Repository navigation
Fix installer fixture path literal #55
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| branches: [ main ] | |
| workflow_dispatch: | |
| env: | |
| DOTNET_VERSION: '10.0.x' | |
| NODE_VERSION: '22' | |
| jobs: | |
| verify-ci: | |
| name: Verify exact-SHA CI before release | |
| runs-on: ubuntu-latest | |
| if: github.ref == 'refs/heads/main' | |
| timeout-minutes: 31 | |
| permissions: | |
| actions: read | |
| contents: read | |
| steps: | |
| - name: Wait for successful CI on this commit | |
| shell: bash | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| set -euo pipefail | |
| deadline=$((SECONDS + 1800)) | |
| ci_workflow_id=$(gh api "repos/${GITHUB_REPOSITORY}/actions/workflows" \ | |
| --jq '[.workflows[] | select(.path == ".github/workflows/ci.yml")][0].id // empty') | |
| if [[ -z "$ci_workflow_id" ]]; then | |
| echo "Could not resolve this repository's CI workflow; release publication is blocked." | |
| exit 1 | |
| fi | |
| while (( SECONDS < deadline )); do | |
| run=$(gh api --method GET "repos/${GITHUB_REPOSITORY}/actions/runs" \ | |
| -f head_sha="$GITHUB_SHA" \ | |
| -F per_page=100 \ | |
| --jq "[.workflow_runs[] | select(.workflow_id == $ci_workflow_id and .head_sha == \"$GITHUB_SHA\" and .head_branch == \"main\" and .event == \"push\")] | sort_by(.created_at) | last // empty") | |
| if [[ -z "$run" ]]; then | |
| echo "Waiting for the CI run for this exact commit to appear." | |
| else | |
| status=$(jq -r '.status' <<<"$run") | |
| conclusion=$(jq -r '.conclusion // ""' <<<"$run") | |
| echo "Exact-SHA CI status: $status; conclusion: ${conclusion:-pending}." | |
| if [[ "$status" == "completed" ]]; then | |
| if [[ "$conclusion" == "success" ]]; then | |
| exit 0 | |
| fi | |
| echo "Exact-SHA CI did not succeed; release publication is blocked." | |
| exit 1 | |
| fi | |
| fi | |
| sleep 15 | |
| done | |
| echo "Timed out waiting for successful exact-SHA CI; release publication is blocked." | |
| exit 1 | |
| build: | |
| name: Build and Test | |
| runs-on: ubuntu-latest | |
| outputs: | |
| version: ${{ steps.version.outputs.version }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v5 | |
| with: | |
| submodules: recursive | |
| - name: Setup .NET | |
| uses: actions/setup-dotnet@v4 | |
| with: | |
| dotnet-version: ${{ env.DOTNET_VERSION }} | |
| - name: Setup Node.js | |
| uses: actions/setup-node@v4 | |
| with: | |
| node-version: ${{ env.NODE_VERSION }} | |
| - name: Install Codex CLI | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| target_version="$(sed -nE 's/^[[:space:]]*public const string TargetVersion = "([0-9]+\.[0-9]+\.[0-9]+)";$/\1/p' CodexSharpSDK/Models/CodexCliCompatibility.cs)" | |
| [[ -n "$target_version" && "$target_version" != *$'\n'* ]] || { echo "Expected exactly one three-part Codex CLI TargetVersion."; exit 1; } | |
| npm install --no-save "@openai/codex@$target_version" | |
| export PATH="$GITHUB_WORKSPACE/node_modules/.bin:$PATH" | |
| [[ -f node_modules/@openai/codex/package.json && -f node_modules/@openai/codex/bin/codex.js ]] || { echo "The pinned Codex npm package is missing its manifest or CLI entry point."; exit 1; } | |
| package_version="$(node -p 'require("./node_modules/@openai/codex/package.json").version')" | |
| [[ "$package_version" == "$target_version" ]] || { echo "The installed Codex npm package version does not match TargetVersion."; exit 1; } | |
| version="$(node node_modules/@openai/codex/bin/codex.js --version)" | |
| printf '%s\n' "$version" | |
| actual_version="$(printf '%s\n' "$version" | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | sed -n '1p')" | |
| printf 'Installed Codex CLI version: %s\n' "$actual_version" | |
| [[ "$actual_version" == "$target_version" ]] | |
| echo "$GITHUB_WORKSPACE/node_modules/.bin" >> "$GITHUB_PATH" | |
| - name: Extract version from Directory.Build.props | |
| id: version | |
| run: | | |
| VERSION=$(grep -oPm1 "(?<=<Version>)[^<]+" Directory.Build.props) | |
| if [ -z "$VERSION" ]; then | |
