Commit Graph
7 Commits
Author SHA1 Message Date
mroberts 57e25f86f2 fix(ci): grant contents:write to the Gitea release job
CI / build (push) Successful in 10s
CI / workflows (push) Successful in 9s
Release / release (push) Successful in 20s
The top-level `permissions: contents: read` added alongside the zizmor
hardening applies to the release job too, and Gitea honours it: the built-in
gitea-actions token became read-only, so `tea releases create` failed with
"user should have a permission to write to a repo" (run 759).

The .github workflow already narrowed write to its release job; the Gitea
workflow has a single job and was left read-only. Grant it contents: write,
keeping the read-only default at the top level.
2026-07-21 15:23:29 -05:00
mroberts 250b3e98ca ci: pin actions to SHAs and gate workflows on actionlint + zizmor
CI / build (push) Successful in 49s
CI / workflows (push) Successful in 16s
Release / release (push) Failing after 19s
Pins every action to the latest release SHA within its current major, so
no untested major bump rides along: checkout v4.4.0, setup-go v5.6.0,
upload-artifact v4.6.2, download-artifact v4.3.0, action-gh-release v2.6.2.

Adds a `workflows` CI job running actionlint and zizmor. actionlint comes
from `go install` (module proxy checksums cover integrity); zizmor has no
published checksums, so its release tarball is pinned by version and
verified against a recorded sha256. The gate uses --min-severity=low, which
fails on low and above while tolerating the one informational
superfluous-actions advisory.

zizmor only collects from .github/workflows: pointing it at .gitea/workflows
yields "no inputs collected", and when both directories are passed it audits
only .github and still exits 0. The gate therefore passes explicit *.yml
paths, which is the only form that actually audits the Gitea workflows.

Auditing them for the first time surfaced seven findings, now fixed:
credential persistence on checkout (persist-credentials: false), setup-go
caching on the release path (cache: false), and missing top-level
permissions (contents: read, with contents: write narrowed to the GitHub
release job that needs it).
2026-07-21 15:16:55 -05:00
mroberts 5b101bc6dd ci(release): fix Gitea repo slug; bump to 0.6.2
CI / build (push) Successful in 59s
The release workflow targeted mroberts/sush, which does not exist
(`tea releases list --repo mroberts/sush` returns "not found"), so the
release step would fail after building the binaries. Present since the
workflow was added in a7a561f.

Also bump softprops/action-gh-release to v2 in the unused .github
workflow; actionlint rejects v1 as too old to run.
2026-07-21 15:07:46 -05:00
mroberts 33b1b2370b ci(release): make release idempotent; bump to 0.6.1
CI / build (push) Successful in 1m34s
tea releases create fails if a release already exists, leaving stale
binaries on tag re-push. Delete any existing release for the tag first
so re-runs self-heal.
2026-07-17 12:54:00 -05:00
mroberts 80e93e9e15 ci: make tea login idempotent (delete stale login before add) 2026-07-03 09:23:37 -05:00
mroberts a7a561fbbd ci: add Gitea release workflow using tea CLI 2026-07-02 09:20:06 -05:00
mroberts 41a491564f ci: add Gitea Actions build/test workflow 2026-07-02 09:20:06 -05:00