All checks were successful
check / check (push) Successful in 3m7s
No tag could be cut at all: .goreleaser.yaml had no gitea_urls block, so
goreleaser defaulted to the GitHub API, and the repo has zero tags.
.goreleaser.yaml now points at git.eeqj.de. Version derives from git via
a new script/version - exact tag with any leading v stripped, else
dev-<12-char sha>, with a -dirty suffix when tracked files are modified -
replacing the hardcoded 1.0.0-rc.1 that every local build was stamping
regardless of git state. A tag-triggered .gitea/workflows/release.yml
runs goreleaser with a scoped token (RELEASE_TOKEN); script/bootstrap
installs a sha256-verified goreleaser, and make release / release-snapshot
become script shims like every other target.
Two fabrications were removed rather than merely replaced. goreleaser's
snapshot.version_template was `{{ incpatch .Version }}-next`, which
invents a release number from the last tag - and with no tags, from
goreleaser's own fabricated v0.0.0. And internal/cli/version.go gated its
development-build notice on Version == "dev" exactly, so the moment
untagged builds carried a sha that notice would have gone silent and an
unreleased binary would have read as a release. Replaced with a tested
IsDevVersion predicate, and closed at both layers: the Makefile now
refuses to build when script/version yields nothing, and an empty version
counts as a development build - reachable today via
`docker build --build-arg VERSION=`.
The release workflow installs Go from a sha-pinned actions/setup-go
(v5.6.0) using go-version-file, so the compiler that produces released
binaries is pinned like every other external reference. Without it the
first tag push would either fail at goreleaser's before-hook or compile
the published artifacts with whatever unpinned Go the runner happened to
carry - the one unpinned thing in a release path that already refuses an
unpinned goreleaser.
Known gap: the Go tarball setup-go fetches is version-pinned but not
checksum-verified against a value in this repo, unlike the goreleaser
install and the Dockerfile digest.
74 lines
2.5 KiB
Bash
Executable File
74 lines
2.5 KiB
Bash
Executable File
#!/bin/sh
|
|
# script/version: output the version string to bake into the binary.
|
|
# Our own extension to scripts-to-rule-them-all, and the single source
|
|
# of truth for the version: the Makefile's LDFLAGS call this rather
|
|
# than carrying a hardcoded constant, which is what used to make every
|
|
# local build claim to be 1.0.0-rc.1 regardless of git state.
|
|
#
|
|
# The rules, in order:
|
|
#
|
|
# HEAD is exactly on an annotated or lightweight tag
|
|
# -> that tag, with a leading "v" stripped
|
|
# anything else
|
|
# -> "dev-<12 chars of HEAD>"
|
|
# not a git checkout at all (release tarball, `go install`)
|
|
# -> "dev"
|
|
#
|
|
# Either of the first two gains a "-dirty" suffix when tracked files
|
|
# have uncommitted changes, because a modified checkout of v1.0.0 is
|
|
# not v1.0.0. Untracked files are ignored, matching `git describe
|
|
# --dirty`: a stray scratch file does not change what was compiled.
|
|
#
|
|
# The "v" is stripped so that a `make` build and a goreleaser build of
|
|
# the same tagged commit report the *same* string: goreleaser's
|
|
# {{ .Version }} is the tag without the prefix, and the release archive
|
|
# names are built from it. A tag named `v1.0.0` therefore produces
|
|
# `vaultik 1.0.0`, matching `vaultik_1.0.0_linux_amd64.tar.gz`.
|
|
#
|
|
# Nothing here ever invents a version number. An untagged build says so
|
|
# and names the commit it was built from; it does not round up to the
|
|
# nearest plausible release.
|
|
set -eu
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
|
|
|
# Length of the commit prefix in a dev version. Matches
|
|
# globals.ShortCommit, so `vaultik version` shows the same 12 chars in
|
|
# its version line and its commit line.
|
|
SHORT_LEN=12
|
|
|
|
main() {
|
|
cd "$ROOT"
|
|
|
|
if ! git rev-parse --git-dir >/dev/null 2>&1; then
|
|
echo "dev"
|
|
return 0
|
|
fi
|
|
|
|
dirty=""
|
|
if [ -n "$(git status --porcelain --untracked-files=no 2>/dev/null)" ]; then
|
|
dirty="-dirty"
|
|
fi
|
|
|
|
# --exact-match so a *descendant* of a tag is not reported as that
|
|
# tag. Plain `git describe --tags` would call a commit 40 patches
|
|
# past v1.0.0 "v1.0.0-40-gabc1234", and the leading token of that is
|
|
# a released version the build is not.
|
|
tag="$(git describe --tags --exact-match HEAD 2>/dev/null || true)"
|
|
if [ -n "$tag" ]; then
|
|
echo "${tag#v}${dirty}"
|
|
return 0
|
|
fi
|
|
|
|
sha="$(git rev-parse "--short=$SHORT_LEN" HEAD 2>/dev/null || true)"
|
|
if [ -z "$sha" ]; then
|
|
# A repo with no commits at all.
|
|
echo "dev"
|
|
return 0
|
|
fi
|
|
|
|
echo "dev-${sha}${dirty}"
|
|
}
|
|
|
|
main "$@"
|