check / check (push) Successful in 12m47s
Linting and testing become the lint and test phases of the Dockerfile, and the build stage depends on both. Dockerfile.lint, CHECK_EPOCH and the tests that checked them are removed. Every docker build in script/ passes --no-cache, and script/cibuild runs script/bootstrap first. A host without Go gets the go.mod version from script/install-go in .tool/go, which bootstrap, the Makefile, fmt, fmt-check, precommit and release add to PATH; fmt-check skips .tool. The image takes its version from the VERSION build arg or git describe, dev without .git. This repo's own entries follow the canonical content in .gitignore and .editorconfig. The golangci-lint v2.14.0 findings are fixed. The rules in CLAUDE.md move into AGENTS.md. IsDevVersion counts "unknown". Model: opus-5-5
55 lines
2.6 KiB
YAML
55 lines
2.6 KiB
YAML
name: release
|
|
on:
|
|
push:
|
|
tags: ["v*"]
|
|
jobs:
|
|
release:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# actions/checkout v4, 2024-09-16
|
|
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5
|
|
with:
|
|
# goreleaser needs the tags and the full history: the version
|
|
# it stamps comes from the tag, and the changelog comes from
|
|
# the commits since the previous one. A shallow checkout
|
|
# silently produces a mislabelled release.
|
|
fetch-depth: 0
|
|
# goreleaser is not a compiler: it shells out to `go` for the
|
|
# `before:` hook and for every one of the four cross-compiles.
|
|
# Without this step the release either fails at the before-hook or,
|
|
# worse, ships binaries built by whatever Go the runner happens to
|
|
# carry. check.yml's runner gets the same Go through
|
|
# script/bootstrap, which calls script/install-go, and uses it only
|
|
# for `go mod download` and gofmt; it compiles inside the
|
|
# digest-pinned Dockerfile images.
|
|
#
|
|
# actions/setup-go would pin the action by commit sha, but the Go
|
|
# tarball it downloads at runtime is verified against no value in
|
|
# this repo, and the action exposes no checksum input.
|
|
# REPO_POLICIES.md requires every external reference to be pinned
|
|
# by hash with no exceptions, and this is the compiler that
|
|
# produces the published binaries -- the input where a substituted
|
|
# artifact matters most. So Go is installed the way goreleaser is:
|
|
# script/install-go downloads the exact archive for go.mod's `go`
|
|
# directive and refuses it unless its sha256 matches the value
|
|
# committed in the script, then puts .tool/go/bin on PATH for the
|
|
# steps below.
|
|
- name: Install Go
|
|
run: script/install-go
|
|
- name: Install goreleaser
|
|
run: script/install-goreleaser
|
|
- name: Release
|
|
run: script/release
|
|
env:
|
|
# RELEASE_TOKEN is a repository Actions secret: a Gitea access
|
|
# token with write access to this repository's releases (scope
|
|
# write:repository), owned by an account that can publish here.
|
|
# It is deliberately not the runner's automatic token, which is
|
|
# not guaranteed to carry that scope.
|
|
GITEA_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
|
# Build with the toolchain install-go just verified, never a
|
|
# different one auto-downloaded from a `toolchain` directive:
|
|
# the point of the hash pin is that this exact compiler makes
|
|
# the release.
|
|
GOTOOLCHAIN: local
|