-
Notifications
You must be signed in to change notification settings - Fork 97
178 lines (154 loc) · 5.39 KB
/
Copy pathrelease.yml
File metadata and controls
178 lines (154 loc) · 5.39 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
name: Release
on:
push:
tags:
- 'v*.*.*'
permissions:
contents: write
jobs:
build:
name: Build ${{ matrix.target }}
runs-on: ${{ matrix.os }}
strategy:
matrix:
include:
# Linux x86_64
- os: ubuntu-latest
target: x86_64-unknown-linux-gnu
bun_target: bun-linux-x64
artifact_name: capa
asset_name: capa-x86_64-unknown-linux-gnu
# Linux aarch64
- os: ubuntu-latest
target: aarch64-unknown-linux-gnu
bun_target: bun-linux-arm64
artifact_name: capa
asset_name: capa-aarch64-unknown-linux-gnu
# macOS x86_64 (Intel) — cross-compiled via --target on Apple Silicon runners
- os: macos-latest
target: x86_64-apple-darwin
bun_target: bun-darwin-x64
artifact_name: capa
asset_name: capa-x86_64-apple-darwin
# macOS aarch64 (Apple Silicon)
- os: macos-latest
target: aarch64-apple-darwin
bun_target: bun-darwin-arm64
artifact_name: capa
asset_name: capa-aarch64-apple-darwin
# Windows x86_64
- os: windows-latest
target: x86_64-pc-windows-msvc
bun_target: bun-windows-x64
artifact_name: capa.exe
asset_name: capa-x86_64-pc-windows-msvc.exe
# Windows ARM64 falls back to the x64 binary via install.ps1
# (`bun build --compile --target=bun-windows-arm64` is unstable as of
# Bun 1.3.x — runtime download fails to extract). Windows on ARM64
# runs x64 binaries fine under Prism emulation.
#
# Windows x86 (32-bit) is also unsupported because there is no
# `bun-windows-i686` build target.
steps:
- name: Checkout code
uses: actions/checkout@v7
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: "1.3.14"
# Stamp the version before `bun install`, which rewrites the lockfile.
# RELEASE_REF can be set by a branch workflow that checks out an existing
# tag. GITHUB_REF cannot: Actions ignores overrides of default GITHUB_* variables.
- name: Generate version from tag
run: bun run scripts/generate-version.ts
env:
RELEASE_REF: ${{ github.ref }}
- name: Update install scripts version
run: bun run scripts/update-install-scripts.ts
env:
RELEASE_REF: ${{ github.ref }}
- name: Install dependencies
run: bun install
- name: Build web UI
run: bun run build:web
- name: Build
env:
BUN_TARGET: ${{ matrix.bun_target }}
run: |
if [ "$RUNNER_OS" == "Windows" ]; then
bun build src/cli/index.ts --compile --target=$BUN_TARGET --windows-icon=./logo.ico --outfile dist/capa
else
bun build src/cli/index.ts --compile --target=$BUN_TARGET --outfile dist/capa --icon logo.ico
fi
shell: bash
- name: Rename artifact
shell: bash
run: |
cd dist
if [ -f "capa.exe" ]; then
mv capa.exe ../capa-${{ matrix.target }}.exe
else
mv capa ../capa-${{ matrix.target }}
fi
- name: Generate SHA256 checksum
shell: bash
run: |
if [ "$RUNNER_OS" == "Windows" ]; then
ARTIFACT="capa-${{ matrix.target }}.exe"
HASH=$(powershell -Command "(Get-FileHash '$ARTIFACT' -Algorithm SHA256).Hash.ToLower()")
echo "$HASH $ARTIFACT" > "${ARTIFACT}.sha256"
elif command -v sha256sum >/dev/null 2>&1; then
ARTIFACT="capa-${{ matrix.target }}"
sha256sum "$ARTIFACT" > "${ARTIFACT}.sha256"
else
ARTIFACT="capa-${{ matrix.target }}"
shasum -a 256 "$ARTIFACT" > "${ARTIFACT}.sha256"
fi
- name: Upload artifact
uses: actions/upload-artifact@v7
with:
name: ${{ matrix.asset_name }}
path: capa-${{ matrix.target }}*
release:
name: Create Release
needs: build
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write
attestations: write
steps:
- name: Checkout code
uses: actions/checkout@v7
- name: Download all artifacts
uses: actions/download-artifact@v8
with:
path: artifacts
- name: Display structure of downloaded files
run: ls -R artifacts
- name: Generate SHA256SUMS.txt
run: |
find artifacts -name '*.sha256' -type f -exec cat {} \; | LC_ALL=C sort -k2 > SHA256SUMS.txt
sha256sum install.sh install.ps1 >> SHA256SUMS.txt
LC_ALL=C sort -k2 -o SHA256SUMS.txt SHA256SUMS.txt
cat SHA256SUMS.txt
- name: Attest build provenance
uses: actions/attest-build-provenance@v4
with:
subject-path: |
SHA256SUMS.txt
install.sh
install.ps1
- name: Create Release
uses: softprops/action-gh-release@v3
with:
files: |
artifacts/**/*
SHA256SUMS.txt
install.sh
install.ps1
draft: false
prerelease: false
generate_release_notes: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}