Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions .github/workflows/create-release-pr.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# Launch this workflow with the "Run workflow" button in the Actions tab of the repository.
#
# See https://github.com/github/rust-gems/blob/main/CONTRIBUTING.md#releasing-a-crate for more details.
name: Create release PR

permissions:
pull-requests: write
contents: write

on: workflow_dispatch

jobs:
# Create a PR with the new versions and changelog, preparing the next release. When merged to main,
# the publish-release.yaml workflow will automatically publish any Rust package versions.
create-release-pr:
name: Create release PR
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
concurrency: # Don't run overlapping instances of this workflow
group: release-plz-${{ github.ref }}
cancel-in-progress: false
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- name: Run release-plz
uses: release-plz/action@b8d6b54b02889ff2ae2bb82e8b57c3a8fc1683a5 # v0.5.139
with:
command: release-pr
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Comment thread
bb8gh marked this conversation as resolved.
92 changes: 0 additions & 92 deletions .github/workflows/publish-crates.yaml

This file was deleted.

45 changes: 45 additions & 0 deletions .github/workflows/publish-release.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# This workflow only publishes releases for PRs created by create-release-pr.yaml
#
# Crates are published with crates.io Trusted Publishing: release-plz exchanges this workflow's
# GitHub OIDC identity for a short-lived crates.io token, so there is no `CARGO_REGISTRY_TOKEN`
# secret. Each crate's trusted publisher on crates.io must be configured with workflow
# `publish-release.yaml` and environment `crates-io`.
#
# See https://github.com/github/rust-gems/blob/main/CONTRIBUTING.md#releasing-a-crate for more details.
name: Release any unpublished crates

permissions:
contents: write

on:
push:
branches:
- main

jobs:
# Release any unpublished packages
release-plz-release:
name: Release-plz release
runs-on: ubuntu-latest
Comment thread
bb8gh marked this conversation as resolved.
# Gate releases behind an environment so protection rules apply, and so the OIDC claim
# matches the trusted publisher configured on crates.io.
environment: crates-io
permissions:
contents: write
id-token: write # Required to mint the crates.io OIDC token.
concurrency: # Serialize releases so runs don't race to publish the same version or tag
group: release-plz-release-${{ github.ref }}
cancel-in-progress: false
steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
- name: Run release-plz
uses: release-plz/action@b8d6b54b02889ff2ae2bb82e8b57c3a8fc1683a5 # v0.5.139
with:
command: release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
29 changes: 17 additions & 12 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,21 +31,26 @@ Here are a few things you can do that will increase the likelihood of your pull

## Releasing a crate

Crates are published to [crates.io](https://crates.io) with
[Trusted Publishing](https://crates.io/docs/trusted-publishing), so there is no long-lived API
token stored in this repository. The `Publish crates` workflow exchanges its GitHub OIDC identity
for a token that is revoked when the run ends.

1. Bump `version` in the crate's `Cargo.toml` and merge that change to `main`.
2. Run the [`Publish crates`](../../actions/workflows/publish-crates.yaml) workflow via
*Run workflow*, pick the crate, and optionally tick *dry-run* first to package and verify it
without uploading. If a newly added crate isn't in the dropdown yet, type its name into
*crate_name_override* instead — and add it to the dropdown in `publish-crates.yaml` while
you're there.
Releases are managed with [release-plz](https://release-plz.dev). Crates are published to
[crates.io](https://crates.io) with [Trusted Publishing](https://crates.io/docs/trusted-publishing),
so there is no long-lived API token stored in this repository. release-plz exchanges the
workflow's GitHub OIDC identity for a token that is revoked when the run ends.

1. Run the [`Create release PR`](../../actions/workflows/create-release-pr.yaml) workflow via
*Run workflow*. This uses `release-plz` to open a PR that bumps the versions and updates the
changelogs of any crates that changed since their last release.
2. Adjust the generated changelog(s) and version number(s) as necessary.
3. Get PR approval.
4. Merge the PR. The [`publish-release.yaml`](../../actions/workflows/publish-release.yaml)
workflow will automatically publish a new release of any crate whose version has changed,
and create the matching git tag and GitHub release.

Development-only crates (benchmarks and tests) are excluded from releases in
[`release-plz.toml`](release-plz.toml). Add new ones there too.

A crate has to be published manually once before crates.io will let you configure a trusted
publisher for it. Configure it at `https://crates.io/crates/<crate>/settings/trusted-publishing`
with repository `github/rust-gems`, workflow `publish-crates.yaml`, and environment `crates-io`.
with repository `github/rust-gems`, workflow `publish-release.yaml`, and environment `crates-io`.
The environment name must match the workflow's `environment:` exactly or the token exchange fails.

## Resources
Expand Down
23 changes: 23 additions & 0 deletions release-plz.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
[workspace]
release_always = false

# Development-only crates that are never published.
[[package]]
name = "bpe-benchmarks"
release = false

[[package]]
name = "bpe-tests"
release = false

[[package]]
name = "casefold-benchmarks"
release = false

[[package]]
name = "consistent-choose-k-benchmarks"
release = false

[[package]]
name = "hash-sorted-map-benchmarks"
release = false
Loading