forked from pyca/cryptography
-
Notifications
You must be signed in to change notification settings - Fork 1
/
release.py
139 lines (117 loc) · 4 KB
/
release.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
# This file is dual licensed under the terms of the Apache License, Version
# 2.0, and the BSD License. See the LICENSE file in the root of this repository
# for complete details.
import getpass
import glob
import io
import os
import subprocess
import time
import zipfile
import click
import requests
def run(*args, **kwargs):
print("[running] {0}".format(list(args)))
subprocess.check_call(list(args), **kwargs)
def wait_for_build_complete_github_actions(session, token, run_url):
while True:
response = session.get(
run_url,
headers={
"Content-Type": "application/json",
"Authorization": "token {}".format(token),
},
)
response.raise_for_status()
if response.json()["conclusion"] is not None:
break
time.sleep(3)
def download_artifacts_github_actions(session, token, run_url):
response = session.get(
run_url,
headers={
"Content-Type": "application/json",
"Authorization": "token {}".format(token),
},
)
response.raise_for_status()
response = session.get(
response.json()["artifacts_url"],
headers={
"Content-Type": "application/json",
"Authorization": "token {}".format(token),
},
)
response.raise_for_status()
paths = []
for artifact in response.json()["artifacts"]:
response = session.get(
artifact["archive_download_url"],
headers={
"Content-Type": "application/json",
"Authorization": "token {}".format(token),
},
)
with zipfile.ZipFile(io.BytesIO(response.content)) as z:
for name in z.namelist():
if not name.endswith(".whl"):
continue
p = z.open(name)
out_path = os.path.join(
os.path.dirname(__file__),
"dist",
os.path.basename(name),
)
with open(out_path, "wb") as f:
f.write(p.read())
paths.append(out_path)
return paths
def fetch_github_actions_wheels(token, version):
session = requests.Session()
response = session.get(
(
"https://api.github.com/repos/pyca/cryptography/actions/workflows/"
"wheel-builder.yml/runs?event=push"
),
headers={
"Content-Type": "application/json",
"Authorization": "token {}".format(token),
},
)
response.raise_for_status()
run_url = response.json()["workflow_runs"][0]["url"]
wait_for_build_complete_github_actions(session, token, run_url)
return download_artifacts_github_actions(session, token, run_url)
@click.command()
@click.argument("version")
def release(version):
"""
``version`` should be a string like '0.4' or '1.0'.
"""
print(
f"Create a new GH PAT at: "
f"https://github.com/settings/tokens/new?"
f"description={version}&scopes=repo"
)
github_token = getpass.getpass("Github person access token: ")
# Tag and push the tag (this will trigger the wheel builder in Actions)
run("git", "tag", "-s", version, "-m", "{0} release".format(version))
run("git", "push", "--tags")
# Generate and upload vector packages
run("python", "setup.py", "sdist", "bdist_wheel", cwd="vectors/")
packages = glob.glob(
"vectors/dist/cryptography_vectors-{0}*".format(version)
)
run("twine", "upload", "-s", *packages)
# Generate sdist for upload
run("python", "setup.py", "sdist")
sdist = glob.glob("dist/cryptography-{0}*".format(version))
# Wait for Actions to complete and download the wheels
github_actions_wheel_paths = fetch_github_actions_wheels(
github_token, version
)
# Upload wheels and sdist
run("twine", "upload", *github_actions_wheel_paths)
run("twine", "upload", "-s", *sdist)
if __name__ == "__main__":
release()