Target the self-hosted runner label and harden the workflow
build / build (push) Failing after 3m38s
build / build (push) Failing after 3m38s
ubuntu-latest matches no runner on this forge, so both the main push and the v1.0.0 tag queued nothing at all. The runner is labelled linux. actions/checkout is pinned to a commit rather than a tag, and to v4.4.0 rather than the current v7.0.1: v7 declares node24, which act_runner does not provide. regctl moves out of /usr/local/bin, which a self-hosted runner cannot write to without sudo, and is pinned to a release rather than tracking latest. Clean under actionlint and zizmor --persona=auditor. Every expansion moves into env so nothing interpolates into a shell body. secrets-outside-env is suppressed deliberately: Gitea has no deployment environment protection rules, so a dedicated environment would add ceremony without a security boundary.
This commit is contained in:
@@ -11,16 +11,18 @@ env:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
build:
|
build:
|
||||||
runs-on: ubuntu-latest
|
runs-on: linux
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
- name: Install regctl
|
- name: Install regctl
|
||||||
run: |
|
run: |
|
||||||
curl -fsSL -o /usr/local/bin/regctl \
|
mkdir -p "$HOME/.local/bin"
|
||||||
|
curl -fsSL -o "$HOME/.local/bin/regctl" \
|
||||||
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
|
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
|
||||||
chmod +x /usr/local/bin/regctl
|
chmod +x "$HOME/.local/bin/regctl"
|
||||||
|
printf '%s\n' "$HOME/.local/bin" >>"$GITHUB_PATH"
|
||||||
|
|
||||||
- name: Resolve tag
|
- name: Resolve tag
|
||||||
id: tag
|
id: tag
|
||||||
|
|||||||
Reference in New Issue
Block a user