name: Release on: push: tags: - "*" workflow_dispatch: permissions: contents: read jobs: release: name: ${{ github.ref_type == 'tag' && 'Release' || 'Release (Dry Run)' }} runs-on: ghcr.io/cirruslabs/macos-runner:sequoia timeout-minutes: 60 environment: publish steps: - uses: actions/checkout@v6 with: fetch-depth: 0 persist-credentials: false - uses: actions/setup-go@v6 with: go-version-file: go.mod cache: true - name: Create release app token for this repository if: github.ref_type == 'tag' id: release-token uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 with: app-id: ${{ secrets.RELEASE_APP_ID }} private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} permission-contents: write - name: Create release app token for homebrew-tools if: github.ref_type == 'tag' id: tap-token uses: actions/create-github-app-token@1b10c78c7865c340bc4f6099eb2f838309f1e8c3 # v3.1.1 with: app-id: ${{ secrets.RELEASE_APP_ID }} private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} owner: openai repositories: homebrew-tools permission-contents: write permission-pull-requests: write - name: Release if: github.ref_type == 'tag' uses: goreleaser/goreleaser-action@v7 with: distribution: goreleaser-pro version: "~> v2" args: release --clean env: GITHUB_TOKEN: ${{ steps.release-token.outputs.token }} GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} HOMEBREW_TAP_GITHUB_TOKEN: ${{ steps.tap-token.outputs.token }} - name: Release dry run if: github.ref_type != 'tag' uses: goreleaser/goreleaser-action@v7 with: distribution: goreleaser-pro version: "~> v2" args: release --skip=publish --snapshot --clean env: GITHUB_TOKEN: ${{ github.token }} GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} - name: Upload dry-run artifacts if: github.ref_type != 'tag' uses: actions/upload-artifact@v6 with: name: tart-guest-agent-snapshot path: dist/**