mirror of
https://github.com/PerpetualSoftware/pad.git
synced 2026-09-10 15:05:40 +00:00
38e1042fee
Bumps the actions-minor-and-patch group with 1 update in the / directory: [docker/login-action](https://github.com/docker/login-action). Updates `docker/login-action` from 4.4.0 to 4.6.0 - [Release notes](https://github.com/docker/login-action/releases) - [Commits](https://github.com/docker/login-action/compare/af1e73f918a031802d376d3c8bbc3fe56130a9b0...dbcb813823bdd20940b903addbd779551569679f) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.5.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: actions-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
157 lines
7.6 KiB
YAML
157 lines
7.6 KiB
YAML
name: Release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
|
|
# Serialize all release runs. If two v* tags land close together (e.g.
|
|
# rc.3 then rc.4 within a minute), queue rather than race — they share
|
|
# mutable outputs (the GHCR `:latest` tag, the homebrew cask in the
|
|
# separate tap repo, the GitHub Releases page) and parallel runs would
|
|
# interleave nondeterministically. Group is intentionally NOT keyed by
|
|
# `github.ref`: we want different tag names to serialize too, not just
|
|
# repeat pushes of the same tag. cancel-in-progress=false so a queued
|
|
# tag never aborts a release mid-publish (which could leave GHCR and the
|
|
# brew tap in inconsistent states).
|
|
concurrency:
|
|
group: release
|
|
cancel-in-progress: false
|
|
|
|
permissions:
|
|
contents: write
|
|
packages: write
|
|
# id-token: write is required for keyless cosign signing (GitHub OIDC
|
|
# exchanges this workflow's identity token for a short-lived Fulcio
|
|
# certificate) and for actions/attest-build-provenance to mint SLSA
|
|
# v1 provenance statements.
|
|
id-token: write
|
|
# attestations: write is required by actions/attest-build-provenance so
|
|
# the resulting provenance bundles can be stored against the repo.
|
|
attestations: write
|
|
|
|
# All third-party Actions are pinned to a 40-char commit SHA with a trailing
|
|
# '# vX.Y.Z' comment so a compromised maintainer or moved tag cannot silently
|
|
# execute attacker code in the release pipeline (this workflow has
|
|
# contents:write + packages:write + the GHCR token, so a malicious action
|
|
# here could publish tampered binaries). Bump the SHA + comment together.
|
|
|
|
jobs:
|
|
release:
|
|
name: Build & Release
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
|
with:
|
|
go-version: "1.26"
|
|
|
|
- name: Allow Go to fetch the toolchain go.mod pins
|
|
# actions/setup-go pins GOTOOLCHAIN=local, which blocks the toolchain
|
|
# go.mod requires (`go 1.26.5`) from being fetched. `auto`, written
|
|
# after setup-go so it wins the $GITHUB_ENV last-write, lets Go pull
|
|
# it on demand. Mirrors the CI workflow; see #896.
|
|
run: echo "GOTOOLCHAIN=auto" >> "$GITHUB_ENV"
|
|
|
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version: "24"
|
|
cache: "npm"
|
|
cache-dependency-path: web/package-lock.json
|
|
|
|
- name: Create web build placeholder for tests
|
|
run: mkdir -p web/build && echo "placeholder" > web/build/.gitkeep
|
|
|
|
- name: Run tests
|
|
run: go test ./...
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0
|
|
|
|
- name: Login to GitHub Container Registry
|
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
|
with:
|
|
registry: ghcr.io
|
|
username: ${{ github.actor }}
|
|
password: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
# cosign + syft need to be on PATH before goreleaser runs — goreleaser
|
|
# shells out to both for the signs/docker_signs/sboms sections.
|
|
- name: Install cosign
|
|
uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
|
|
|
|
- name: Install syft (for SBOM generation)
