diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index f3e550bc..0d1ccea4 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -32,3 +32,28 @@ jobs: name: dist path: dist/ - uses: pypa/gh-action-pypi-publish@release/v1 + + github-release: + needs: publish + runs-on: ubuntu-latest + permissions: + contents: write + steps: + - uses: actions/checkout@v4 + - uses: actions/download-artifact@v4 + with: + name: dist + path: dist/ + - name: Extract latest CHANGELOG section + run: | + # Grab the topmost "## [...]" block from CHANGELOG.md as release notes. + awk '/^## \[/{c++} c==1' CHANGELOG.md | sed '/^---$/d' > release_notes.md + echo "Release notes:" && cat release_notes.md + - name: Create GitHub Release + env: + GH_TOKEN: ${{ github.token }} + run: | + gh release create "${GITHUB_REF_NAME}" \ + --title "${GITHUB_REF_NAME}" \ + --notes-file release_notes.md \ + dist/* diff --git a/CHANGELOG.md b/CHANGELOG.md index e549b0c8..ba051b65 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -27,6 +27,9 @@ and this project uses [Calendar Versioning](https://calver.org/) in the format - **OpenSSF Scorecard** — `.github/workflows/scorecard.yml` runs the official OSSF Scorecard action on push to `main` and weekly. Publishes a public security health score at scorecard.dev with a README badge. Actions pinned by SHA. +- **GitHub Releases** — `publish.yml` now cuts a GitHub Release on each `v*` tag, + with notes pulled from the top CHANGELOG section and the built dist attached. + PyPI publish + GitHub Release now fire from the same tag. - **Registry descriptions** — all 13 branches now have one-liner descriptions in `AIPASS_REGISTRY.json`. `drone systems` shows what each agent does instead of blank lines. Closes [#607](https://github.com/AIOSAI/AIPass/issues/607).