Target the self-hosted runner label and harden the workflow
build / build (push) Failing after 3m38s
build / build (push) Failing after 3m38s
ubuntu-latest matches no runner on this forge, so both the main push and the v1.0.0 tag queued nothing at all. The runner is labelled linux. actions/checkout is pinned to a commit rather than a tag, and to v4.4.0 rather than the current v7.0.1: v7 declares node24, which act_runner does not provide. regctl moves out of /usr/local/bin, which a self-hosted runner cannot write to without sudo, and is pinned to a release rather than tracking latest. Clean under actionlint and zizmor --persona=auditor. Every expansion moves into env so nothing interpolates into a shell body. secrets-outside-env is suppressed deliberately: Gitea has no deployment environment protection rules, so a dedicated environment would add ceremony without a security boundary.
This commit is contained in:
@@ -11,16 +11,18 @@ env:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
runs-on: linux
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Install regctl
|
||||
run: |
|
||||
curl -fsSL -o /usr/local/bin/regctl \
|
||||
mkdir -p "$HOME/.local/bin"
|
||||
curl -fsSL -o "$HOME/.local/bin/regctl" \
|
||||
https://github.com/regclient/regclient/releases/latest/download/regctl-linux-amd64
|
||||
chmod +x /usr/local/bin/regctl
|
||||
chmod +x "$HOME/.local/bin/regctl"
|
||||
printf '%s\n' "$HOME/.local/bin" >>"$GITHUB_PATH"
|
||||
|
||||
- name: Resolve tag
|
||||
id: tag
|
||||
|
||||
Reference in New Issue
Block a user