← Files Plugin AutopilotARCHIVED FILE

.github/workflows/release.yml

3.67 KB · Oct 2, 2026 · 00:33 UTC

↓ Download file

name: Release

on:
  push:
    tags:
      - "v*"

permissions: {}

jobs:
  verify:
    name: Verify Release Candidate
    runs-on: ubuntu-latest
    permissions:
      contents: read
    steps:
      - name: Checkout repository and history
        uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
        with:
          fetch-depth: 0

      - name: Verify tag matches manifest version
        shell: bash
        run: |
          set -euo pipefail
          version="$(python3 -c 'import json; print(json.load(open(".codex-plugin/plugin.json"))["version"])')"
          test "$GITHUB_REF_NAME" = "v$version"

      - name: Verify release commit provenance on main
        shell: bash
        run: |
          set -euo pipefail
          git fetch origin main:refs/remotes/origin/main
          git merge-base --is-ancestor "$GITHUB_SHA" origin/main

      - name: Unit tests
        run: python3 -m unittest discover -s tests -v

      - name: Directory listing pack
        run: python3 skills/chatgpt-codex-plugin-autopilot/scripts/build_directory_pack.py . --listing submission/listing.json --json

      - name: Self-check
        run: python3 scripts/self_check.py

      - name: Build twice
        run: |
          python3 scripts/build_release.py --out-dir dist-a
          python3 scripts/build_release.py --out-dir dist-b

      - name: Verify deterministic package and archive
        shell: bash
        run: |
          set -euo pipefail
          a=(dist-a/chatgpt-codex-plugin-autopilot-*.zip)
          b=(dist-b/chatgpt-codex-plugin-autopilot-*.zip)
          test ${#a[@]} -eq 1
          test ${#b[@]} -eq 1
          cmp -- "${a[0]}" "${b[0]}"
          cmp -- dist-a/SHA256SUMS dist-b/SHA256SUMS
          (cd dist-a && sha256sum -c SHA256SUMS)
          unzip -t "${a[0]}"
          unzip -Z1 "${a[0]}"

      - name: Stage verified release assets
        run: |
          mkdir -p verified-assets
          cp dist-a/chatgpt-codex-plugin-autopilot-*.zip verified-assets/
          cp dist-a/SHA256SUMS verified-assets/
          cp submission/reviewer-packet.json verified-assets/

      - name: Upload verified release assets
        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
        with:
          name: verified-release-assets
          path: verified-assets/
          if-no-files-found: error
          retention-days: 1

  publish:
    name: Publish GitHub Release
    needs: verify
    runs-on: ubuntu-latest
    permissions:
      contents: write
    steps:
      - name: Download verified release assets
        uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
        with:
          name: verified-release-assets
          path: dist-release

      - name: Verify release asset checksums before publication
        shell: bash
        run: |
          set -euo pipefail
          cd dist-release && sha256sum -c SHA256SUMS

      - name: Create GitHub Release
        env:
          GH_TOKEN: ${{ github.token }}
        run: |
          gh release create "$GITHUB_REF_NAME" \
            dist-release/chatgpt-codex-plugin-autopilot-*.zip \
            dist-release/SHA256SUMS \
            dist-release/reviewer-packet.json \
            --repo "$GITHUB_REPOSITORY" \
            --verify-tag \
            --generate-notes \
            --title "$GITHUB_REF_NAME"

      - name: Post-publish download and checksum verification
        env:
          GH_TOKEN: ${{ github.token }}
        shell: bash
        run: |
          set -euo pipefail
          mkdir -p dist-download
          gh release download "$GITHUB_REF_NAME" --repo "$GITHUB_REPOSITORY" --dir dist-download
          cd dist-download && sha256sum -c SHA256SUMS

SHA-256: 2af626b36338fae0b47a92d0e3187cb72382649aeaac34d04a19f28fa3964654