Files
shush/.gitea/workflows/release.yml
T
mroberts 250b3e98ca
CI / build (push) Successful in 49s
CI / workflows (push) Successful in 16s
Release / release (push) Failing after 19s
ci: pin actions to SHAs and gate workflows on actionlint + zizmor
Pins every action to the latest release SHA within its current major, so
no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0,
upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2.

Adds a `workflows` CI job running actionlint and zizmor. actionlint comes
from `go install` (module proxy checksums cover integrity); zizmor has no
published checksums, so its release tarball is pinned by version and
verified against a recorded sha256. The gate uses --min-severity=low, which
fails on low and above while tolerating the one informational
superfluous-actions advisory.

zizmor only collects from .github/workflows: pointing it at .gitea/workflows
yields "no inputs collected", and when both directories are passed it audits
only .github and still exits 0. The gate therefore passes explicit *.yml
paths, which is the only form that actually audits the Gitea workflows.

Auditing them for the first time surfaced seven findings, now fixed:
credential persistence on checkout (persist-credentials: false), setup-go
caching on the release path (cache: false), and missing top-level
permissions (contents: read, with contents: write narrowed to the GitHub
release job that needs it).
2026-07-21 15:16:55 -05:00

72 lines
2.2 KiB
YAML

name: Release
permissions:
contents: read
on:
push:
tags: ['v*']
workflow_dispatch:
jobs:
release:
runs-on: cpu
timeout-minutes: 20
steps:
- name: Checkout
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: '1.25'
cache: false
- name: Build cross-platform binaries
run: |
set -euo pipefail
mkdir -p dist
build() {
os=$1
label=$2
goarch=$3
echo "building dist/shush-${os}-${label}"
CGO_ENABLED=0 GOOS="$os" GOARCH="$goarch" go build -ldflags="-w -s" -o "dist/shush-${os}-${label}" ./cmd/shush
}
build linux x86_64 amd64
build linux aarch64 arm64
build darwin x86_64 amd64
build darwin aarch64 arm64
ls -la dist
- name: Create Gitea release
env:
TAG: ${{ github.ref_name }}
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
run: |
set -euo pipefail
if ! command -v tea >/dev/null 2>&1; then
echo "tea CLI not installed on runner; install from https://dl.gitea.com/tea/"
exit 1
fi
if [ -z "${TAG:-}" ]; then
echo "no tag ref; run this workflow from a v* tag"
exit 1
fi
tea login delete ci >/dev/null 2>&1 || true
tea login add --name ci --url https://git.mroberts.dev --token "$GITEA_TOKEN"
# Idempotent: drop any existing release for this tag so re-runs replace
# stale assets instead of failing with "already a release for this tag".
tea releases delete -y --login ci --repo mroberts/shush "$TAG" >/dev/null 2>&1 || true
tea releases create \
--login ci \
--repo mroberts/shush \
--tag "$TAG" \
--title "$TAG" \
--asset dist/shush-linux-x86_64 \
--asset dist/shush-linux-aarch64 \
--asset dist/shush-darwin-x86_64 \
--asset dist/shush-darwin-aarch64