mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Crates.io publication is a manual release step even though Nostr CI already validates tagged commits. Publish after the existing lint, formatting and test steps succeed, using a repository-scoped CARGO_REGISTRY_TOKEN secret only in the publication step. Require a push event on a v-prefixed tag and an exact manifest-version match. Use Cargo package verification and --locked against the explicit crates-io registry. Only ngit-grasp is selected; grasp-audit remains unpublished. This assumes the coordinator has the scoped token configured and the tagged commit contains this workflow. It does not change archive/NIP-82 publication, stable promotion, documentation sync or registry versions; no live crate was uploaded during development. Validated workflow syntax with actionlint, matching/mismatched tag and missing-secret cases with an intercepted publish command, Cargo packaging without upload, cargo fmt --all -- --check, and git diff --cached --check.
22 lines
1.1 KiB
Markdown
22 lines
1.1 KiB
Markdown
# Publish ngit-grasp to crates.io
|
|
|
|
Nostr CI publishes `ngit-grasp` after the existing formatting, lint and test
|
|
steps pass for a `v*` tag push. The tag must exactly match `v` followed by the
|
|
package version in `Cargo.toml`, including any prerelease suffix. Branch pushes
|
|
and pull requests do not publish crates. The unpublished `grasp-audit` workspace
|
|
member is not selected for publication.
|
|
|
|
Configure the repository's `CARGO_REGISTRY_TOKEN` secret in ngit-ci with a
|
|
crates.io token scoped to publishing `ngit-grasp`. The token is supplied only
|
|
to the publication step; Cargo does not write a login credential file.
|
|
|
|
The workflow runs `cargo publish --locked --registry crates-io --package
|
|
ngit-grasp`, including Cargo's package verification. A missing token or an
|
|
already-published version fails the step; the workflow does not overwrite or
|
|
automatically bump releases.
|
|
|
|
The workflow must be included in the tagged commit. Adding it does not
|
|
backfill existing tags, and crate publication is independent of the existing
|
|
archive, NIP-82 and container publication jobs. It requires no GitHub registry
|
|
authentication.
|