Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions .github/workflows/publish-crates.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
name: Publish crate

on:
push:
tags:
- 'v*'

permissions:
contents: read
id-token: write

jobs:
publish:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Verify tag matches Cargo package version
shell: bash
run: |
set -euo pipefail
TAG_VERSION="${GITHUB_REF_NAME#v}"
PACKAGE_VERSION="$(python - <<'PY'
import tomllib
with open('Cargo.toml','rb') as f:
print(tomllib.load(f)['package']['version'])
PY
)"
test "$TAG_VERSION" = "$PACKAGE_VERSION"
- name: Qualify package
run: |
cargo test --locked
cargo package --locked
- name: Authenticate with crates.io trusted publishing
id: auth
uses: rust-lang/crates-io-auth-action@v1
- name: Publish crate
run: cargo publish --locked
env:
CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }}
34 changes: 34 additions & 0 deletions PUBLISHING.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# crates.io publication

This repository is prepared for crates.io trusted publishing through `.github/workflows/publish-crates.yml`.

## One-time registry setup

crates.io Trusted Publishing cannot publish a brand-new crate name for the first time. The crate owner must therefore complete the **first release manually** after confirming that `entity-rust-cleanroom` is available and the package contents are correct.

After the first crate version exists:

1. Open the crate settings on crates.io.
2. Add a GitHub Actions Trusted Publisher.
3. Set repository owner to `blackmore-technology-group`.
4. Set repository to `ENTITY-RUST-CLEANROOM`.
5. Set workflow filename to `publish-crates.yml`.
6. Do not configure a GitHub environment unless the workflow is changed to use the same environment.
7. After the trusted path is proven, prefer Trusted-Publishing-only mode over reusable API tokens.

## Release gate

A release tag must be exactly `v<Cargo.toml package.version>`. The workflow:

- requests a short-lived GitHub OIDC identity;
- verifies the tag matches the Cargo package version;
- runs the locked test suite;
- runs `cargo package --locked`;
- exchanges OIDC identity for a short-lived crates.io publishing token using `rust-lang/crates-io-auth-action`;
- publishes with `cargo publish --locked`.

No long-lived crates.io token is stored in this repository.

## Evidence boundary

crates.io publication improves Rust discovery and installation of the BTG-controlled verifier. It does not constitute unrelated third-party validation or an independently authored ENTITY implementation.
Loading