diff --git a/.github/actions/prepare-nuget-deps/action.yml b/.github/actions/prepare-nuget-deps/action.yml new file mode 100644 index 00000000..cc4479ee --- /dev/null +++ b/.github/actions/prepare-nuget-deps/action.yml @@ -0,0 +1,46 @@ +name: prepare-nuget-deps +description: Sets up Release NuGet packaging dependencies and decrypts supplied signing key + +inputs: + encrypted-key-path: + description: Path to encrypted signing key, relative to workspace + required: true + release-key-secret: + description: Password for encrypted signing key + required: true + +runs: + using: "composite" + + steps: + - uses: actions/setup-dotnet@v4 + with: + dotnet-quality: ga + dotnet-version: | + 3.1 + 10.0.x + + - name: Install Linux dependencies + if: runner.os == 'Linux' + shell: bash + run: | + wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + + - name: Prepare secure-file tool + shell: bash + run: | + curl -fL -o "$RUNNER_TEMP/secure-file.zip" https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip + unzip "$RUNNER_TEMP/secure-file.zip" -d "$RUNNER_TEMP/secure-file" + + - name: Decrypt signing key + shell: bash + env: + ENCRYPTED_KEY_PATH: ${{ inputs.encrypted-key-path }} + RELEASE_KEY_SECRET: ${{ inputs.release-key-secret }} + run: | + if [ -z "$RELEASE_KEY_SECRET" ]; then + echo "::error::RELEASE_KEY_SECRET is required." + exit 1 + fi + dotnet "$RUNNER_TEMP/secure-file/secure-file.dll" -decrypt "$ENCRYPTED_KEY_PATH" -secret "$RELEASE_KEY_SECRET" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 57503eb1..5335035f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,6 +4,8 @@ concurrency: group: ${{github.workflow}}-${{github.event.pull_request.number || github.sha}} cancel-in-progress: true +permissions: {} + on: push: branches-ignore: @@ -24,6 +26,8 @@ jobs: lint: runs-on: ubuntu-latest + permissions: + contents: read steps: - run: git config --global core.autocrlf true @@ -40,6 +44,8 @@ jobs: test-js: runs-on: ubuntu-latest + permissions: + contents: read strategy: fail-fast: false @@ -76,6 +82,8 @@ jobs: test-dotnet: runs-on: windows-latest + permissions: + contents: read steps: - uses: actions/checkout@v4 @@ -92,47 +100,50 @@ jobs: release-packages: runs-on: ubuntu-latest + permissions: + contents: read env: - RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1 + BUILD_CONFIGURATION: ${{ (github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'push' && github.ref == format('refs/heads/{0}', github.event.repository.default_branch)) && 'Release' || 'Debug' }} steps: - - uses: actions/setup-dotnet@v4 - with: - dotnet-quality: ga - dotnet-version: | - 3.1 - 10.0 - - uses: actions/checkout@v4 - - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: | - wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - curl -L -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip - unzip /opt/secure-file.zip -d /opt/secure-file - dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret ${{ env.RELEASE_KEY_SECRET }} - - run: node build/make-nojquery - run: node build/replace-meta "${{ github.run_number }}" "${{ github.ref }}" "${{ github.repository }}" - run: npm pack - run: npm pack ./js-nojquery - - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: dotnet pack net/DevExtreme.AspNet.Data --configuration=Release --include-symbols + - name: Prepare NuGet deps + if: env.BUILD_CONFIGURATION == 'Release' + uses: ./.github/actions/prepare-nuget-deps + with: + encrypted-key-path: net/DevExtreme.AspNet.Data/release.snk.enc + release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} + + - name: Pack NuGet package + run: dotnet pack net/DevExtreme.AspNet.Data -c ${{ env.BUILD_CONFIGURATION }} --include-symbols + + - name: Remove signing key + if: always() + shell: bash + run: rm -f net/DevExtreme.AspNet.Data/release.snk - uses: actions/upload-artifact@v4 with: name: release-packages path: | - net/DevExtreme.AspNet.Data/bin/Release/*.nupkg + net/DevExtreme.AspNet.Data/bin/${{ env.BUILD_CONFIGURATION }}/*.nupkg devextreme-aspnet-data-*.tgz + retention-days: 14 + if-no-files-found: error docfx: runs-on: windows-latest + permissions: + contents: read steps: - uses: actions/checkout@v4 