Skip to content

Commit a4637f1

Browse files
authored
Merge pull request #168 from github/bb8gh/release-plz-workflows
Replace publish-crates workflow with release-plz
2 parents 5eeca08 + 65ef08f commit a4637f1

5 files changed

Lines changed: 121 additions & 104 deletions

File tree

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
# Launch this workflow with the "Run workflow" button in the Actions tab of the repository.
2+
#
3+
# See https://github.com/github/rust-gems/blob/main/CONTRIBUTING.md#releasing-a-crate for more details.
4+
name: Create release PR
5+
6+
permissions:
7+
pull-requests: write
8+
contents: write
9+
10+
on: workflow_dispatch
11+
12+
jobs:
13+
# Create a PR with the new versions and changelog, preparing the next release. When merged to main,
14+
# the publish-release.yaml workflow will automatically publish any Rust package versions.
15+
create-release-pr:
16+
name: Create release PR
17+
runs-on: ubuntu-latest
18+
permissions:
19+
contents: write
20+
pull-requests: write
21+
concurrency: # Don't run overlapping instances of this workflow
22+
group: release-plz-${{ github.ref }}
23+
cancel-in-progress: false
24+
steps:
25+
- name: Checkout repository
26+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
27+
with:
28+
fetch-depth: 0
29+
- name: Install Rust toolchain
30+
uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
31+
- name: Run release-plz
32+
uses: release-plz/action@b8d6b54b02889ff2ae2bb82e8b57c3a8fc1683a5 # v0.5.139
33+
with:
34+
command: release-pr
35+
env:
36+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

‎.github/workflows/publish-crates.yaml‎

Lines changed: 0 additions & 92 deletions
This file was deleted.
Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# This workflow only publishes releases for PRs created by create-release-pr.yaml
2+
#
3+
# Crates are published with crates.io Trusted Publishing: release-plz exchanges this workflow's
4+
# GitHub OIDC identity for a short-lived crates.io token, so there is no `CARGO_REGISTRY_TOKEN`
5+
# secret. Each crate's trusted publisher on crates.io must be configured with workflow
6+
# `publish-release.yaml` and environment `crates-io`.
7+
#
8+
# See https://github.com/github/rust-gems/blob/main/CONTRIBUTING.md#releasing-a-crate for more details.
9+
name: Release any unpublished crates
10+
11+
permissions:
12+
contents: write
13+
14+
on:
15+
push:
16+
branches:
17+
- main
18+
19+
jobs:
20+
# Release any unpublished packages
21+
release-plz-release:
22+
name: Release-plz release
23+
runs-on: ubuntu-latest
24+
# Gate releases behind an environment so protection rules apply, and so the OIDC claim
25+
# matches the trusted publisher configured on crates.io.
26+
environment: crates-io
27+
permissions:
28+
contents: write
29+
id-token: write # Required to mint the crates.io OIDC token.
30+
concurrency: # Serialize releases so runs don't race to publish the same version or tag
31+
group: release-plz-release-${{ github.ref }}
32+
cancel-in-progress: false
33+
steps:
34+
- name: Checkout repository
35+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
36+
with:
37+
fetch-depth: 0
38+
- name: Install Rust toolchain
39+
uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
40+
- name: Run release-plz
41+
uses: release-plz/action@b8d6b54b02889ff2ae2bb82e8b57c3a8fc1683a5 # v0.5.139
42+
with:
43+
command: release
44+
env:
45+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

‎CONTRIBUTING.md‎

Lines changed: 17 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -31,21 +31,26 @@ Here are a few things you can do that will increase the likelihood of your pull
3131

3232
## Releasing a crate
3333

34-
Crates are published to [crates.io](https://crates.io) with
35-
[Trusted Publishing](https://crates.io/docs/trusted-publishing), so there is no long-lived API
36-
token stored in this repository. The `Publish crates` workflow exchanges its GitHub OIDC identity
37-
for a token that is revoked when the run ends.
38-
39-
1. Bump `version` in the crate's `Cargo.toml` and merge that change to `main`.
40-
2. Run the [`Publish crates`](../../actions/workflows/publish-crates.yaml) workflow via
41-
*Run workflow*, pick the crate, and optionally tick *dry-run* first to package and verify it
42-
without uploading. If a newly added crate isn't in the dropdown yet, type its name into
43-
*crate_name_override* instead — and add it to the dropdown in `publish-crates.yaml` while
44-
you're there.
34+
Releases are managed with [release-plz](https://release-plz.dev). Crates are published to
35+
[crates.io](https://crates.io) with [Trusted Publishing](https://crates.io/docs/trusted-publishing),
36+
so there is no long-lived API token stored in this repository. release-plz exchanges the
37+
workflow's GitHub OIDC identity for a token that is revoked when the run ends.
38+
39+
1. Run the [`Create release PR`](../../actions/workflows/create-release-pr.yaml) workflow via
40+
*Run workflow*. This uses `release-plz` to open a PR that bumps the versions and updates the
41+
changelogs of any crates that changed since their last release.
42+
2. Adjust the generated changelog(s) and version number(s) as necessary.
43+
3. Get PR approval.
44+
4. Merge the PR. The [`publish-release.yaml`](../../actions/workflows/publish-release.yaml)
45+
workflow will automatically publish a new release of any crate whose version has changed,
46+
and create the matching git tag and GitHub release.
47+
48+
Development-only crates (benchmarks and tests) are excluded from releases in
49+
[`release-plz.toml`](release-plz.toml). Add new ones there too.
4550

4651
A crate has to be published manually once before crates.io will let you configure a trusted
4752
publisher for it. Configure it at `https://crates.io/crates/<crate>/settings/trusted-publishing`
48-
with repository `github/rust-gems`, workflow `publish-crates.yaml`, and environment `crates-io`.
53+
with repository `github/rust-gems`, workflow `publish-release.yaml`, and environment `crates-io`.
4954
The environment name must match the workflow's `environment:` exactly or the token exchange fails.
5055

5156
## Resources

‎release-plz.toml‎

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,23 @@
1+
[workspace]
2+
release_always = false
3+
4+
# Development-only crates that are never published.
5+
[[package]]
6+
name = "bpe-benchmarks"
7+
release = false
8+
9+
[[package]]
10+
name = "bpe-tests"
11+
release = false
12+
13+
[[package]]
14+
name = "casefold-benchmarks"
15+
release = false
16+
17+
[[package]]
18+
name = "consistent-choose-k-benchmarks"
19+
release = false
20+
21+
[[package]]
22+
name = "hash-sorted-map-benchmarks"
23+
release = false

0 commit comments

Comments
 (0)