Pins every action to the latest release SHA within its current major, so no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0, upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2. Adds a `workflows` CI job running actionlint and zizmor. actionlint comes from `go install` (module proxy checksums cover integrity); zizmor has no published checksums, so its release tarball is pinned by version and verified against a recorded sha256. The gate uses --min-severity=low, which fails on low and above while tolerating the one informational superfluous-actions advisory. zizmor only collects from .github/workflows: pointing it at .gitea/workflows yields "no inputs collected", and when both directories are passed it audits only .github and still exits 0. The gate therefore passes explicit *.yml paths, which is the only form that actually audits the Gitea workflows. Auditing them for the first time surfaced seven findings, now fixed: credential persistence on checkout (persist-credentials: false), setup-go caching on the release path (cache: false), and missing top-level permissions (contents: read, with contents: write narrowed to the GitHub release job that needs it).
72 lines
2.2 KiB
YAML
72 lines
2.2 KiB
YAML
name: Release
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: cpu
|
|
timeout-minutes: 20
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Set up Go
|
|
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
|
|
with:
|
|
go-version: '1.25'
|
|
cache: false
|
|
|
|
- name: Build cross-platform binaries
|
|
run: |
|
|
set -euo pipefail
|
|
mkdir -p dist
|
|
build() {
|
|
os=$1
|
|
label=$2
|
|
goarch=$3
|
|
echo "building dist/shush-${os}-${label}"
|
|
CGO_ENABLED=0 GOOS="$os" GOARCH="$goarch" go build -ldflags="-w -s" -o "dist/shush-${os}-${label}" ./cmd/shush
|
|
}
|
|
build linux x86_64 amd64
|
|
build linux aarch64 arm64
|
|
build darwin x86_64 amd64
|
|
build darwin aarch64 arm64
|
|
ls -la dist
|
|
|
|
- name: Create Gitea release
|
|
env:
|
|
TAG: ${{ github.ref_name }}
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
if ! command -v tea >/dev/null 2>&1; then
|
|
echo "tea CLI not installed on runner; install from https://dl.gitea.com/tea/"
|
|
exit 1
|
|
fi
|
|
if [ -z "${TAG:-}" ]; then
|
|
echo "no tag ref; run this workflow from a v* tag"
|
|
exit 1
|
|
fi
|
|
tea login delete ci >/dev/null 2>&1 || true
|
|
tea login add --name ci --url https://git.mroberts.dev --token "$GITEA_TOKEN"
|
|
# Idempotent: drop any existing release for this tag so re-runs replace
|
|
# stale assets instead of failing with "already a release for this tag".
|
|
tea releases delete -y --login ci --repo mroberts/shush "$TAG" >/dev/null 2>&1 || true
|
|
tea releases create \
|
|
--login ci \
|
|
--repo mroberts/shush \
|
|
--tag "$TAG" \
|
|
--title "$TAG" \
|
|
--asset dist/shush-linux-x86_64 \
|
|
--asset dist/shush-linux-aarch64 \
|
|
--asset dist/shush-darwin-x86_64 \
|
|
--asset dist/shush-darwin-aarch64
|