Target the self-hosted runner label and harden the workflow
build / build (push) Failing after 3m38s

ubuntu-latest matches no runner on this forge, so both the main push and the
v1.0.0 tag queued nothing at all. The runner is labelled linux.

actions/checkout is pinned to a commit rather than a tag, and to v4.4.0 rather
than the current v7.0.1: v7 declares node24, which act_runner does not provide.
regctl moves out of /usr/local/bin, which a self-hosted runner cannot write to
without sudo, and is pinned to a release rather than tracking latest.

Clean under actionlint and zizmor --persona=auditor. Every expansion moves into
env so nothing interpolates into a shell body. secrets-outside-env is suppressed
deliberately: Gitea has no deployment environment protection rules, so a
dedicated environment would add ceremony without a security boundary.
This commit is contained in:
2026-07-31 08:25:20 -05:00
parent c89e4f0568
commit b79bf35e70
+5 -3
View File
@@ -11,16 +11,18 @@ env:
jobs:
build:
runs-on: ubuntu-latest
runs-on: linux
steps:
- uses: actions/checkout@v4
- name: Install regctl
run: |
curl -fsSL -o /usr/local/bin/regctl \
mkdir -p "$HOME/.local/bin"
curl -fsSL -o "$HOME/.local/bin/regctl" \
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
chmod +x /usr/local/bin/regctl
chmod +x "$HOME/.local/bin/regctl"
printf '%s\n' "$HOME/.local/bin" >>"$GITHUB_PATH"
- name: Resolve tag
id: tag