This repository has been archived on 2026-09-24. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
Michael Lyonandclaude 8b0b1e25b3 Use nix-hash for SRI conversion and add install-nix-action
Replace the fragile Python one-liner with nix-hash --sri for
computing flake hashes in CI. Add cachix/install-nix-action@v31
to ensure Nix is available on the runner. Add grep verification
to fail loudly if sed replacements don't take effect.

Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
2026-04-03 11:15:21 -06:00

95 lines
2.8 KiB
YAML

name: Release
on:
workflow_dispatch:
inputs:
bump:
description: "Semver bump (patch, minor, major)"
required: false
default: "patch"
push:
branches:
- release
jobs:
build-and-release:
if: github.actor != 'github-actions[bot]'
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@v4
with:
persist-credentials: true
- name: Use Node.js
uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- name: Install dependencies
run: npm ci
- name: Bump version and tag
id: bump
env:
BUMP: ${{ inputs.bump }}
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
npm version "${BUMP:-patch}" -m "chore: release %s"
VERSION=$(node -p "require('./package.json').version")
echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
git push
git push --tags
- name: Build artifacts
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
npm run build
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
tag_name: v${{ steps.bump.outputs.version }}
name: Linear v${{ steps.bump.outputs.version }}
draft: false
prerelease: false
files: |
dist/*.AppImage
dist/*.deb
dist/*.rpm
- name: Install Nix
uses: cachix/install-nix-action@v31
- name: Update flake.nix hashes
env:
VERSION: ${{ steps.bump.outputs.version }}
run: |
X86_SRI=$(nix-hash --type sha256 --flat --sri dist/linear-linux-${VERSION}-x86_64.AppImage)
ARM_SRI=$(nix-hash --type sha256 --flat --sri dist/linear-linux-${VERSION}-arm64.AppImage)
sed -i "s|version = \".*\";|version = \"${VERSION}\";|" flake.nix
sed -i "s|hash = \"sha256-.*\"; # x86_64|hash = \"${X86_SRI}\"; # x86_64|" flake.nix
sed -i "s|hash = \"sha256-.*\"; # aarch64|hash = \"${ARM_SRI}\"; # aarch64|" flake.nix
grep -q "${X86_SRI}" flake.nix || { echo "::error::Failed to update x86_64 hash"; exit 1; }
grep -q "${ARM_SRI}" flake.nix || { echo "::error::Failed to update aarch64 hash"; exit 1; }
- name: Commit flake.nix update
env:
VERSION: ${{ steps.bump.outputs.version }}
run: |
git add flake.nix
if git diff --cached --quiet; then
echo "No changes to flake.nix"
else
git commit -m "chore: update flake.nix hashes for v${VERSION}"
git push
fi