Files
shush/.gitea/workflows/release.yml
T
mroberts 57e25f86f2
CI / build (push) Successful in 10s
CI / workflows (push) Successful in 9s
Release / release (push) Successful in 20s
fix(ci): grant contents:write to the Gitea release job
The top-level `permissions: contents: read` added alongside the zizmor
hardening applies to the release job too, and Gitea honours it: the built-in
gitea-actions token became read-only, so `tea releases create` failed with
"user should have a permission to write to a repo" (run 759).

The .github workflow already narrowed write to its release job; the Gitea
workflow has a single job and was left read-only. Grant it contents: write,
keeping the read-only default at the top level.
2026-07-21 15:23:29 -05:00

74 lines
2.3 KiB
YAML

name: Release
permissions:
contents: read
on:
push:
tags: ['v*']
workflow_dispatch:
jobs:
release:
runs-on: cpu
timeout-minutes: 20
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
persist-credentials: false
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: '1.25'
cache: false
- name: Build cross-platform binaries
run: |
set -euo pipefail
mkdir -p dist
build() {
os=$1
label=$2
goarch=$3
echo "building dist/shush-${os}-${label}"
CGO_ENABLED=0 GOOS="$os" GOARCH="$goarch" go build -ldflags="-w -s" -o "dist/shush-${os}-${label}" ./cmd/shush
}
build linux x86_64 amd64
build linux aarch64 arm64
build darwin x86_64 amd64
build darwin aarch64 arm64
ls -la dist
- name: Create Gitea release
env:
TAG: ${{ github.ref_name }}
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
run: |
set -euo pipefail
if ! command -v tea >/dev/null 2>&1; then
echo "tea CLI not installed on runner; install from https://dl.gitea.com/tea/"
exit 1
fi
if [ -z "${TAG:-}" ]; then
echo "no tag ref; run this workflow from a v* tag"
exit 1
fi
tea login delete ci >/dev/null 2>&1 || true
tea login add --name ci --url https://git.mroberts.dev --token "$GITEA_TOKEN"
# Idempotent: drop any existing release for this tag so re-runs replace
# stale assets instead of failing with "already a release for this tag".
tea releases delete -y --login ci --repo mroberts/shush "$TAG" >/dev/null 2>&1 || true
tea releases create \
--login ci \
--repo mroberts/shush \
--tag "$TAG" \
--title "$TAG" \
--asset dist/shush-linux-x86_64 \
--asset dist/shush-linux-aarch64 \
--asset dist/shush-darwin-x86_64 \
--asset dist/shush-darwin-aarch64