| echo "Failed to resolve package version from Directory.Build.props" | |
| exit 1 | |
| fi | |
| echo "version=$VERSION" >> "$GITHUB_OUTPUT" | |
| echo "Version from Directory.Build.props: $VERSION" | |
| - name: Validate semantic version | |
| run: | | |
| VERSION="${{ steps.version.outputs.version }}" | |
| if [[ ! "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?(\+[0-9A-Za-z.-]+)?$ ]]; then | |
| echo "Version '$VERSION' is not a valid semantic version." | |
| exit 1 | |
| fi | |
| - name: Restore dependencies | |
| run: dotnet restore ManagedCode.CodexSharpSDK.slnx | |
| - name: Build | |
| run: dotnet build ManagedCode.CodexSharpSDK.slnx --configuration Release --warnaserror --no-restore | |
| - name: Test (full solution) | |
| run: dotnet test --solution ManagedCode.CodexSharpSDK.slnx --configuration Release --no-build -- --treenode-filter "/*/*/*/*[RequiresCodexAuth!=true]" | |
| - name: Install Native AOT prerequisites | |
| run: sudo apt-get update && sudo apt-get install -y clang zlib1g-dev libssl-dev libbrotli-dev | |
| - name: Publish and run Native AOT smoke | |
| run: | | |
| dotnet publish AotSmoke/ManagedCode.CodexSharpSDK.AotSmoke.csproj --configuration Release --runtime linux-x64 --output ./AotSmoke/artifacts | |
| ./AotSmoke/artifacts/ManagedCode.CodexSharpSDK.AotSmoke | |
| - name: Codex CLI smoke tests | |
| run: dotnet test --project CodexSharpSDK.Tests/CodexSharpSDK.Tests.csproj --configuration Release --no-build -- --treenode-filter "/*/*/*/CodexCli_Smoke_*" | |
| - name: Pack NuGet packages | |
| run: | | |
| mkdir -p ./artifacts | |
| dotnet pack ManagedCode.CodexSharpSDK.slnx --configuration Release --no-build -p:IncludeSymbols=false -p:SymbolPackageFormat=snupkg --output ./artifacts | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: nuget-packages | |
| path: ./artifacts/*.nupkg | |
| retention-days: 5 | |
| publish-nuget: | |
| name: Publish to NuGet | |
| needs: [build, verify-ci] | |
| runs-on: ubuntu-latest | |
| if: github.ref == 'refs/heads/main' | |
| outputs: | |
| published: ${{ steps.publish.outputs.published }} | |
| version: ${{ needs.build.outputs.version }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v5 | |
| - name: Download artifacts | |
| uses: actions/download-artifact@v5 | |
| with: | |
| name: nuget-packages | |
| path: ./artifacts | |
| - name: Setup .NET | |
| uses: actions/setup-dotnet@v4 | |
| with: | |
| dotnet-version: ${{ env.DOTNET_VERSION }} | |
| - name: Publish to NuGet | |
| id: publish | |
| continue-on-error: true | |
| run: | | |
| set +e | |
| OUTPUT="" | |
| PUBLISHED=false | |
| for package in ./artifacts/*.nupkg; do | |
| echo "Publishing $package..." | |
| RESULT=$(dotnet nuget push "$package" \ | |
| --api-key ${{ secrets.NUGET_API_KEY }} \ | |
| --source https://api.nuget.org/v3/index.json \ | |
| --skip-duplicate 2>&1) | |
| EXIT_CODE=$? | |
| echo "$RESULT" | |
| OUTPUT="$OUTPUT$RESULT" | |
| if [ $EXIT_CODE -eq 0 ]; then | |
| echo "Successfully published $package" | |
| PUBLISHED=true | |
| elif echo "$RESULT" | grep -qi "already exists"; then | |
| echo "Package already exists, skipping..." | |
| else | |
| echo "Failed to publish $package" | |
| exit 1 | |
| fi | |
| done | |
| if [ "$PUBLISHED" = true ] || echo "$OUTPUT" | grep -q "Your package was pushed"; then | |
| echo "published=true" >> "$GITHUB_OUTPUT" | |
| echo "At least one package was successfully published" | |
| else | |
| echo "published=false" >> "$GITHUB_OUTPUT" | |
| echo "No new packages were published (all already exist)" | |
| fi | |
| create-release: | |
| name: Create GitHub Release and Tag | |
| needs: publish-nuget | |
| runs-on: ubuntu-latest | |
| if: needs.publish-nuget.outputs.published == 'true' | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v5 | |
| with: | |
| fetch-depth: 0 | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Download artifacts | |
| uses: actions/download-artifact@v5 | |
| with: | |
| name: nuget-packages | |
| path: ./artifacts | |
