All checks were successful
check / check (push) Successful in 3m7s
No tag could be cut at all: .goreleaser.yaml had no gitea_urls block, so
goreleaser defaulted to the GitHub API, and the repo has zero tags.
.goreleaser.yaml now points at git.eeqj.de. Version derives from git via
a new script/version - exact tag with any leading v stripped, else
dev-<12-char sha>, with a -dirty suffix when tracked files are modified -
replacing the hardcoded 1.0.0-rc.1 that every local build was stamping
regardless of git state. A tag-triggered .gitea/workflows/release.yml
runs goreleaser with a scoped token (RELEASE_TOKEN); script/bootstrap
installs a sha256-verified goreleaser, and make release / release-snapshot
become script shims like every other target.
Two fabrications were removed rather than merely replaced. goreleaser's
snapshot.version_template was `{{ incpatch .Version }}-next`, which
invents a release number from the last tag - and with no tags, from
goreleaser's own fabricated v0.0.0. And internal/cli/version.go gated its
development-build notice on Version == "dev" exactly, so the moment
untagged builds carried a sha that notice would have gone silent and an
unreleased binary would have read as a release. Replaced with a tested
IsDevVersion predicate, and closed at both layers: the Makefile now
refuses to build when script/version yields nothing, and an empty version
counts as a development build - reachable today via
`docker build --build-arg VERSION=`.
The release workflow installs Go from a sha-pinned actions/setup-go
(v5.6.0) using go-version-file, so the compiler that produces released
binaries is pinned like every other external reference. Without it the
first tag push would either fail at goreleaser's before-hook or compile
the published artifacts with whatever unpinned Go the runner happened to
carry - the one unpinned thing in a release path that already refuses an
unpinned goreleaser.
Known gap: the Go tarball setup-go fetches is version-pinned but not
checksum-verified against a value in this repo, unlike the goreleaser
install and the Dockerfile digest.
51 lines
1.6 KiB
Go
51 lines
1.6 KiB
Go
package cli
|
|
|
|
import (
|
|
"fmt"
|
|
"io"
|
|
"runtime"
|
|
|
|
"github.com/spf13/cobra"
|
|
"sneak.berlin/go/vaultik/internal/globals"
|
|
)
|
|
|
|
// NewVersionCommand creates the version command
|
|
func NewVersionCommand() *cobra.Command {
|
|
cmd := &cobra.Command{
|
|
Use: "version",
|
|
Short: "Print version information",
|
|
Long: `Print version, git commit, and build information for vaultik.`,
|
|
Args: cobra.NoArgs,
|
|
Run: func(cmd *cobra.Command, _ []string) {
|
|
writeVersion(cmd.OutOrStdout())
|
|
},
|
|
}
|
|
|
|
return cmd
|
|
}
|
|
|
|
// writeVersion prints the version report. It takes a writer rather than
|
|
// using os.Stdout directly so the output can be asserted on in tests.
|
|
func writeVersion(w io.Writer) {
|
|
_, _ = fmt.Fprintf(w, "vaultik %s\n", globals.Version)
|
|
_, _ = fmt.Fprintf(w, " commit: %s\n", globals.Commit)
|
|
_, _ = fmt.Fprintf(w, " build date: %s\n", globals.CommitDate)
|
|
_, _ = fmt.Fprintf(w, " go: %s\n", runtime.Version())
|
|
_, _ = fmt.Fprintf(w, " os/arch: %s/%s\n", runtime.GOOS, runtime.GOARCH)
|
|
_, _ = fmt.Fprintf(w, " author: %s\n", globals.Author)
|
|
_, _ = fmt.Fprintf(w, " homepage: %s\n", globals.Homepage)
|
|
_, _ = fmt.Fprintf(w, " license: %s\n", globals.License)
|
|
|
|
if globals.IsDevVersion(globals.Version) {
|
|
_, _ = fmt.Fprintln(w)
|
|
_, _ = fmt.Fprintln(w,
|
|
"This is a development build: it was not built from a tagged")
|
|
_, _ = fmt.Fprintln(w,
|
|
"commit, so it carries no release version. Released binaries")
|
|
_, _ = fmt.Fprintf(w,
|
|
"are published at %s\n", globals.ReleasesURL)
|
|
_, _ = fmt.Fprintln(w,
|
|
"and report their tag on the first line above.")
|
|
}
|
|
}
|