From de5146d25a5d99339cf1c4df32986a196a5bf8a5 Mon Sep 17 00:00:00 2001 From: Simon Nordberg Date: Mon, 14 Sep 2026 11:43:55 +0200 Subject: [PATCH 1/3] ci: enable GitHub releases on tag push Goreleaser now creates a GitHub release with binaries, checksums, and GPG signatures attached. S3 upload continues as before. - .goreleaser.yaml: replace disable:true with draft:false, prerelease:auto - release.yml: drop --skip=publish, upgrade to contents:write --- .github/workflows/release.yml | 8 +++++--- .goreleaser.yaml | 3 ++- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index a720969..8ccb959 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,7 +6,7 @@ on: - "v*" permissions: - contents: read + contents: write jobs: test: @@ -38,10 +38,12 @@ jobs: env: GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }} - - name: Build + - name: Build and release uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 with: - args: release --clean --skip=publish + args: release --clean + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Upload to S3 run: ./scripts/upload-release.sh "${{ github.ref_name }}" diff --git a/.goreleaser.yaml b/.goreleaser.yaml index 0227d14..a24b512 100644 --- a/.goreleaser.yaml +++ b/.goreleaser.yaml @@ -47,4 +47,5 @@ signs: signature: "${artifact}.asc" release: - disable: true + draft: false + prerelease: auto From 6f410f6efc3f650eb4255dca60b4faebbcc4ec52 Mon Sep 17 00:00:00 2001 From: Simon Nordberg Date: Mon, 14 Sep 2026 11:46:05 +0200 Subject: [PATCH 2/3] ci: switch release to workflow_dispatch Resolves the latest v* tag at dispatch time instead of triggering on tag push. Goreleaser and S3 upload both use the resolved tag. --- .github/workflows/release.yml | 33 ++++++++++++++++++++++++++++----- 1 file changed, 28 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8ccb959..531a41a 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,18 +1,39 @@ name: Release on: - push: - tags: - - "v*" + workflow_dispatch: permissions: contents: write jobs: + resolve-tag: + runs-on: ubuntu-latest + outputs: + tag: ${{ steps.tag.outputs.tag }} + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + fetch-depth: 0 + + - name: Find latest v* tag + id: tag + run: | + TAG=$(git tag --list 'v*' --sort=-v:refname | head -1) + if [ -z "$TAG" ]; then + echo "::error::No v* tag found" + exit 1 + fi + echo "tag=$TAG" >> "$GITHUB_OUTPUT" + echo "Releasing $TAG" + test: + needs: resolve-tag runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + ref: ${{ needs.resolve-tag.outputs.tag }} - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: @@ -22,11 +43,12 @@ jobs: run: go test -race ./... release: - needs: test + needs: [resolve-tag, test] runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: + ref: ${{ needs.resolve-tag.outputs.tag }} fetch-depth: 0 - uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 @@ -44,9 +66,10 @@ jobs: args: release --clean env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GORELEASER_CURRENT_TAG: ${{ needs.resolve-tag.outputs.tag }} - name: Upload to S3 - run: ./scripts/upload-release.sh "${{ github.ref_name }}" + run: ./scripts/upload-release.sh "${{ needs.resolve-tag.outputs.tag }}" env: AWS_ACCESS_KEY_ID: ${{ secrets.SCW_ACCESS_KEY }} AWS_SECRET_ACCESS_KEY: ${{ secrets.SCW_SECRET_KEY }} From 1686d59c18dac72d751477bd849db97de74555d9 Mon Sep 17 00:00:00 2001 From: Simon Nordberg Date: Mon, 14 Sep 2026 11:47:28 +0200 Subject: [PATCH 3/3] ci: add MCP registry publish to release workflow Runs in parallel with the binary release job. Uses OIDC auth, updates server.json version from the resolved tag. --- .github/workflows/release.yml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 531a41a..adaa35b 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -5,6 +5,7 @@ on: permissions: contents: write + id-token: write jobs: resolve-tag: @@ -74,3 +75,30 @@ jobs: AWS_ACCESS_KEY_ID: ${{ secrets.SCW_ACCESS_KEY }} AWS_SECRET_ACCESS_KEY: ${{ secrets.SCW_SECRET_KEY }} AWS_DEFAULT_REGION: fr-par + + mcp-registry: + needs: [resolve-tag, test] + runs-on: ubuntu-latest + permissions: + contents: read + id-token: write + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + ref: ${{ needs.resolve-tag.outputs.tag }} + + - name: Set version from tag + run: | + VERSION=${{ needs.resolve-tag.outputs.tag }} + VERSION=${VERSION#v} + jq --arg v "$VERSION" '.version = $v' server.json > server.tmp && mv server.tmp server.json + + - name: Install mcp-publisher + run: | + curl -L "https://github.com/modelcontextprotocol/registry/releases/latest/download/mcp-publisher_linux_amd64.tar.gz" | tar xz mcp-publisher + + - name: Authenticate to MCP Registry + run: ./mcp-publisher login github-oidc + + - name: Publish to MCP Registry + run: ./mcp-publisher publish