Files
ngit-grasp/.ngit/act/workflows/release.yaml
T
DanConwayDev 6162dd41b7 ci(release): rely on signed asset checksums
Motivation: NIP-82 asset events already bind release files to their SHA-256, while publishing a second platform-agnostic SHA256SUMS asset is redundant and rejected by catalogs that require an f tag.

Approach: package and upload only the static archive, document the signed-checksum model in the manifest, and derive the release event timestamp from Git creatordate so annotated and lightweight tags both produce stable dates.

Correctness: the archive remains deterministic and actions/upload-artifact retains the exact distributable; ngit signs its hash, size, MIME type, filename, URL, and Linux platform in the kind-3063 event.

Excluded: the already-published 3.0.1 release is not replaced, and truly multi-platform release layouts remain unchanged.

Validation: actionlint accepts the workflow; Git creatordate reproduces the v3.0.0 and v3.0.1 tag timestamps; ngit parses the manifest and reaches the expected publisher-author guard without signing or uploading.
2026-09-03 12:42:22 +00:00

93 lines
3.3 KiB
YAML

on:
push:
tags: ["v*"]
name: release assets
jobs:
linux-x86_64:
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- uses: actions/checkout@v5
- uses: danconwaydev/setup-ngit@v3
- uses: cachix/install-nix-action@v31
with:
nix_path: nixpkgs=channel:nixos-unstable
- name: Restore Nix store cache
continue-on-error: true
uses: nix-community/cache-nix-action@v7
with:
primary-key: release-nix-${{ runner.os }}-${{ hashFiles('**/*.nix', 'flake.lock') }}
restore-prefixes-first-match: release-nix-${{ runner.os }}-
# cache-nix-action requires a token even with purge disabled;
# github.token is empty under ngit-ci, so any non-empty value works.
token: unused
- name: Build static binary
run: nix build .#static --out-link result-static
- name: Package release asset
shell: bash
run: |
set -euo pipefail
version="${GITHUB_REF_NAME#v}"
if [[ -z "$version" || "$version" == *[!A-Za-z0-9._+-]* ]]; then
echo "unsupported release version from tag: $GITHUB_REF_NAME" >&2
exit 1
fi
package_version="$(nix eval --raw .#static.version)"
if [[ "$version" != "$package_version" ]]; then
echo "tag version $version does not match package version $package_version" >&2
exit 1
fi
target="x86_64-unknown-linux-musl"
archive="ngit-grasp-${version}-${target}"
source_date_epoch="$(git show -s --format=%ct "$GITHUB_SHA")"
install -Dm755 result-static/bin/ngit-grasp \
"release-stage/${archive}/ngit-grasp"
install -Dm644 LICENSE "release-stage/${archive}/LICENSE"
mkdir -p dist
tar --sort=name --mtime="@${source_date_epoch}" \
--owner=0 --group=0 --numeric-owner -C release-stage \
-czf "dist/${archive}.tar.gz" "$archive"
- name: Upload release assets
uses: actions/upload-artifact@v4
with:
name: ngit-grasp-release-assets
path: dist/*.tar.gz
if-no-files-found: error
- name: Publish NIP-82 release
shell: bash
env:
NGIT_PUBLISHER_NBUNKSEC: ${{ secrets.NGIT_PUBLISHER_NBUNKSEC }}
run: |
set -euo pipefail
: "${NGIT_PUBLISHER_NBUNKSEC:?Set the NGIT_PUBLISHER_NBUNKSEC repository secret}"
umask 077
signer_file="$RUNNER_TEMP/ngit-release-nbunksec"
trap 'rm -f "$signer_file"' EXIT
printf '%s\n' "$NGIT_PUBLISHER_NBUNKSEC" > "$signer_file"
version="${GITHUB_REF_NAME#v}"
released_at="$(git for-each-ref \
--format='%(creatordate:unix)' \
"refs/tags/$GITHUB_REF_NAME")"
if [[ ! "$released_at" =~ ^[0-9]+$ ]]; then
echo "could not derive release date from tag $GITHUB_REF_NAME" >&2
exit 1
fi
ngit release publish "$version" \
--repo nostr://npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/relay.ngit.dev/ngit-grasp \
--manifest .ngit/release.yaml \
--tag "$GITHUB_REF_NAME" \
--released-at "$released_at" \
--nbunksec-file "$signer_file" \
--defaults \
--repo-relay-only \
--json