Skip to content

feat: harden AWS integration security and deployment evidence #22

feat: harden AWS integration security and deployment evidence

feat: harden AWS integration security and deployment evidence #22

Workflow file for this run

name: Release
on:
push:
tags:
- "v*.*.*"
pull_request:
paths:
- ".github/workflows/release.yml"
- "pyproject.toml"
- "CHANGELOG.md"
- "RELEASE_NOTES_*.md"
workflow_dispatch:
inputs:
tag:
description: "Existing semantic-version tag to validate"
required: true
type: string
permissions:
contents: read
jobs:
verify:
name: Verify release candidate
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
ref: ${{ github.event_name == 'workflow_dispatch' && format('refs/tags/{0}', inputs.tag) || github.ref }}
- uses: actions/setup-python@v5
with:
python-version: "3.11"
cache: pip
cache-dependency-path: |
requirements.txt
requirements-dev.txt
pyproject.toml
- name: Validate version and release notes
if: startsWith(github.ref, 'refs/tags/') || github.event_name == 'workflow_dispatch'
shell: bash
run: |
tag="${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref_name }}"
[[ "$tag" =~ ^v[0-9]+\.[0-9]+\.[0-9]+$ ]]
version="${tag#v}"
RELEASE_VERSION="$version" python - <<'PY'
import os
from pathlib import Path
import tomllib
version = os.environ["RELEASE_VERSION"]
project = tomllib.loads(Path("pyproject.toml").read_text(encoding="utf-8"))
assert project["project"]["version"] == version
assert Path(f"RELEASE_NOTES_{version}.md").is_file()
assert f"## [{version}]" in Path("CHANGELOG.md").read_text(encoding="utf-8")
PY
- name: Install release dependencies
run: |
python -m pip install --upgrade pip
python -m pip install -r requirements.txt -r requirements-dev.txt build
- name: Run quality gates
run: |
black --diff --check . --line-length=100
ruff check .
mypy models.py utils.py event_bus.py location_store.py matching_engine.py pricing_engine.py consumer.py --ignore-missing-imports
pytest
python benchmarks/ride_sharing_benchmarks.py --iterations 250 --driver-count 100 --output benchmark-results.json
python -m json.tool benchmark-results.json > /dev/null
- name: Build Python distributions
run: python -m build
- name: Build application image
run: docker build --tag ride-sharing-platform:${{ github.sha }} .
- name: Create release checksums
run: sha256sum dist/* > SHA256SUMS.txt
- name: Generate SPDX SBOM
uses: anchore/sbom-action@v0
with:
path: .
format: spdx-json
output-file: sbom.spdx.json
- uses: actions/upload-artifact@v4
with:
name: release-assets
path: |
dist/*
SHA256SUMS.txt
sbom.spdx.json
publish-release:
name: Publish GitHub Release
if: startsWith(github.ref, 'refs/tags/v')
needs: verify
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
with:
name: release-assets
path: release-assets
- id: notes
shell: bash
run: echo "path=RELEASE_NOTES_${GITHUB_REF_NAME#v}.md" >> "$GITHUB_OUTPUT"
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
with:
body_path: ${{ steps.notes.outputs.path }}
generate_release_notes: false
files: release-assets/*
publish-container:
name: Publish release container to GHCR
if: startsWith(github.ref, 'refs/tags/v')
needs: verify
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- id: metadata
uses: docker/metadata-action@v5
with:
images: ghcr.io/coreyleath-code/ride-sharing-platform
tags: |
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
type=raw,value=latest
- uses: docker/build-push-action@v6
with:
context: .
push: true
tags: ${{ steps.metadata.outputs.tags }}
labels: ${{ steps.metadata.outputs.labels }}