mirror of
https://github.com/microsoft/regorus.git
synced 2026-08-05 02:16:11 +00:00
Security Improvements: - Pin all GitHub Actions to specific commit hashes instead of version tags - Update actions/checkout from v4 to commit 08eba0b27e820071cde6df949e0beb9ba4906955 - Update actions/setup-python from v5 to commit a26af69be951a213d495a4c3e4e4022e16d87065 (v5.6.0) - Update actions/setup-java from v4 to commit dded0888837ed1f317902acf8a20df0ad188d165 (v5.0.0) - Update actions/setup-node from v4 to commit 1e60f620b9541d16bece96c5465dc8ee9832be0b (v4.4.0) - Update actions/setup-go from v5 to commit 41dfa10bad2bb2ae585af6ee5bb4d7d973ad74ed (v5.1.0) - Update actions/setup-dotnet from v4 to commit 3e891b0cb619bf60e2c25674b222b8940e2c1c25 (v4.1.0) - Update actions/upload-artifact from v4 to commit ea165f8d65b6e75b540449e92b4886f43607fa02 (v4.6.2) - Update actions/download-artifact from v4 to commit 634f93cb2916e3fdff6788551b99b062d0335ce0 (v5.0.0) - Update github/codeql-action from v3 to commit 01fe2e8c43536ad5e1085bad5e7cd6fbc8a30988 (v3.29.11) Rust Toolchain Consolidation: - Create custom composite action .github/actions/toolchains/rust/action.yml - Standardize on Rust 1.89.0 (latest stable) with clippy and rustfmt components - Add optional targets parameter for cross-compilation support - Replace dtolnay/rust-toolchain@stable across 16 workflows This creates a more secure, maintainable, and consistent CI/CD pipeline with centralized Rust toolchain management across all workflows. Signed-off-by: Anand Krishnamoorthi <anakrish@microsoft.com>
129 lines
4.2 KiB
YAML
129 lines
4.2 KiB
YAML
# This file is autogenerated by maturin v1.4.0
|
|
# To update, run
|
|
#
|
|
# maturin generate-ci --manifest-path bindings/python/Cargo.toml github
|
|
#
|
|
name: publish-python
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
linux:
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
matrix:
|
|
target: [x86_64, x86, aarch64, armv7, s390x, ppc64le]
|
|
steps:
|
|
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
|
|
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
|
|
with:
|
|
python-version: '3.10'
|
|
- uses: ./.github/actions/toolchains/rust
|
|
|
|
- name: Build Python extension
|
|
run: |
|
|
cargo fetch
|
|
cargo clippy --all-targets --no-deps -- -Dwarnings
|
|
cargo build --release --target ${{ matrix.target }} --frozen
|
|
working-directory: bindings/python
|
|
|
|
- name: Build wheels
|
|
uses: PyO3/maturin-action@63b75c597b83e247fbf4fb7719801cc4220ae9f3 # v1.43.0
|
|
with:
|
|
target: ${{ matrix.target }}
|
|
args: --release --out dist --manifest-path bindings/python/Cargo.toml --offline --strip
|
|
sccache: 'true'
|
|
manylinux: auto
|
|
- name: Upload wheels
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: wheels-linux-${{ matrix.target }}
|
|
path: dist
|
|
|
|
windows:
|
|
runs-on: windows-latest
|
|
strategy:
|
|
matrix:
|
|
target: [x64, x86]
|
|
steps:
|
|
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
|
|
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
|
|
with:
|
|
python-version: '3.10'
|
|
architecture: ${{ matrix.target }}
|
|
- uses: ./.github/actions/toolchains/rust
|
|
|
|
- name: Build Python extension
|
|
run: |
|
|
cargo fetch
|
|
cargo clippy --all-targets --no-deps -- -Dwarnings
|
|
cargo build --release --target ${{ matrix.host.target }} --frozen
|
|
working-directory: bindings/python
|
|
|
|
- name: Build wheels
|
|
uses: PyO3/maturin-action@63b75c597b83e247fbf4fb7719801cc4220ae9f3 # v1.43.0
|
|
with:
|
|
target: ${{ matrix.target }}
|
|
args: --release --out dist --manifest-path bindings/python/Cargo.toml --frozen --strip
|
|
sccache: 'true'
|
|
- name: Upload wheels
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: wheels-windows-${{ matrix.target }}
|
|
path: dist
|
|
|
|
macos:
|
|
runs-on: macos-latest
|
|
strategy:
|
|
matrix:
|
|
target: [x86_64, aarch64, universal2-apple-darwin]
|
|
steps:
|
|
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4
|
|
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
|
|
with:
|
|
python-version: '3.10'
|
|
- uses: ./.github/actions/toolchains/rust
|
|
|
|
- name: Build Python extension
|
|
run: |
|
|
cargo fetch
|
|
cargo clippy --all-targets --no-deps -- -Dwarnings
|
|
cargo build --release --target ${{ matrix.host.target }} --frozen
|
|
working-directory: bindings/python
|
|
|
|
- name: Build wheels
|
|
uses: PyO3/maturin-action@63b75c597b83e247fbf4fb7719801cc4220ae9f3 # v1.43.0
|
|
with:
|
|
target: ${{ matrix.target }}
|
|
args: --release --out dist --manifest-path bindings/python/Cargo.toml --offline --strip
|
|
sccache: 'true'
|
|
- name: Upload wheels
|
|
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: wheels-macos-${{ matrix.host.target }}
|
|
path: dist
|
|
|
|
release:
|
|
name: Release
|
|
runs-on: ubuntu-latest
|
|
# Commented out for initial release.
|
|
# if: "startsWith(github.ref, 'refs/tags/')"
|
|
needs: [linux, windows, macos]
|
|
steps:
|
|
- uses: actions/download-artifact@634f93cb2916e3fdff6788551b99b062d0335ce0 # v5.0.0
|
|
with:
|
|
pattern: wheels-*
|
|
merge-multiple: true
|
|
path: wheels
|
|
- name: Publish to PyPI
|
|
uses: PyO3/maturin-action@63b75c597b83e247fbf4fb7719801cc4220ae9f3 # v1.43.0
|
|
env:
|
|
MATURIN_PYPI_TOKEN: ${{ secrets.PYPI_API_TOKEN }}
|
|
with:
|
|
command: upload
|
|
args: --non-interactive --skip-existing *
|