Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 23 additions & 5 deletions .github/workflows/ci-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,8 @@ name: CI and Release

# Tests run on every pull request update.
# On merge (or manual dispatch), tests must pass, then we bump the version,
# create a tag + GitHub release (notes from commits), and attach production builds.
# create a tag + draft GitHub release, attach production builds, then publish
# (draft-first so immutable releases can still receive assets).
on:
pull_request:
types: [opened, synchronize, reopened, closed]
Expand Down Expand Up @@ -187,22 +188,24 @@ jobs:
} > "${NOTES_FILE}"
echo "path=${NOTES_FILE}" >> "$GITHUB_OUTPUT"

- name: Create GitHub release
- name: Create draft GitHub release
id: create_release
env:
GH_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }}
TAG: ${{ steps.bump.outputs.tag }}
NOTES_FILE: ${{ steps.notes.outputs.path }}
run: |
set -euo pipefail
# Draft first so assets can upload before immutable publish locks the release.
URL="$(gh release create "${TAG}" \
--title "${TAG}" \
--notes-file "${NOTES_FILE}" \
--draft \
--verify-tag)"
echo "url=${URL}" >> "$GITHUB_OUTPUT"
ID="$(gh release view "${TAG}" --json databaseId --jq .databaseId)"
echo "id=${ID}" >> "$GITHUB_OUTPUT"
echo "Created release ${TAG} (${URL})"
echo "Created draft release ${TAG} (${URL})"

build:
name: Production build (${{ matrix.label }})
Expand Down Expand Up @@ -269,13 +272,28 @@ jobs:
- name: Install frontend dependencies
run: pnpm install --frozen-lockfile

- name: Build and upload to release
- name: Build and upload to draft release
uses: tauri-apps/tauri-action@v1
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }}
with:
tagName: ${{ needs.version-and-release.outputs.tag }}
releaseId: ${{ needs.version-and-release.outputs.release_id }}
releaseDraft: false
releaseDraft: true
prerelease: false
args: ${{ matrix.args }}

publish-release:
name: Publish release
needs: [version-and-release, build]
runs-on: ubuntu-22.04
steps:
- name: Publish draft release
env:
GH_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }}
TAG: ${{ needs.version-and-release.outputs.tag }}
run: |
set -euo pipefail
gh release edit "${TAG}" --draft=false
echo "Published immutable release ${TAG}"
gh release view "${TAG}" --json url,isDraft,isImmutable,assets --jq '{url,isDraft,isImmutable,asset_count:(.assets|length),assets:[.assets[].name]}'
5 changes: 3 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,8 +66,9 @@ Every pull request runs the test suite. When a PR is **merged**, or when you run
- Title starts with `MAJOR` → major bump (`1.2.3` → `2.0.0`)
- Title starts with `MINOR` → minor bump (`1.2.3` → `1.3.0`)
- Title starts with `PATCH`, or anything else → patch bump (`1.2.3` → `1.2.4`)
3. Creates a `vX.Y.Z` tag and a GitHub Release (notes from commit subjects since the previous tag)
4. Builds production bundles for macOS (arm64 + x64), Linux x64, and Windows x64 (NSIS setup.exe **and** MSI), then attaches them to that release
3. Creates a draft `vX.Y.Z` GitHub Release (notes from commit subjects since the previous tag)
4. Builds production bundles for macOS (arm64 + x64), Linux x64, and Windows x64 (NSIS setup.exe **and** MSI), then attaches them to that draft
5. Publishes the release (immutable releases lock assets only after publish)

Example titles: `MINOR add dark mode default`, `MAJOR redesign library schema`, `add filter sidebar` (patch).

Expand Down
Loading