Skip to content

Bump goreleaser/goreleaser-action from 6.4.0 to 7.2.1 (#19) #186

Bump goreleaser/goreleaser-action from 6.4.0 to 7.2.1 (#19)

Bump goreleaser/goreleaser-action from 6.4.0 to 7.2.1 (#19) #186

Workflow file for this run

name: goreleaser
on:
push:
branches:
- main
tags:
- 'v[0-9]+.[0-9]+.[0-9]+*' # Only semver tags (v1.2.3, v1.2.3-rc1, etc.)
pull_request:
types: [opened, reopened, synchronize]
jobs:
# PR and main branch: only build validation, NO goreleaser (prevents hook injection)
validate:
if: github.event_name == 'pull_request' || (github.event_name == 'push' && !startsWith(github.ref, 'refs/tags/'))
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
- name: Set up Go
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
with:
go-version: 1.22
- name: Security scan for dangerous Go patterns
run: |
if grep -rn '//go:generate\|import "C"\|#cgo' --include='*.go' .; then
echo "::error::Detected potentially dangerous Go directive"
exit 1
fi
- name: Build
run: go build -v ./...
- name: Test
run: go test -v ./...
# Release: only on semver tags, with environment protection
release:
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
environment: production
permissions:
contents: write
id-token: write
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@7a3fe6cf4cb3a834922a1244abfce67bcef6a0c5 # v6.2.0
with:
go-version: 1.22
- name: Run GoReleaser
uses: goreleaser/goreleaser-action@1a80836c5c9d9e5755a25cb59ec6f45a3b5f41a8 # v7.2.1
with:
distribution: goreleaser
version: "2.6.1"
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GH_PAT }}