Replace Drone CI with SHA-pinned Gitea Actions workflow
build / build and release (push) Has been cancelled
build / build and release (push) Has been cancelled
Ports the build-and-release pipeline from .drone.yml to .gitea/workflows/release.yaml. Same three amd64 targets, same release-on-tag trigger. Actions are pinned to full commit SHAs resolved from gitea.com, the runner's action resolution host. Its mirror of actions/checkout lags upstream, so the floating v4 tag there points at a different commit than github's; only immutable version tags agree across both hosts. checkout stays on v4 and setup-go on v5 because later majors require a Node 24 runtime that act_runner images do not generally ship. Hardening driven by zizmor: workflow-level permissions denied by default with contents:write scoped to the job that publishes the release, persist-credentials disabled so the token is not left in .git/config, and the Go module cache disabled so released binaries cannot be built from restorable cache state. Behaviour changes: - sha1 checksums dropped; gitea-release-action only emits md5 and sha256 - the gitea_public_releases secret is no longer read, as the action defaults to the runner-injected repo token - Go version now comes from go.mod rather than the floating golang image Also gitignores the usergen build output, which dist/* missed. Verified: go build, go vet and go test clean; all three cross-compile targets produce binaries; actionlint and zizmor --offline report no findings. The release step itself is unverified until a tag is pushed.
This commit is contained in:
-24
@@ -1,24 +0,0 @@
|
|||||||
kind: pipeline
|
|
||||||
name: default
|
|
||||||
|
|
||||||
steps:
|
|
||||||
- name: build
|
|
||||||
image: golang
|
|
||||||
commands:
|
|
||||||
- GOOS=windows GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-windows.exe
|
|
||||||
- GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-linux
|
|
||||||
- GOOS=darwin GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-darwin
|
|
||||||
|
|
||||||
- name: create_release
|
|
||||||
image: plugins/gitea-release
|
|
||||||
settings:
|
|
||||||
api_key:
|
|
||||||
from_secret: gitea_public_releases
|
|
||||||
base_url: https://git.mroberts.dev/
|
|
||||||
files: dist/*
|
|
||||||
checksum:
|
|
||||||
- sha256
|
|
||||||
- md5
|
|
||||||
- sha1
|
|
||||||
when:
|
|
||||||
event: tag
|
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
name: build
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
tags: ['*']
|
||||||
|
|
||||||
|
permissions: {}
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
name: build and release
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
|
||||||
|
with:
|
||||||
|
persist-credentials: false
|
||||||
|
|
||||||
|
- uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
|
||||||
|
with:
|
||||||
|
go-version-file: go.mod
|
||||||
|
cache: false
|
||||||
|
|
||||||
|
- name: build
|
||||||
|
run: |
|
||||||
|
GOOS=windows GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-windows.exe
|
||||||
|
GOOS=linux GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-linux
|
||||||
|
GOOS=darwin GOARCH=amd64 go build -ldflags="-s -w" -o dist/usergen-amd64-darwin
|
||||||
|
|
||||||
|
- name: create_release
|
||||||
|
if: startsWith(github.ref, 'refs/tags/')
|
||||||
|
uses: actions/gitea-release-action@b8d9144f302c68610911db1aaf722708d5c02d94 # v1.3.6
|
||||||
|
with:
|
||||||
|
files: dist/*
|
||||||
|
md5sum: true
|
||||||
|
sha256sum: true
|
||||||
+4
-1
@@ -19,4 +19,7 @@
|
|||||||
|
|
||||||
# Go workspace file
|
# Go workspace file
|
||||||
go.work
|
go.work
|
||||||
dist/*
|
dist/*
|
||||||
|
|
||||||
|
# Local build output
|
||||||
|
usergen
|
||||||
Reference in New Issue
Block a user