All checks were successful
check / check (push) Successful in 3m7s
No tag could be cut at all: .goreleaser.yaml had no gitea_urls block, so
goreleaser defaulted to the GitHub API, and the repo has zero tags.
.goreleaser.yaml now points at git.eeqj.de. Version derives from git via
a new script/version - exact tag with any leading v stripped, else
dev-<12-char sha>, with a -dirty suffix when tracked files are modified -
replacing the hardcoded 1.0.0-rc.1 that every local build was stamping
regardless of git state. A tag-triggered .gitea/workflows/release.yml
runs goreleaser with a scoped token (RELEASE_TOKEN); script/bootstrap
installs a sha256-verified goreleaser, and make release / release-snapshot
become script shims like every other target.
Two fabrications were removed rather than merely replaced. goreleaser's
snapshot.version_template was `{{ incpatch .Version }}-next`, which
invents a release number from the last tag - and with no tags, from
goreleaser's own fabricated v0.0.0. And internal/cli/version.go gated its
development-build notice on Version == "dev" exactly, so the moment
untagged builds carried a sha that notice would have gone silent and an
unreleased binary would have read as a release. Replaced with a tested
IsDevVersion predicate, and closed at both layers: the Makefile now
refuses to build when script/version yields nothing, and an empty version
counts as a development build - reachable today via
`docker build --build-arg VERSION=`.
The release workflow installs Go from a sha-pinned actions/setup-go
(v5.6.0) using go-version-file, so the compiler that produces released
binaries is pinned like every other external reference. Without it the
first tag push would either fail at goreleaser's before-hook or compile
the published artifacts with whatever unpinned Go the runner happened to
carry - the one unpinned thing in a release path that already refuses an
unpinned goreleaser.
Known gap: the Go tarball setup-go fetches is version-pinned but not
checksum-verified against a value in this repo, unlike the goreleaser
install and the Dockerfile digest.
70 lines
1.7 KiB
YAML
70 lines
1.7 KiB
YAML
version: 2
|
|
|
|
project_name: vaultik
|
|
|
|
# This repo lives on Gitea, not GitHub. Without this block goreleaser
|
|
# talks to the GitHub API by default and a `goreleaser release` either
|
|
# fails outright or publishes somewhere nobody is looking.
|
|
gitea_urls:
|
|
api: https://git.eeqj.de/api/v1
|
|
download: https://git.eeqj.de
|
|
|
|
before:
|
|
hooks:
|
|
- go mod tidy
|
|
|
|
builds:
|
|
- id: vaultik
|
|
main: ./cmd/vaultik
|
|
binary: vaultik
|
|
env:
|
|
- CGO_ENABLED=0
|
|
goos:
|
|
- linux
|
|
- darwin
|
|
goarch:
|
|
- amd64
|
|
- arm64
|
|
ldflags:
|
|
- -s -w
|
|
- -X 'sneak.berlin/go/vaultik/internal/globals.Version={{ .Version }}'
|
|
- -X 'sneak.berlin/go/vaultik/internal/globals.Commit={{ .Commit }}'
|
|
- -X 'sneak.berlin/go/vaultik/internal/globals.CommitDate={{ slice .CommitDate 0 10 }}'
|
|
|
|
archives:
|
|
- id: default
|
|
name_template: "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}"
|
|
formats:
|
|
- tar.gz
|
|
files:
|
|
- LICENSE
|
|
- README.md
|
|
|
|
checksum:
|
|
name_template: "checksums.txt"
|
|
algorithm: sha256
|
|
|
|
# A snapshot is not a release and must not name itself like one. The
|
|
# previous `{{ incpatch .Version }}-next` derived a plausible-looking
|
|
# release number from the last tag -- and with no tags in the repo at
|
|
# all, from goreleaser's fabricated v0.0.0. This produces the same
|
|
# string script/version produces for an untagged build, so a snapshot
|
|
# binary and a `make vaultik` binary of the same clean commit agree.
|
|
snapshot:
|
|
version_template: "dev-{{ slice .FullCommit 0 12 }}"
|
|
|
|
changelog:
|
|
sort: asc
|
|
use: git
|
|
filters:
|
|
exclude:
|
|
- "^docs:"
|
|
- "^test:"
|
|
- "^chore:"
|
|
- "Merge pull request"
|
|
- "Merge branch"
|
|
|
|
release:
|
|
draft: true
|
|
prerelease: auto
|