Files
usergen/.gitea/workflows/release.yaml
T
mroberts a829aa774f
build / build and release (push) Has been cancelled
Replace Drone CI with SHA-pinned Gitea Actions workflow
Ports the build-and-release pipeline from .drone.yml to
.gitea/workflows/release.yaml. Same three amd64 targets, same
release-on-tag trigger.

Actions are pinned to full commit SHAs resolved from gitea.com, the
runner's action resolution host. Its mirror of actions/checkout lags
upstream, so the floating v4 tag there points at a different commit than
github's; only immutable version tags agree across both hosts.

checkout stays on v4 and setup-go on v5 because later majors require a
Node 24 runtime that act_runner images do not generally ship.

Hardening driven by zizmor: workflow-level permissions denied by
default with contents:write scoped to the job that publishes the
release, persist-credentials disabled so the token is not left in
.git/config, and the Go module cache disabled so released binaries
cannot be built from restorable cache state.

Behaviour changes:
- sha1 checksums dropped; gitea-release-action only emits md5 and sha256
- the gitea_public_releases secret is no longer read, as the action
  defaults to the runner-injected repo token
- Go version now comes from go.mod rather than the floating golang image

Also gitignores the usergen build output, which dist/* missed.

Verified: go build, go vet and go test clean; all three cross-compile
targets produce binaries; actionlint and zizmor --offline report no
findings. The release step itself is unverified until a tag is pushed.
2026-07-20 15:04:52 -05:00

43 lines
1.1 KiB
YAML

name: build
on:
push:
branches: [main]
tags: ['*']
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
build:
name: build and release
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
persist-credentials: false
- uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
with:
go-version-file: go.mod
cache: false
- name: build
run: |
GOOS=windows GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-windows.exe
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-linux
GOOS=darwin GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-darwin
- name: create_release
if: startsWith(github.ref, 'refs/tags/')
uses: actions/gitea-release-action@b8d9144f302c68610911db1aaf722708d5c02d94 # v1.3.6
with:
files: dist/*
md5sum: true
sha256sum: true