Ports the build-and-release pipeline from .drone.yml to
.gitea/workflows/release.yaml. Same three amd64 targets, same
release-on-tag trigger.
Actions are pinned to full commit SHAs resolved from gitea.com, the
runner's action resolution host. Its mirror of actions/checkout lags
upstream, so the floating v4 tag there points at a different commit than
github's; only immutable version tags agree across both hosts.
checkout stays on v4 and setup-go on v5 because later majors require a
Node 24 runtime that act_runner images do not generally ship.
Hardening driven by zizmor: workflow-level permissions denied by
default with contents:write scoped to the job that publishes the
release, persist-credentials disabled so the token is not left in
.git/config, and the Go module cache disabled so released binaries
cannot be built from restorable cache state.
Behaviour changes:
- sha1 checksums dropped; gitea-release-action only emits md5 and sha256
- the gitea_public_releases secret is no longer read, as the action
defaults to the runner-injected repo token
- Go version now comes from go.mod rather than the floating golang image
Also gitignores the usergen build output, which dist/* missed.
Verified: go build, go vet and go test clean; all three cross-compile
targets produce binaries; actionlint and zizmor --offline report no
findings. The release step itself is unverified until a tag is pushed.