# TODO: Move this to bash scripts intead of Github Actions # so it can be run from Buildkite, see: .buildkite/scripts/release.sh name: Release concurrency: release env: BUN_VERSION: ${{ github.event.inputs.tag || github.event.release.tag_name || 'canary' }} BUN_LATEST: ${{ (inputs.is-latest || github.event.release.tag_name) && 'true' || 'false' }} permissions: contents: read on: release: types: - published schedule: - cron: "0 14 * * *" # every day at 6am PST workflow_dispatch: inputs: is-latest: description: Is this the latest release? type: boolean default: false tag: type: string description: What is the release tag? (e.g. "1.0.2", "canary") required: true use-docker: description: Should Docker images be released? type: boolean default: false use-npm: description: Should npm packages be published? type: boolean default: false use-homebrew: description: Should binaries be released to Homebrew? type: boolean default: false use-s3: description: Should binaries be uploaded to S3? type: boolean default: false use-types: description: Should types be released to npm? type: boolean default: false use-definitelytyped: description: "Should types be PR'd to DefinitelyTyped?" type: boolean default: false jobs: sign: name: Sign Release runs-on: ubuntu-latest if: ${{ github.repository_owner == 'oven-sh' }} permissions: contents: write defaults: run: working-directory: packages/bun-release steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup GPG uses: crazy-max/ghaction-import-gpg@2dc316deee8e90f13e1a351ab510b4d5bc0c82cd # v7.0.0 with: gpg_private_key: ${{ secrets.GPG_PRIVATE_KEY }} passphrase: ${{ secrets.GPG_PASSPHRASE }} - name: Setup Bun uses: ./.github/actions/setup-bun with: bun-version: "1.3.14" - name: Install Dependencies run: bun install - name: Sign Release run: | echo "$GPG_PASSPHRASE" | bun upload-assets -- "$BUN_VERSION" env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} GPG_PASSPHRASE: ${{ secrets.GPG_PASSPHRASE }} npm: name: Release to NPM runs-on: ubuntu-latest needs: sign if: ${{ github.event_name != 'workflow_dispatch' || github.event.inputs.use-npm == 'true' }} permissions: contents: read defaults: run: working-directory: packages/bun-release steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false # To workaround issue ref: main - name: Setup Bun uses: ./.github/actions/setup-bun with: bun-version: "1.3.14" - name: Install Dependencies run: bun install - name: Release run: bun upload-npm -- "$BUN_VERSION" publish env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} NPM_TOKEN: ${{ secrets.NPM_TOKEN }} npm-types: name: Release types to NPM runs-on: ubuntu-latest needs: sign if: ${{ github.event_name != 'workflow_dispatch' || github.event.inputs.use-types == 'true' }} permissions: contents: read defaults: run: working-directory: packages/bun-types steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: node-version: latest - name: Setup Bun if: ${{ env.BUN_VERSION != 'canary' }} uses: ./.github/actions/setup-bun with: bun-version: "1.3.14" - name: Setup Bun if: ${{ env.BUN_VERSION == 'canary' }} uses: ./.github/actions/setup-bun with: bun-version: "canary" # Must be 'canary' so tag is correct - name: Install Dependencies run: bun install - name: Setup Tag if: ${{ env.BUN_VERSION == 'canary' }} run: | VERSION=$(bun --version) TAG="${VERSION}-canary.$(date +'%Y%m%dT%H%M%S')" echo "Setup tag: ${TAG}" echo "TAG=${TAG}" >> ${GITHUB_ENV} - name: Build run: bun run build env: BUN_VERSION: ${{ env.TAG || env.BUN_VERSION }} - name: Release if: ${{ env.BUN_VERSION == 'canary' || env.BUN_LATEST == 'true' }} env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} NPM_CONFIG_USERCONFIG: ${{ runner.temp }}/.npmrc NPM_TAG: ${{ env.BUN_VERSION == 'canary' && 'canary' || 'latest' }} run: | echo '//registry.npmjs.org/:_authToken=${NODE_AUTH_TOKEN}' > "$NPM_CONFIG_USERCONFIG" VERSION=$(node -p 'require("./package.json").version') if [ "$(npm view bun-types@"$VERSION" version 2>/dev/null)" = "$VERSION" ]; then echo "bun-types@$VERSION already published, skipping" exit 0 fi npm publish --access public --tag "$NPM_TAG" definitelytyped: name: Make pr to DefinitelyTyped to update `bun-types` version runs-on: ubuntu-latest needs: npm-types if: ${{ github.event_name == 'release' || github.event.inputs.use-definitelytyped == 'true' }} permissions: contents: read steps: - name: Checkout (DefinitelyTyped) uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false repository: DefinitelyTyped/DefinitelyTyped - name: Checkout (bun) uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false path: bun - name: Setup Bun uses: ./bun/.github/actions/setup-bun with: bun-version: "1.3.14" - id: bun-version run: echo "BUN_VERSION=${BUN_VERSION#bun-v}" >> "$GITHUB_OUTPUT" - name: Update bun-types version in package.json run: | bun -e ' const