name: release on: push: tags: - 'v*' # Needed to create the draft release. permissions: contents: write jobs: draft-release: runs-on: ubuntu-24.04 steps: - uses: actions/checkout@v7 with: submodules: recursive # Tags let git describe stamp the exact release version into # the binary rather than the Makefile fallback. fetch-tags: true fetch-depth: 0 - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev # Build two hardened variants: a self-contained one with no Lua, and one # that links the lua: filter backend. Each is packaged with a checksum. - name: Build and package both variants run: | package() { # $1 = release-build.sh arg, $2 = tarball suffix ./tools/release-build.sh $1 dist="cgit-${GITHUB_REF_NAME}${2}" make dist DIST_NAME="$dist" mv "build/${dist}.tar.gz" . sha256sum "${dist}.tar.gz" > "${dist}.tar.gz.sha256" } package "" "" package "lua" "-lua" # Creates a DRAFT release only. Review and publish it by hand. - name: Create draft release env: GH_TOKEN: ${{ github.token }} run: | gh release create "${GITHUB_REF_NAME}" \ --draft \ --title "cgit ${GITHUB_REF_NAME}" \ --generate-notes \ "cgit-${GITHUB_REF_NAME}.tar.gz" \ "cgit-${GITHUB_REF_NAME}.tar.gz.sha256" \ "cgit-${GITHUB_REF_NAME}-lua.tar.gz" \ "cgit-${GITHUB_REF_NAME}-lua.tar.gz.sha256"