| - name: Create and push tag | |
| id: create_tag | |
| run: | | |
| VERSION="${{ needs.publish-nuget.outputs.version }}" | |
| TAG="v$VERSION" | |
| git config user.name "github-actions[bot]" | |
| git config user.email "github-actions[bot]@users.noreply.github.com" | |
| if git rev-parse "$TAG" >/dev/null 2>&1; then | |
| echo "Tag $TAG already exists" | |
| echo "tag_exists=true" >> "$GITHUB_OUTPUT" | |
| else | |
| echo "Creating tag $TAG" | |
| git tag -a "$TAG" -m "Release $VERSION" | |
| git push origin "$TAG" | |
| echo "tag_exists=false" >> "$GITHUB_OUTPUT" | |
| fi | |
| - name: Get previous tag | |
| id: prev_tag | |
| run: | | |
| CURRENT_TAG="v${{ needs.publish-nuget.outputs.version }}" | |
| PREVIOUS_TAG=$(git tag --sort=-version:refname | grep -A1 "^$CURRENT_TAG$" | tail -n1 || echo "") | |
| if [ "$PREVIOUS_TAG" = "$CURRENT_TAG" ] || [ -z "$PREVIOUS_TAG" ]; then | |
| PREVIOUS_TAG=$(git tag --sort=-version:refname | grep -v "^$CURRENT_TAG$" | head -n1 || echo "") | |
| fi | |
| echo "previous_tag=$PREVIOUS_TAG" >> "$GITHUB_OUTPUT" | |
| echo "Current tag: $CURRENT_TAG" | |
| echo "Previous tag: $PREVIOUS_TAG" | |
| - name: Generate release notes | |
| id: release_notes | |
| run: | | |
| VERSION="${{ needs.publish-nuget.outputs.version }}" | |
| CURRENT_TAG="v$VERSION" | |
| PREVIOUS_TAG="${{ steps.prev_tag.outputs.previous_tag }}" | |
| echo "# Release $VERSION" > release_notes.md | |
| echo "" >> release_notes.md | |
| echo "Released on $(date +'%Y-%m-%d')" >> release_notes.md | |
| echo "" >> release_notes.md | |
| if [ -n "$PREVIOUS_TAG" ]; then | |
| echo "## Changes since $PREVIOUS_TAG" >> release_notes.md | |
| echo "" >> release_notes.md | |
| echo "### Features" >> release_notes.md | |
| git log --pretty=format:"- %s (%h)" "$PREVIOUS_TAG"..HEAD --grep="^feat" --grep="^feature" >> release_notes.md || true | |
| echo "" >> release_notes.md | |
| echo "### Bug Fixes" >> release_notes.md | |
| git log --pretty=format:"- %s (%h)" "$PREVIOUS_TAG"..HEAD --grep="^fix" --grep="^bugfix" >> release_notes.md || true | |
| echo "" >> release_notes.md | |
| echo "### Documentation" >> release_notes.md | |
| git log --pretty=format:"- %s (%h)" "$PREVIOUS_TAG"..HEAD --grep="^docs" --grep="^doc" >> release_notes.md || true | |
| echo "" >> release_notes.md | |
| echo "### Other Changes" >> release_notes.md | |
| git log --pretty=format:"- %s (%h)" "$PREVIOUS_TAG"..HEAD --invert-grep --grep="^feat" --grep="^feature" --grep="^fix" --grep="^bugfix" --grep="^docs" --grep="^doc" >> release_notes.md || true | |
| echo "" >> release_notes.md | |
| else | |
| echo "## Initial Release" >> release_notes.md | |
| echo "" >> release_notes.md | |
| echo "### Recent Changes" >> release_notes.md | |
| git log --pretty=format:"- %s (%h)" --max-count=20 >> release_notes.md | |
| echo "" >> release_notes.md | |
| fi | |
| echo "" >> release_notes.md | |
| echo "## NuGet Packages" >> release_notes.md | |
| echo "" >> release_notes.md | |
| shopt -s nullglob | |
| for package in ./artifacts/*.nupkg; do | |
| base_name=$(basename "$package" .nupkg) | |
| if [[ "$base_name" =~ ^(.+)\.([0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?(\+[0-9A-Za-z.-]+)?)$ ]]; then | |
| PACKAGE_ID="${BASH_REMATCH[1]}" | |
| PACKAGE_VERSION="${BASH_REMATCH[2]}" | |
| echo "- [$PACKAGE_ID v$PACKAGE_VERSION](https://www.nuget.org/packages/$PACKAGE_ID/$PACKAGE_VERSION)" >> release_notes.md | |
| else | |
| echo "- $base_name" >> release_notes.md | |
| fi | |
| done | |
| echo "" >> release_notes.md | |
| echo "---" >> release_notes.md | |
| echo "*This release was automatically created by GitHub Actions*" >> release_notes.md | |
| - name: Create GitHub Release | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| tag_name: v${{ needs.publish-nuget.outputs.version }} | |
| name: v${{ needs.publish-nuget.outputs.version }} | |
| body_path: release_notes.md | |
| draft: false | |
| prerelease: false | |
| files: ./artifacts/*.nupkg | |
| token: ${{ secrets.GITHUB_TOKEN }} |