diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 84f48100a..a6c2d3d03 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -6,6 +6,7 @@ on: pull_request: branches: - main + workflow_call: concurrency: group: ${{ github.workflow }}-${{ github.ref }} diff --git a/.github/workflows/pre-release.yml b/.github/workflows/pre-release.yml index 9cbd3fd21..55e946062 100644 --- a/.github/workflows/pre-release.yml +++ b/.github/workflows/pre-release.yml @@ -1,58 +1,62 @@ name: pre-release -# creates/updates a pre-release with the .vsix +# Update the development release only after the main workflow has passed. on: - push: - branches: ["main"] + workflow_run: + workflows: + - main + branches: + - main + types: + - completed -env: - FILE_OUT: r-latest.vsix - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} +concurrency: + group: pre-release + cancel-in-progress: true +permissions: + actions: read + contents: write jobs: - build: - runs-on: ubuntu-latest - env: - VSIX_FILE: vscode-R.vsix - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 - with: - node-version: 24 - cache: 'pnpm' - - run: pnpm install --frozen-lockfile - - name: Package extension - run: pnpm exec vsce package --no-dependencies -o $VSIX_FILE - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: "${{ env.VSIX_FILE }}" - path: "${{ env.VSIX_FILE }}" - pre-release: name: Pre-Release - needs: build + if: >- + github.event.workflow_run.conclusion == 'success' && + github.event.workflow_run.event == 'push' && + github.event.workflow_run.head_repository.full_name == github.repository runs-on: ubuntu-latest env: - VSIX_FILE: vscode-R.vsix - permissions: - contents: write + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + ref: ${{ github.event.workflow_run.head_sha }} - name: Download artifacts uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: - name: "${{ env.VSIX_FILE }}" - path: "artifacts/" + name: vscode-R.vsix + path: artifacts/ + run-id: ${{ github.event.workflow_run.id }} + github-token: ${{ secrets.GITHUB_TOKEN }} + - name: Check main still points to the verified revision + id: current + env: + VERIFIED_SHA: ${{ github.event.workflow_run.head_sha }} + run: | + MAIN_SHA=$(git ls-remote origin refs/heads/main | cut -f1) + test -n "$MAIN_SHA" + if [ "$MAIN_SHA" = "$VERIFIED_SHA" ]; then + echo "publish=true" >> "$GITHUB_OUTPUT" + fi - name: Create or update pre-release + if: steps.current.outputs.publish == 'true' run: | gh release delete latest --yes || true - git tag -d latest || true - git tag latest + git tag -f latest git push origin latest --force - gh release create latest artifacts/${{ env.VSIX_FILE }} \ + gh release create latest artifacts/vscode-R.vsix \ --title "Development Build" \ - --notes "Contains the vsix-file from the latest push to main." \ + --notes "Contains the VSIX from the latest verified push to main." \ --prerelease diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d269f84c4..2fe41f45f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,35 +5,19 @@ name: release on: push: - tags: ["v*"] + tags: + - "v*" env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} jobs: - build: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 - - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 - with: - node-version: 24 - cache: 'pnpm' - - run: pnpm install --frozen-lockfile - - name: Package extension - id: package - run: | - pnpm exec vsce package --no-dependencies - echo "VSIX_FILE=$(ls *.vsix)" >> $GITHUB_OUTPUT - - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: vsix-artifact - path: "*.vsix" + verify: + uses: ./.github/workflows/main.yml release: name: Release - needs: build + needs: verify runs-on: ubuntu-latest permissions: contents: write @@ -43,12 +27,13 @@ jobs: - name: Download artifacts uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: - name: vsix-artifact + name: vscode-R.vsix path: artifacts/ - name: Create release run: | VERSION=${GITHUB_REF#refs/tags/v} - gh release create v$VERSION artifacts/*.vsix \ + mv artifacts/vscode-R.vsix "artifacts/r-$VERSION.vsix" + gh release create "v$VERSION" "artifacts/r-$VERSION.vsix" \ --title "v$VERSION" \ --notes "Release v$VERSION" \ --generate-notes @@ -57,7 +42,9 @@ jobs: name: Publish timeout-minutes: 30 runs-on: ubuntu-latest - needs: build + needs: + - verify + - release steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - uses: pnpm/action-setup@ea17c68df8912ef543352723c149a84f56e3d413 # v6.1.0 @@ -69,7 +56,7 @@ jobs: - name: Download artifacts uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: - name: vsix-artifact + name: vscode-R.vsix path: artifacts/ - name: Publish to Visual Studio Marketplace run: pnpm exec vsce publish -p ${{ secrets.VSCE_TOKEN }} --packagePath artifacts/*.vsix diff --git a/README.md b/README.md index ec0923c78..7b3a65d9a 100644 --- a/README.md +++ b/README.md @@ -41,7 +41,7 @@ for other changes and upgrade notes. Install the development version The [`latest`](https://github.com/REditorSupport/vscode-R/releases/tag/latest) - pre-release is rebuilt from every push to `main`. Download and install it: + pre-release is updated after successful verification of a push to `main`. Download and install it: ```sh curl -fsSL -o vscode-R.vsix https://github.com/REditorSupport/vscode-R/releases/download/latest/vscode-R.vsix