Skip to content

Commit e51c1a2

Browse files
Add trusted publishing
1 parent 8b5e942 commit e51c1a2

File tree

2 files changed

+39
-0
lines changed

2 files changed

+39
-0
lines changed

.github/workflows/cd-test.yml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
name: Continuous delivery - test
2+
3+
on:
4+
pull_request:
5+
# opened, reopenened, synchronize are the default types for pull_request
6+
# labeled, unlabeled ensure this check is also run if a label is added or removed
7+
types: [opened, reopened, synchronize, labeled, unlabeled]
8+
9+
jobs:
10+
test-publish:
11+
runs-on: ubuntu-latest
12+
if: ${{ !contains(github.event.pull_request.labels.*.name, 'skip-publish-check') }}
13+
steps:
14+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
15+
with:
16+
submodules: true
17+
- run: cargo publish --dry-run

.github/workflows/cd.yml

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
name: Continuous delivery - crates.io
2+
3+
on:
4+
release:
5+
types: [published]
6+
workflow_dispatch:
7+
8+
jobs:
9+
publish:
10+
runs-on: ubuntu-latest
11+
environment: crates.io
12+
permissions:
13+
id-token: write
14+
steps:
15+
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
16+
with:
17+
submodules: true
18+
- uses: rust-lang/crates-io-auth-action@b7e9a28eded4986ec6b1fa40eeee8f8f165559ec # v1.0.3
19+
id: auth
20+
- run: cargo publish
21+
env:
22+
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}

0 commit comments

Comments
 (0)