| - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 https://github.com/actions/checkout/releases/tag/v5.0.0 | |
| # Update Docker Hub from README | |
| - name: Docker Hub Description | |
| uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5.0.0 https://github.com/peter-evans/dockerhub-description/releases/tag/v5.0.0 | |
| with: | |
| username: blinklabs | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| repository: blinklabs/vpn-indexer | |
| readme-filepath: ./README.md | |
| short-description: "VPN indexer" | |
| finalize-release: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| needs: [create-draft-release, build-binaries, build-images, build-image-manifest] | |
| steps: | |
| - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0 https://github.com/actions/github-script/releases/tag/v8.0.0 | |
| if: startsWith(github.ref, 'refs/tags/') | |
| with: | |
| github-token: ${{ secrets.GITHUB_TOKEN }} | |
| script: | | |
| try { | |
| await github.rest.repos.updateRelease({ | |
| owner: context.repo.owner, | |
| repo: context.repo.repo, | |
| release_id: ${{ needs.create-draft-release.outputs.RELEASE_ID }}, | |
| draft: false, | |
| }); | |
| } catch (error) { | |
| core.setFailed(error.message); | |
| } |