Skip to content

Release

Release #105

Workflow file for this run

name: Release
on:
workflow_dispatch:
inputs:
tag:
description: 'Release tag (e.g., v0.1.0)'
required: false
channel:
description: Release channel
type: choice
options: [stable, prerelease]
default: stable
prerelease_version:
description: 'Explicit v5 candidate version (5.0.0-next.N)'
type: string
required: false
source_revision:
description: 'Full approved next commit SHA for the candidate'
type: string
required: false
publish_prerelease:
description: 'Request publication after exact-head CI and environment review (default prepares artifacts only)'
type: boolean
default: false
push:
tags:
- "v*"
- "!v*-*"
- '!v*\+*'
permissions:
contents: read
jobs:
prerelease:
if: ${{ github.event_name == 'workflow_dispatch' && inputs.channel == 'prerelease' }}
uses: ./.github/workflows/prerelease.yml
permissions:
contents: write
actions: read
checks: read
statuses: read
deployments: read
with:
version: ${{ inputs.prerelease_version }}
source_revision: ${{ inputs.source_revision }}
publish: ${{ inputs.publish_prerelease }}
create-release:
if: ${{ github.event_name == 'push' || inputs.channel == 'stable' }}
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
contents: write
outputs:
version: ${{ steps.version.outputs.version }}
tag: ${{ steps.version.outputs.tag }}
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Resolve version
id: version
env:
RELEASE_CHANNEL: ${{ inputs.channel || 'stable' }}
RELEASE_TAG_INPUT: ${{ inputs.tag }}
run: bun scripts/prerelease-plan.ts stable
- name: Create GitHub release
uses: softprops/action-gh-release@v2
with:
tag_name: "${{ steps.version.outputs.tag }}"
generate_release_notes: true
build:
needs: create-release
runs-on: ${{ matrix.os }}
permissions:
contents: write
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
upload_install: true
skip_tests: true
- os: macos-15
upload_install: false
skip_tests: true
- os: blacksmith-6vcpu-macos-15
upload_install: false
skip_tests: true
- os: macos-15-intel
upload_install: false
skip_tests: true
steps:
- name: Checkout
uses: actions/checkout@v4
with:
ref: ${{ needs.create-release.outputs.tag }}
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Install dependencies
run: bun install
- name: Build release artifacts
if: ${{ !matrix.skip_tests }}
env:
RELEASE_VERSION: ${{ needs.create-release.outputs.version }}
run: bun run build:release "--version=$RELEASE_VERSION"
- name: Build release artifacts (skip tests)
if: ${{ matrix.skip_tests }}
env:
RELEASE_VERSION: ${{ needs.create-release.outputs.version }}
run: bun run build:release "--version=$RELEASE_VERSION" --skip-tests
- name: Upload tarball
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.create-release.outputs.tag }}
RELEASE_VERSION: ${{ needs.create-release.outputs.version }}
run: |
set -euo pipefail
shopt -s nullglob
files=(dist/release/hack-"${RELEASE_VERSION}"-*.tar.gz)
if [ "${#files[@]}" -eq 0 ]; then
echo "No tarballs matched dist/release/hack-${RELEASE_VERSION}-*.tar.gz"
exit 1
fi
for file in "${files[@]}"; do
for attempt in 1 2 3; do
if gh release upload "${RELEASE_TAG}" "${file}" --clobber; then
echo "Uploaded ${file}"
break
fi
if [ "${attempt}" -eq 3 ]; then
echo "Failed uploading ${file} after ${attempt} attempts"
exit 1
fi
sleep $((attempt * 5))
done
done
- name: Upload install scripts
if: ${{ matrix.upload_install }}
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.create-release.outputs.tag }}
RELEASE_VERSION: ${{ needs.create-release.outputs.version }}
run: |
set -euo pipefail
files=(
"dist/release/hack-${RELEASE_VERSION}-install.sh"
"dist/release/hack-install.sh"
"dist/release/hack-${RELEASE_VERSION}-codex-install.sh"
"dist/release/hack-codex-install.sh"
)
for file in "${files[@]}"; do
if [ ! -f "${file}" ]; then
echo "Missing expected install script: ${file}"
exit 1
fi
for attempt in 1 2 3; do
if gh release upload "${RELEASE_TAG}" "${file}" --clobber; then
echo "Uploaded ${file}"
break
fi
if [ "${attempt}" -eq 3 ]; then
echo "Failed uploading ${file} after ${attempt} attempts"
exit 1
fi
sleep $((attempt * 5))
done
done
update-homebrew-tap:
if: ${{ github.event_name == 'push' || inputs.channel == 'stable' }}
needs: [create-release, build]
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
contents: read
steps:
- name: Require tap push token
env:
TAP_TOKEN: ${{ secrets.RELEASE_PAT }}
run: |
if [ -z "$TAP_TOKEN" ]; then
echo "Missing secret RELEASE_PAT"
exit 1
fi
- name: Checkout hack
uses: actions/checkout@v4
- name: Checkout tap repo
uses: actions/checkout@v4
with:
repository: hack-dance/homebrew-tap
token: ${{ secrets.RELEASE_PAT }}
ref: main
path: homebrew-tap
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Render formula
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.create-release.outputs.tag }}
RELEASE_VERSION: ${{ needs.create-release.outputs.version }}
run: |
bun run scripts/update-homebrew-tap.ts \
--tag="$RELEASE_TAG" \
--version="$RELEASE_VERSION" \
--tap-dir=homebrew-tap
- name: Commit and push tap update
working-directory: homebrew-tap
env:
RELEASE_TAG: ${{ needs.create-release.outputs.tag }}
run: |
set -euo pipefail
git add Formula/hack.rb
if git diff --cached --quiet; then
echo "No Homebrew tap changes to push."
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git commit -m "build(hack): update formula to $RELEASE_TAG"
git push origin HEAD:main