All checks were successful
check / check (push) Successful in 3m7s
No tag could be cut at all: .goreleaser.yaml had no gitea_urls block, so
goreleaser defaulted to the GitHub API, and the repo has zero tags.
.goreleaser.yaml now points at git.eeqj.de. Version derives from git via
a new script/version - exact tag with any leading v stripped, else
dev-<12-char sha>, with a -dirty suffix when tracked files are modified -
replacing the hardcoded 1.0.0-rc.1 that every local build was stamping
regardless of git state. A tag-triggered .gitea/workflows/release.yml
runs goreleaser with a scoped token (RELEASE_TOKEN); script/bootstrap
installs a sha256-verified goreleaser, and make release / release-snapshot
become script shims like every other target.
Two fabrications were removed rather than merely replaced. goreleaser's
snapshot.version_template was `{{ incpatch .Version }}-next`, which
invents a release number from the last tag - and with no tags, from
goreleaser's own fabricated v0.0.0. And internal/cli/version.go gated its
development-build notice on Version == "dev" exactly, so the moment
untagged builds carried a sha that notice would have gone silent and an
unreleased binary would have read as a release. Replaced with a tested
IsDevVersion predicate, and closed at both layers: the Makefile now
refuses to build when script/version yields nothing, and an empty version
counts as a development build - reachable today via
`docker build --build-arg VERSION=`.
The release workflow installs Go from a sha-pinned actions/setup-go
(v5.6.0) using go-version-file, so the compiler that produces released
binaries is pinned like every other external reference. Without it the
first tag push would either fail at goreleaser's before-hook or compile
the published artifacts with whatever unpinned Go the runner happened to
carry - the one unpinned thing in a release path that already refuses an
unpinned goreleaser.
Known gap: the Go tarball setup-go fetches is version-pinned but not
checksum-verified against a value in this repo, unlike the goreleaser
install and the Dockerfile digest.
89 lines
3.1 KiB
Go
89 lines
3.1 KiB
Go
// Package globals holds application-wide metadata (name, version,
|
|
// commit) that is populated at build time via linker flags.
|
|
package globals
|
|
|
|
import (
|
|
"strings"
|
|
"time"
|
|
)
|
|
|
|
// Appname is the application name, populated from main().
|
|
var Appname = "vaultik" //nolint:gochecknoglobals // set via -ldflags at build time
|
|
|
|
// DevVersion is the version a binary reports when it was not built
|
|
// from a tagged commit. script/version emits either this exact string
|
|
// (outside a git checkout) or this string followed by "-" and the
|
|
// commit it was built from, and goreleaser's snapshot template matches
|
|
// that shape. It is deliberately not a number: a build that is not a
|
|
// release must not name itself like one.
|
|
const DevVersion = "dev"
|
|
|
|
// Version is the application version, populated from main().
|
|
var Version = DevVersion //nolint:gochecknoglobals // set via -ldflags at build time
|
|
|
|
// Commit is the git commit hash, populated from main().
|
|
var Commit = "unknown" //nolint:gochecknoglobals // set via -ldflags at build time
|
|
|
|
// CommitDate is the ISO-8601 date of the commit, populated from main().
|
|
var CommitDate = "unknown" //nolint:gochecknoglobals // set via -ldflags at build time
|
|
|
|
// Author identifies the upstream author of vaultik.
|
|
const Author = "Jeffrey Paul <sneak@sneak.berlin>"
|
|
|
|
// Homepage is the canonical URL for vaultik.
|
|
const Homepage = "https://sneak.berlin/go/vaultik"
|
|
|
|
// ReleasesURL is where tagged release artifacts are published.
|
|
const ReleasesURL = "https://git.eeqj.de/sneak/vaultik/releases"
|
|
|
|
// License is the SPDX identifier for the project license.
|
|
const License = "MIT"
|
|
|
|
// Globals contains application-wide configuration and metadata.
|
|
type Globals struct {
|
|
Appname string
|
|
Version string
|
|
Commit string
|
|
CommitDate string
|
|
StartTime time.Time
|
|
}
|
|
|
|
// New creates and returns a new Globals instance initialized with the
|
|
// package-level variables.
|
|
func New() (*Globals, error) {
|
|
return &Globals{
|
|
Appname: Appname,
|
|
Version: Version,
|
|
Commit: Commit,
|
|
CommitDate: CommitDate,
|
|
}, nil
|
|
}
|
|
|
|
// IsDevVersion reports whether v names a development build rather than
|
|
// a release. Both "dev" and "dev-<sha>" (and its "-dirty" variant)
|
|
// count: a caller that compares against "dev" exactly would treat every
|
|
// commit-stamped development build as a release.
|
|
//
|
|
// The empty string counts too. Nothing that knows its version reports
|
|
// no version, so an empty Version means the stamping failed, and the
|
|
// safe reading of "we could not establish that this is a release" is
|
|
// that it is not one. The Makefile refuses to build at all in that
|
|
// case; this is the second line of defence, for a binary linked by
|
|
// something other than the Makefile.
|
|
func IsDevVersion(v string) bool {
|
|
return v == "" || v == DevVersion || strings.HasPrefix(v, DevVersion+"-")
|
|
}
|
|
|
|
// shortCommitLen is the number of commit-hash characters ShortCommit keeps.
|
|
const shortCommitLen = 12
|
|
|
|
// ShortCommit returns the first 12 chars of the commit hash, or the
|
|
// whole string if it's shorter (e.g. "unknown").
|
|
func (g *Globals) ShortCommit() string {
|
|
if len(g.Commit) > shortCommitLen {
|
|
return g.Commit[:shortCommitLen]
|
|
}
|
|
|
|
return g.Commit
|
|
}
|