The top-level `permissions: contents: read` added alongside the zizmor hardening applies to the release job too, and Gitea honours it: the built-in gitea-actions token became read-only, so `tea releases create` failed with "user should have a permission to write to a repo" (run 759). The .github workflow already narrowed write to its release job; the Gitea workflow has a single job and was left read-only. Grant it contents: write, keeping the read-only default at the top level.
74 lines
2.3 KiB
YAML
74 lines
2.3 KiB
YAML
name: Release
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: cpu
|
|
timeout-minutes: 20
|
|
permissions:
|
|
contents: write
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Set up Go
|
|
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
|
|
with:
|
|
go-version: '1.25'
|
|
cache: false
|
|
|
|
- name: Build cross-platform binaries
|
|
run: |
|
|
set -euo pipefail
|
|
mkdir -p dist
|
|
build() {
|
|
os=$1
|
|
label=$2
|
|
goarch=$3
|
|
echo "building dist/shush-${os}-${label}"
|
|
CGO_ENABLED=0 GOOS="$os" GOARCH="$goarch" go build -ldflags="-w -s" -o "dist/shush-${os}-${label}" ./cmd/shush
|
|
}
|
|
build linux x86_64 amd64
|
|
build linux aarch64 arm64
|
|
build darwin x86_64 amd64
|
|
build darwin aarch64 arm64
|
|
ls -la dist
|
|
|
|
- name: Create Gitea release
|
|
env:
|
|
TAG: ${{ github.ref_name }}
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
if ! command -v tea >/dev/null 2>&1; then
|
|
echo "tea CLI not installed on runner; install from https://dl.gitea.com/tea/"
|
|
exit 1
|
|
fi
|
|
if [ -z "${TAG:-}" ]; then
|
|
echo "no tag ref; run this workflow from a v* tag"
|
|
exit 1
|
|
fi
|
|
tea login delete ci >/dev/null 2>&1 || true
|
|
tea login add --name ci --url https://git.mroberts.dev --token "$GITEA_TOKEN"
|
|
# Idempotent: drop any existing release for this tag so re-runs replace
|
|
# stale assets instead of failing with "already a release for this tag".
|
|
tea releases delete -y --login ci --repo mroberts/shush "$TAG" >/dev/null 2>&1 || true
|
|
tea releases create \
|
|
--login ci \
|
|
--repo mroberts/shush \
|
|
--tag "$TAG" \
|
|
--title "$TAG" \
|
|
--asset dist/shush-linux-x86_64 \
|
|
--asset dist/shush-linux-aarch64 \
|
|
--asset dist/shush-darwin-x86_64 \
|
|
--asset dist/shush-darwin-aarch64
|