-
Notifications
You must be signed in to change notification settings - Fork 0
37 lines (33 loc) · 1.06 KB
/
Copy pathrelease.yml
File metadata and controls
37 lines (33 loc) · 1.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
name: Release
on:
push:
tags: ['v*']
# Least privilege by default (audit T61): the workflow as a whole is
# read-only; only the publishing job escalates to contents: write.
permissions:
contents: read
jobs:
verify:
# The exact commit being released must pass the same gates CI runs —
# previously the tag pipeline published without running a single test
# (audit F64).
uses: ./.github/workflows/ci.yml
release:
needs: verify
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
fetch-depth: 0
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: '1.26'
- uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
with:
version: latest
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_GITHUB_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}