name: Release on: push: tags: - 'v*' # Trigger on version tags like v1.0.0, v0.13.0, etc. env: FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true" jobs: release: runs-on: ubuntu-latest permissions: id-token: write contents: write steps: - uses: actions/checkout@v6 with: fetch-depth: 0 - name: Set up Python uses: actions/setup-python@v6 with: python-version: "3.12" - name: Install uv run: | pip install uv - name: Install dependencies and build run: | uv venv uv sync uv build - name: Verify build succeeded run: | # Verify that build artifacts exist ls -la dist/ echo "Build completed successfully" - name: Create GitHub Release uses: softprops/action-gh-release@v3 with: files: | dist/*.whl dist/*.tar.gz generate_release_notes: true tag_name: ${{ github.ref_name }} token: ${{ secrets.GITHUB_TOKEN }} - name: Publish to PyPI uses: pypa/gh-action-pypi-publish@release/v1 with: password: ${{ secrets.PYPI_TOKEN }} openclaw: name: Publish OpenClaw npm Package needs: release # npm publishes only for stable product tags. Pre-release Python tags use # versions like 0.21.3b1, which are not valid npm pre-release semver. if: ${{ !contains(github.ref_name, 'dev') && !contains(github.ref_name, 'b') && !contains(github.ref_name, 'rc') }} runs-on: ubuntu-latest permissions: contents: read id-token: write defaults: run: working-directory: integrations/openclaw steps: - uses: actions/checkout@v6 - uses: extractions/setup-just@v4 - name: Setup Bun uses: oven-sh/setup-bun@v2 with: bun-version: "1.3.8" - name: Setup Node uses: actions/setup-node@v4 with: node-version: "24" registry-url: "https://registry.npmjs.org" - name: Install dependencies run: bun install --frozen-lockfile - name: Release readiness run: just release-check - name: Publish to npm run: npm publish --access public --provenance env: NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} homebrew: name: Update Homebrew Formula needs: release runs-on: ubuntu-latest # Only run for stable releases (not dev, beta, or rc versions) if: ${{ !contains(github.ref_name, 'dev') && !contains(github.ref_name, 'b') && !contains(github.ref_name, 'rc') }} permissions: contents: read steps: # Inline bump replaces mislav/bump-homebrew-formula-action@v4.x. # The action does a HEAD request to api.github.com /repos/.../tarball/ # with the bearer token and expects a 302 redirect. GitHub now returns # 303 on that endpoint when authenticated, which the action treats as a # fatal error. Re-implementing the bump as plain git+sed keeps the same # contract (update url + sha256, commit, push) with no third-party action. - name: Update Homebrew formula env: HOMEBREW_TOKEN: ${{ secrets.HOMEBREW_TOKEN }} REF: ${{ github.ref_name }} REPO: ${{ github.repository }} RUN_URL: https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }} run: | set -euo pipefail VERSION="${REF#v}" ARCHIVE_URL="https://github.com/${REPO}/archive/refs/tags/${REF}.tar.gz" echo "::group::Compute tarball sha256" SHA256="$(curl --fail --silent --location "$ARCHIVE_URL" | sha256sum | awk '{print $1}')" test -n "$SHA256" echo "sha256: $SHA256" echo "::endgroup::" echo "::group::Clone tap" git clone \ --depth 1 \ "https://x-access-token:${HOMEBREW_TOKEN}@github.com/basicmachines-co/homebrew-basic-memory.git" \ tap cd tap git config user.name "github-actions[bot]" git config user.email "41898282+github-actions[bot]@users.noreply.github.com" echo "::endgroup::" echo "::group::Patch Formula/basic-memory.rb" # Pipe-delimited sed because the URL contains slashes. The Formula # only has one `url` and one `sha256` directive, so a first-match # replacement is unambiguous. POSIX character classes ([[:space:]]) # keep this portable across BSD and GNU sed. sed -i -E \ -e "s|^([[:space:]]*url[[:space:]]+)\"[^\"]+\"|\1\"${ARCHIVE_URL}\"|" \ -e "s|^([[:space:]]*sha256[[:space:]]+)\"[^\"]+\"|\1\"${SHA256}\"|" \ Formula/basic-memory.rb git --no-pager diff Formula/basic-memory.rb echo "::endgroup::" if git diff --quiet Formula/basic-memory.rb; then echo "Formula already at ${REF}; nothing to do." exit 0 fi echo "::group::Commit & push" git add Formula/basic-memory.rb git commit -m "basic-memory ${VERSION} Created by ${RUN_URL}" git push origin HEAD:main echo "::endgroup::"