Files
tldr/.github/workflows/copy-release-assets.yml
dependabot[bot] deeb72b014 build(deps): bump actions/attest-build-provenance from 1 to 2 (#15061)
Bumps [actions/attest-build-provenance](https://github.com/actions/attest-build-provenance) from 1 to 2.
- [Release notes](https://github.com/actions/attest-build-provenance/releases)
- [Changelog](https://github.com/actions/attest-build-provenance/blob/main/RELEASE.md)
- [Commits](https://github.com/actions/attest-build-provenance/compare/v1...v2)

---
updated-dependencies:
- dependency-name: actions/attest-build-provenance
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-07 23:08:34 +05:30

54 lines
1.7 KiB
YAML

name: Copy assets to the new release
on:
release:
types: published
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
jobs:
release:
name: Copy release assets
runs-on: ubuntu-latest
permissions:
contents: write # to upload assets to releases
attestations: write # to upload assets attestation for build provenance
id-token: write # grant additional permission to attestation action to mint the OIDC token permission
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set tag names
run: |
echo "LATEST=$(git describe --tags --abbrev=0)" >> $GITHUB_ENV
echo "PREVIOUS=$(git describe --tags --abbrev=0 $(git describe --tags --abbrev=0)^)" >> $GITHUB_ENV
- name: Download assets
run: |
mkdir release-assets && cd release-assets
gh release download "$PREVIOUS"
- name: Construct subject-path for attest
if: github.repository == 'tldr-pages/tldr'
id: construct-subject-path
run: |
zip_files=$(find release-assets -name '*.zip' -printf '%p,')
pdf_files=$(find release-assets -name '*.pdf' -printf '%p,')
subject_path="${zip_files::-1},${pdf_files::-1},release-assets/tldr.sha256sums"
echo "subject_path=$subject_path" >> $GITHUB_ENV
- name: Attest copied assets
if: github.repository == 'tldr-pages/tldr'
id: attest
uses: actions/attest-build-provenance@v2
with:
subject-path: ${{ env.subject_path }}
- name: Upload assets
if: github.repository == 'tldr-pages/tldr'
working-directory: release-assets
run: gh release upload "$LATEST" -- *