1
0
Fork 0
mirror of https://codeberg.org/icewind/haze.git synced 2026-10-01 16:54:08 +02:00
haze/.forgejo/workflows/release.yaml
2026-09-08 01:54:58 +02:00

47 lines
1.4 KiB
YAML

name: Release
on:
release:
types: [published]
enable-openid-connect: true
jobs:
publish:
runs-on: nix
steps:
- name: fetch jwt
id: jwt
env:
AUD: u:168061:141d46eb-9b70-4c27-9d49-db5b30b6da28
run: |
jwt=$( \
curl --fail \
-H "Authorization: bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" \
"$ACTIONS_ID_TOKEN_REQUEST_URL&audience=$AUD" \
| jq -r ".value" \
)
# ::add-mask:: tells Forgejo Runner that the JWT
# is a secret which should be masked in the logs.
echo "::add-mask::$jwt"
echo "jwt=$jwt" >> $FORGEJO_OUTPUT
- uses: actions/checkout@v4
- uses: https://codeberg.org/icewind/attic-action@v1
with:
name: link
instance: https://cache.icewind.link
- name: Collect assets
run: |
mkdir assets
for asset in x86_64-unknown-linux-musl aarch64-unknown-linux-musl; do
nix build .#$asset
cp result/bin/haze assets/$asset
done
- name: Create release
# https://code.forgejo.org/actions/forgejo-release/issues/121
uses: https://code.forgejo.org/astrelion/forgejo-release@b523d26318949212b87ef4a5a19a5ee9218d0c20
with:
direction: upload
release-dir: assets
only-assets: true
token: "${{ steps.jwt.outputs.jwt }}"