name: Release on: push: tags: - "*" workflow_dispatch: permissions: contents: read jobs: release: name: Release Binaries if: github.ref_type == 'tag' runs-on: ubuntu-latest timeout-minutes: 60 environment: publish permissions: contents: read packages: write steps: - uses: actions/checkout@v6 with: fetch-depth: 0 - uses: actions/setup-go@v6 with: go-version-file: go.mod cache: true - uses: docker/setup-qemu-action@v4 - uses: docker/setup-buildx-action@v4 - uses: docker/login-action@v4 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ github.token }} - name: Create release app token for this repo id: app-token uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 with: app-id: ${{ secrets.RELEASE_APP_ID }} private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} permission-contents: write - name: Create release app token for homebrew-tools id: tap-token uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 with: app-id: ${{ secrets.RELEASE_APP_ID }} private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} owner: openai repositories: homebrew-tools permission-contents: write permission-pull-requests: write - name: Release uses: goreleaser/goreleaser-action@v7 with: distribution: goreleaser-pro version: "~> v2" args: release --clean env: GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} HOMEBREW_TAP_GITHUB_TOKEN: ${{ steps.tap-token.outputs.token }} MACOS_NOTARY_ISSUER_ID: ${{ secrets.MACOS_NOTARY_ISSUER_ID }} MACOS_NOTARY_KEY: ${{ secrets.MACOS_NOTARY_KEY }} MACOS_NOTARY_KEY_ID: ${{ secrets.MACOS_NOTARY_KEY_ID }} MACOS_SIGN_P12: ${{ secrets.MACOS_SIGN_P12 }} MACOS_SIGN_PASSWORD: ${{ secrets.MACOS_SIGN_PASSWORD }} snapshot: name: Release Binaries (Dry Run) if: github.event_name == 'workflow_dispatch' runs-on: ubuntu-latest timeout-minutes: 60 steps: - uses: actions/checkout@v6 with: fetch-depth: 0 - uses: actions/setup-go@v6 with: go-version-file: go.mod cache: true - name: Release dry run uses: goreleaser/goreleaser-action@v7 with: distribution: goreleaser-pro version: "~> v2" args: release --skip=publish --snapshot --clean - name: Upload dry-run artifacts uses: actions/upload-artifact@v6 with: name: orchard-snapshot path: dist/**