file = Bun.file("./types/bun/package.json"); const json = await file.json(); const version = process.env.BUN_VERSION.replace(/^bun-v/, ""); json.dependencies["bun-types"] = version; json.version = version.slice(0, version.lastIndexOf(".")) + ".9999"; await file.write(JSON.stringify(json, null, 4) + "\n"); ' - name: Create Pull Request uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1 if: ${{ env.BUN_LATEST == 'true' && env.BUN_VERSION != 'canary'}} with: token: ${{ secrets.ROBOBUN_TOKEN }} add-paths: ./types/bun/package.json title: "[bun] update to ${{ steps.bun-version.outputs.BUN_VERSION }}" commit-message: "[bun] update to ${{ steps.bun-version.outputs.BUN_VERSION }}" body: | Update `bun-types` version to ${{ steps.bun-version.outputs.BUN_VERSION }} https://bun.com/blog/${{ env.BUN_VERSION }} push-to-fork: oven-sh/DefinitelyTyped branch: ${{env.BUN_VERSION}} docker: name: Release to Dockerhub runs-on: ubuntu-latest needs: sign if: ${{ github.event_name != 'workflow_dispatch' || github.event.inputs.use-docker == 'true' }} permissions: contents: read strategy: fail-fast: false matrix: include: - variant: debian suffix: "" - variant: debian suffix: -debian - variant: slim suffix: -slim dir: debian-slim - variant: alpine suffix: -alpine - variant: distroless suffix: -distroless steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Docker emulator uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0 - id: buildx name: Setup Docker buildx uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0 with: platforms: linux/amd64,linux/arm64 - id: metadata name: Setup Docker metadata uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 with: images: oven/bun flavor: | latest=false tags: | type=raw,value=latest,enable=${{ env.BUN_LATEST == 'true' && matrix.suffix == '' }} type=raw,value=${{ matrix.variant }},enable=${{ env.BUN_LATEST == 'true' }} type=match,pattern=(bun-v)?(canary|\d+.\d+.\d+),group=2,value=${{ env.BUN_VERSION }},suffix=${{ matrix.suffix }} type=match,pattern=(bun-v)?(canary|\d+.\d+),group=2,value=${{ env.BUN_VERSION }},suffix=${{ matrix.suffix }} type=match,pattern=(bun-v)?(canary|\d+),group=2,value=${{ env.BUN_VERSION }},suffix=${{ matrix.suffix }} - name: Login to Docker uses: docker/login-action@371161bbe7024a29a25c5e19bfcbc0804fe9ad2c # v4.5.2 with: username: ${{ secrets.DOCKER_USERNAME }} password: ${{ secrets.DOCKER_PASSWORD }} - name: Push to Docker uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0 with: context: ./dockerhub/${{ matrix.dir || matrix.variant }} platforms: linux/amd64,linux/arm64 builder: ${{ steps.buildx.outputs.name }} push: true tags: ${{ steps.metadata.outputs.tags }} labels: ${{ steps.metadata.outputs.labels }} build-args: | BUN_VERSION=${{ env.BUN_VERSION }} homebrew: name: Release to Homebrew runs-on: ubuntu-latest needs: sign permissions: contents: read if: ${{ github.event_name == 'release' || github.event.inputs.use-homebrew == 'true' }} steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: oven-sh/homebrew-bun persist-credentials: false - name: Setup GPG uses: crazy-max/ghaction-import-gpg@2dc316deee8e90f13e1a351ab510b4d5bc0c82cd # v7.0.0 with: gpg_private_key: ${{ secrets.GPG_PRIVATE_KEY }} passphrase: ${{ secrets.GPG_PASSPHRASE }} git_user_signingkey: true git_commit_gpgsign: true git_committer_name: robobun git_committer_email: robobun@oven.sh - name: Setup Ruby uses: ruby/setup-ruby@95ef2b042f9d7a56d8268cba8559e2842e2ad01b # v1 with: ruby-version: "2.6" - name: Update Tap run: ruby scripts/release.rb "$BUN_VERSION" - name: Commit Tap env: ROBOBUN_TOKEN: ${{ secrets.ROBOBUN_TOKEN }} run: | git add -A git diff --cached --quiet && exit 0 git commit -m "Release $BUN_VERSION" git push "https://x-access-token:${ROBOBUN_TOKEN}@github.com/oven-sh/homebrew-bun" HEAD:main s3: name: Upload to S3 runs-on: ubuntu-latest needs: sign if: ${{ github.event_name != 'workflow_dispatch' || github.event.inputs.use-s3 == 'true' }} permissions: contents: read defaults: run: working-directory: packages/bun-release steps: - name: Checkout uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false - name: Setup Bun uses: ./.github/actions/setup-bun with: bun-version: "1.3.14" - name: Install Dependencies run: bun install - name: Release run: bun upload-s3 -- "$BUN_VERSION" env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY}} AWS_ENDPOINT: ${{ secrets.AWS_ENDPOINT }} AWS_BUCKET: bun notify-sentry: name: Notify Sentry runs-on: ubuntu-latest needs: s3 steps: - name: Notify Sentry uses: getsentry/action-release@ff07929a6537bac57790c3451cf4d364aca38528 # v3.7.0 env: SENTRY_AUTH_TOKEN: ${{ secrets.SENTRY_AUTH_TOKEN }} SENTRY_ORG: ${{ secrets.SENTRY_ORG }} SENTRY_PROJECT: ${{ secrets.SENTRY_PROJECT }} with: ignore_missing: true ignore_empty: true version: ${{ env.BUN_VERSION }} environment: production