All checks were successful
check / check (push) Successful in 3m7s
No tag could be cut at all: .goreleaser.yaml had no gitea_urls block, so
goreleaser defaulted to the GitHub API, and the repo has zero tags.
.goreleaser.yaml now points at git.eeqj.de. Version derives from git via
a new script/version - exact tag with any leading v stripped, else
dev-<12-char sha>, with a -dirty suffix when tracked files are modified -
replacing the hardcoded 1.0.0-rc.1 that every local build was stamping
regardless of git state. A tag-triggered .gitea/workflows/release.yml
runs goreleaser with a scoped token (RELEASE_TOKEN); script/bootstrap
installs a sha256-verified goreleaser, and make release / release-snapshot
become script shims like every other target.
Two fabrications were removed rather than merely replaced. goreleaser's
snapshot.version_template was `{{ incpatch .Version }}-next`, which
invents a release number from the last tag - and with no tags, from
goreleaser's own fabricated v0.0.0. And internal/cli/version.go gated its
development-build notice on Version == "dev" exactly, so the moment
untagged builds carried a sha that notice would have gone silent and an
unreleased binary would have read as a release. Replaced with a tested
IsDevVersion predicate, and closed at both layers: the Makefile now
refuses to build when script/version yields nothing, and an empty version
counts as a development build - reachable today via
`docker build --build-arg VERSION=`.
The release workflow installs Go from a sha-pinned actions/setup-go
(v5.6.0) using go-version-file, so the compiler that produces released
binaries is pinned like every other external reference. Without it the
first tag push would either fail at goreleaser's before-hook or compile
the published artifacts with whatever unpinned Go the runner happened to
carry - the one unpinned thing in a release path that already refuses an
unpinned goreleaser.
Known gap: the Go tarball setup-go fetches is version-pinned but not
checksum-verified against a value in this repo, unlike the goreleaser
install and the Dockerfile digest.
116 lines
3.7 KiB
Makefile
116 lines
3.7 KiB
Makefile
.PHONY: all bootstrap setup check test lint lint-fix fmt fmt-check build clean deps test-coverage local install release release-snapshot docker hooks
|
||
|
||
# Version number, derived from git by script/version -- the tag when
|
||
# HEAD is on one, otherwise dev-<sha>. This used to be a hardcoded
|
||
# constant, which meant every local build claimed to be a release that
|
||
# had never been tagged.
|
||
VERSION := $(shell script/version)
|
||
|
||
# $(shell) discards exit status, so a script/version that is missing,
|
||
# non-executable or broken would otherwise leave VERSION empty and every
|
||
# binary built here would print "vaultik " with no version at all. A
|
||
# build that cannot determine what it is must not produce an artifact.
|
||
ifeq ($(strip $(VERSION)),)
|
||
$(error script/version produced no version string; a build that cannot \
|
||
determine its version will not be made. Check that script/version exists \
|
||
and is executable)
|
||
endif
|
||
|
||
# Build variables
|
||
GIT_REVISION := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown")
|
||
GIT_COMMIT_DATE := $(shell git show -s --format=%cs HEAD 2>/dev/null || echo "unknown")
|
||
|
||
# Linker flags
|
||
LDFLAGS := -X 'sneak.berlin/go/vaultik/internal/globals.Version=$(VERSION)' \
|
||
-X 'sneak.berlin/go/vaultik/internal/globals.Commit=$(GIT_REVISION)' \
|
||
-X 'sneak.berlin/go/vaultik/internal/globals.CommitDate=$(GIT_COMMIT_DATE)'
|
||
|
||
# Default target
|
||
all: vaultik
|
||
|
||
# Install all development dependencies.
|
||
bootstrap:
|
||
@script/bootstrap
|
||
|
||
# Prepare a fresh clone: bootstrap plus pre-commit hook.
|
||
setup:
|
||
@script/setup
|
||
|
||
# Combined pre-commit/CI gate: tests, lint, format check.
|
||
check:
|
||
@script/check
|
||
|
||
# Run tests only. This runs the ENTIRE suite -- there is no separate
|
||
# integration target and no build-tagged subset held back. In
|
||
# particular internal/vaultik/integration_test.go, which does full
|
||
# chunk -> pack -> encrypt -> upload -> restore round-trips, runs here.
|
||
# A `test-integration` target used to exist and was removed: no file in
|
||
# the repo carried a build tag, so `-tags=integration` selected nothing
|
||
# extra and the target was an exact duplicate of this one.
|
||
test:
|
||
@script/test
|
||
|
||
# Check if code is formatted (read-only).
|
||
fmt-check:
|
||
@script/fmt-check
|
||
|
||
# Format code.
|
||
fmt:
|
||
@script/fmt
|
||
|
||
# Run linter only.
|
||
lint:
|
||
@script/lint
|
||
|
||
# Apply the linter's autofixes (rewrites files).
|
||
lint-fix:
|
||
@script/lint-fix
|
||
|
||
# Build binary.
|
||
vaultik: internal/*/*.go cmd/vaultik/*.go
|
||
go build -ldflags "$(LDFLAGS)" -o $@ ./cmd/vaultik
|
||
|
||
# Clean build artifacts.
|
||
clean:
|
||
rm -f vaultik
|
||
go clean
|
||
|
||
# Install dependencies. The linter is deliberately not installed here:
|
||
# script/lint runs the digest-pinned golangci-lint image declared by the
|
||
# Dockerfile's lint stage, which is the single source of truth for the
|
||
# linter version. A second, separately pinned copy on PATH could drift
|
||
# from it and make a local `make lint` disagree with CI.
|
||
deps:
|
||
go mod download
|
||
|
||
# Run tests with coverage. -count=1 for the same reason script/test
|
||
# uses it: without it an unchanged package is served from Go's test
|
||
# result cache, and a coverage profile assembled from cached results
|
||
# describes a run that did not happen.
|
||
test-coverage:
|
||
go test -v -count=1 -coverprofile=coverage.out ./...
|
||
go tool cover -html=coverage.out -o coverage.html
|
||
|
||
local:
|
||
VAULTIK_CONFIG=$(HOME)/etc/vaultik/config.yml ./vaultik snapshot --debug list 2>&1
|
||
VAULTIK_CONFIG=$(HOME)/etc/vaultik/config.yml ./vaultik snapshot --debug create 2>&1
|
||
|
||
install: vaultik
|
||
cp ./vaultik $(HOME)/bin/
|
||
|
||
# Build and publish release artifacts (linux/darwin × amd64/arm64) via goreleaser.
|
||
release:
|
||
@script/release
|
||
|
||
# Dry-run a release build without publishing or tagging.
|
||
release-snapshot:
|
||
@script/release-snapshot
|
||
|
||
# Build Docker image.
|
||
docker:
|
||
@script/docker
|
||
|
||
# Install pre-commit hook.
|
||
hooks:
|
||
@script/install-precommit
|