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 5d847154..1c0fcbcb 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -8,8 +8,11 @@ on: type: boolean default: false -permissions: - contents: read +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +permissions: {} env: NPM_CONFIG_AUDIT: "false" @@ -20,35 +23,25 @@ env: jobs: pack: - runs-on: ubuntu-24.04 + if: github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'workflow_dispatch' && startsWith(github.ref, 'refs/tags/') + runs-on: ubuntu-latest + environment: nuget + permissions: + contents: read env: - RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1 + BUILD_CONFIGURATION: Release steps: - - uses: actions/setup-dotnet@v4 + - uses: actions/checkout@v4 with: - dotnet-quality: ga - dotnet-version: | - 3.1 - 8.0 + persist-credentials: false - uses: actions/setup-node@v4 with: node-version: '24' - - uses: actions/checkout@v4 - - - name: Decrypt signing key - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: | - wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - curl -L -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip - unzip /opt/secure-file.zip -d /opt/secure-file - dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret ${{ env.RELEASE_KEY_SECRET }} - - name: Build no-jquery package run: node build/make-nojquery @@ -60,27 +53,40 @@ jobs: npm pack npm pack ./js-nojquery + - name: Prepare NuGet deps + uses: ./.github/actions/prepare-nuget-deps + with: + encrypted-key-path: net/DevExtreme.AspNet.Data/release.snk.enc + release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} + - name: Pack NuGet package - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: dotnet pack net/DevExtreme.AspNet.Data --configuration=Release --include-symbols + run: dotnet pack net/DevExtreme.AspNet.Data -c ${{ env.BUILD_CONFIGURATION }} --include-symbols - - name: Upload NuGet packages as artifacts - if: ${{ env.RELEASE_KEY_SECRET != '' }} - uses: actions/upload-artifact@v4 - with: - name: nuget-packages - path: net/DevExtreme.AspNet.Data/bin/Release/*.nupkg + - name: Remove signing key + if: always() + shell: bash + run: rm -f net/DevExtreme.AspNet.Data/release.snk - name: Upload npm packages as artifacts uses: actions/upload-artifact@v4 with: name: npm-packages path: devextreme-aspnet-data-*.tgz + retention-days: 7 + if-no-files-found: error + + - name: Upload NuGet packages as artifacts + uses: actions/upload-artifact@v4 + with: + name: nuget-packages + path: net/DevExtreme.AspNet.Data/bin/${{ env.BUILD_CONFIGURATION }}/*.nupkg + retention-days: 7 + if-no-files-found: error publish: - runs-on: ubuntu-latest + runs-on: ubuntu-slim needs: pack - if: startsWith(github.ref, 'refs/tags/') + if: github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'workflow_dispatch' && startsWith(github.ref, 'refs/tags/') environment: npmjs permissions: contents: read diff --git a/docs/using-ci-builds.md b/docs/using-ci-builds.md index b7234105..43cfe46d 100644 --- a/docs/using-ci-builds.md +++ b/docs/using-ci-builds.md @@ -1,12 +1,14 @@ # Using CI Builds -You can download automated build artifacts [here](https://github.com/DevExpress/DevExtreme.AspNet.Data/actions/workflows/ci.yml?query=branch%3Amaster). Please note that you need to be signed in to GitHub. +You can download automated build artifacts [here](https://github.com/DevExpress/DevExtreme.AspNet.Data/actions/workflows/ci.yml?query=branch%3Amaster+event%3Apush). Please note that you need to be signed in to GitHub. - Click the most recent successful workflow run result. -- At the bottom of the opened page, download the `release-packages` archive. +- At the bottom of the opened page, download the `release-packages` archive for npm packages and the NuGet package and symbols. + +The `release-packages` archive from an upstream default-branch push contains the following files: -It contains the following files: - `net/DevExtreme.AspNet.Data/bin/Release/DevExtreme.AspNet.Data.99.0.0-ci-NNN.nupkg` +- `net/DevExtreme.AspNet.Data/bin/Release/DevExtreme.AspNet.Data.99.0.0-ci-NNN.symbols.nupkg` - `devextreme-aspnet-data-99.0.0-ci-NNN.tgz` - `devextreme-aspnet-data-nojquery-99.0.0-ci-NNN.tgz`