diff --git a/.github/workflows/cd.yml b/.github/workflows/cd.yml new file mode 100644 index 0000000..57a2a16 --- /dev/null +++ b/.github/workflows/cd.yml @@ -0,0 +1,14 @@ +name: CD + +on: # zizmor: ignore[dangerous-triggers] deploy-after-CI-passes is the standard rubyatscale release pattern; the called workflow only tags/publishes on main + workflow_run: + workflows: [CI] + types: [completed] + branches: [main] + +jobs: + call-workflow-from-shared-config: + permissions: + contents: write + uses: rubyatscale/shared-config/.github/workflows/cd.yml@main # zizmor: ignore[unpinned-uses,secrets-inherit] internal reusable workflow tracked at @main by convention so shared-config updates propagate automatically; environments are managed by callers + secrets: inherit diff --git a/.github/workflows/push_gem.yml b/.github/workflows/push_gem.yml deleted file mode 100644 index 06864c5..0000000 --- a/.github/workflows/push_gem.yml +++ /dev/null @@ -1,32 +0,0 @@ -name: Publish to Rubygems -on: - push: - branches: - - "main" - tags: - - v* - -jobs: - push: - name: Push gem to RubyGems.org - runs-on: ubuntu-latest - - permissions: - id-token: write # IMPORTANT: this permission is mandatory for trusted publishing - contents: write # IMPORTANT: this permission is required for `rake release` to push the release tag - - steps: - # Set up - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Ruby - uses: ruby/setup-ruby@14594264cd68ce8a2345dd349bc3d138a4ef85c8 # v1.327.0 - with: - ruby-version: ruby - # Not bundler-cache: a tag-triggered release shouldn't restore a cache other workflows can write. - - name: Install gems - run: bundle install - - # Release - - uses: rubygems/release-gem@7f9650160c1a4e7989fdc9855807bdbd421d8b6b # v1.4.1