|
|
uses: anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
|
|
|
|
# Build the SvelteKit web UI before GoReleaser so the static assets
|
|
# get embedded into the Go binary. Done as a dedicated step (instead
|
|
# of a goreleaser `before:` hook) so the npm install/build does NOT
|
|
# inherit the MACOS_* signing secrets — those are scoped only to the
|
|
# `Run GoReleaser` step's env block below. This isolates the 5-year
|
|
# Developer ID cert from any npm supply-chain compromise during
|
|
# dependency install.
|
|
- name: Build web UI
|
|
run: cd web && npm ci && npm run build
|
|
|
|
- name: Run GoReleaser
|
|
id: goreleaser
|
|
# GoReleaser binary is pinned to an exact version (not "~> v2") to
|
|
# match the SHA-pinning policy applied to the Actions themselves —
|
|
# see the comment at the top of this file. With Apple signing
|
|
# credentials now flowing through this step, a compromised or
|
|
# regressed GoReleaser release would carry meaningful blast radius;
|
|
# pinning forces an explicit, reviewed bump.
|
|
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
|
|
with:
|
|
version: "v2.15.4"
|
|
# --timeout=2h overrides GoReleaser's 1h default. With Apple
|
|
# notarization (`wait: true`, up to 20m per the .goreleaser.yaml
|
|
# notarize block) layered on top of build + cosign blob-sign +
|
|
# SBOM + multi-arch docker manifest, slow notary days could push
|
|
# close to the default ceiling. 2h gives comfortable headroom
|
|
# without burning excessive Action minutes when notarization
|
|
# actually fails fast (the worker exits as soon as Apple replies).
|
|
args: release --clean --timeout=2h
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
# Force-set the release tag from the triggering ref to bypass
|
|
# goreleaser's git-describe-based auto-detection. When two
|
|
# lightweight tags point at the same commit (e.g. v0.4.0 cut
|
|
# right on top of v0.4.0-rc.1 with no intervening commits),
|
|
# git-describe's tiebreaker is non-deterministic across hosts
|
|
# — locally it picked v0.4.0, the CI runner picked v0.4.0-rc.1
|
|
# during the v0.4.0 ship and stamped artifacts with the RC
|
|
# version. github.ref_name is unambiguous: it's exactly the
|
|
# tag that triggered the workflow. See PLAYB-1160 failure modes.
|
|
GORELEASER_CURRENT_TAG: ${{ github.ref_name }}
|
|
# Cross-repo PAT for pushing the brew formula to PerpetualSoftware/homebrew-tap.
|
|
# The default GITHUB_TOKEN above only has access to PerpetualSoftware/pad.
|
|
# Add this secret in repo settings before tagging a release that ships
|
|
# a brew formula — without it goreleaser fails at the brew publish step.
|
|
HOMEBREW_TAP_GITHUB_TOKEN: ${{ secrets.HOMEBREW_TAP_GITHUB_TOKEN }}
|
|
# macOS code-signing + Apple notarization (per IDEA-830). The
|
|
# `notarize:` block in .goreleaser.yaml is gated on MACOS_CERT_P12
|
|
# being set, so PR builds + snapshot mode skip cleanly when these
|
|
# are absent. The .p12 cert and .p8 notary key are stored
|
|
# base64-encoded; GoReleaser's Quill backend decodes them in-process,
|
|
# so no external signing tool needs to be installed on the runner.
|
|
MACOS_CERT_P12: ${{ secrets.MACOS_CERT_P12 }}
|
|
MACOS_CERT_PASSWORD: ${{ secrets.MACOS_CERT_PASSWORD }}
|
|
MACOS_NOTARY_KEY_P8: ${{ secrets.MACOS_NOTARY_KEY_P8 }}
|
|
MACOS_NOTARY_KEY_ID: ${{ secrets.MACOS_NOTARY_KEY_ID }}
|
|
MACOS_NOTARY_ISSUER_ID: ${{ secrets.MACOS_NOTARY_ISSUER_ID }}
|
|
|
|
# SLSA build provenance for every archive GoReleaser produced.
|
|
# Writes a Sigstore-backed attestation to the repo so downstream
|
|
# consumers can verify this binary was actually built by this
|
|
# workflow from this commit, e.g.:
|
|
# gh attestation verify pad_v1.0.0_linux_amd64.tar.gz \
|
|
# --repo PerpetualSoftware/pad
|
|
- name: Generate build provenance for archives
|
|
uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1
|
|
with:
|
|
subject-path: "dist/pad_*_*_*.tar.gz,dist/pad_*_*_*.zip"
|