mirror of
https://github.com/fastfetch-cli/fastfetch.git
synced 2026-09-13 02:14:37 +02:00
b6d95a0ce5
Jobs without a permissions block get the repository's default token scope, and reusable workflow calls pass the caller's grants straight through. Scopes are now derived from what each workflow actually does with the token: - every build workflow declares contents: read; none of them writes through the GITHUB_TOKEN. - build-linux-hosts.yml keeps security-events: write for the CodeQL upload; the other callers had that grant too but never upload scanning results, so they drop it. - build-windows-hosts.yml gets actions: read, which the SignPath action documents needing to read job details and download the unsigned artifact. - build-release.yml declares contents: write, matching the grant its caller already makes for creating the release. Runs that execute pull request code now hold a token that can do nothing but read the repository.
62 lines
2.6 KiB
YAML
62 lines
2.6 KiB
YAML
name: Reusable Release
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
ffversion:
|
|
required: true
|
|
type: string
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
jobs:
|
|
release:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: get latest release version
|
|
id: get_version_release
|
|
uses: pozetroninc/github-action-get-latest-release@2a61c339ea7ef0a336d1daa35ef0cb1418e7676c # v0.8.0
|
|
with:
|
|
repository: ${{ github.repository }}
|
|
|
|
- name: download artifacts
|
|
if: inputs.ffversion != steps.get_version_release.outputs.release
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
|
|
- name: create release
|
|
if: inputs.ffversion != steps.get_version_release.outputs.release
|
|
uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1.21.0
|
|
with:
|
|
tag: ${{ inputs.ffversion }}
|
|
commit: ${{ github.sha }}
|
|
artifactErrorsFailBuild: true
|
|
artifacts: fastfetch-*/fastfetch-*
|
|
body: "Please refer to [CHANGELOG.md](https://github.com/${{ github.repository }}/blob/${{ inputs.ffversion }}/CHANGELOG.md) for details."
|
|
|
|
- name: download source tarballs
|
|
if: inputs.ffversion != steps.get_version_release.outputs.release
|
|
run: |
|
|
for i in 1 2 3 4 5; do curl -L --remote-name-all --output-dir fastfetch-source --create-dirs https://github.com/${{ github.repository }}/archive/refs/tags/${{ inputs.ffversion }}.{tar.gz,zip} && break || sleep 5; done
|
|
ls fastfetch-*/*
|
|
|
|
- name: generate release notes
|
|
if: inputs.ffversion != steps.get_version_release.outputs.release
|
|
run: |
|
|
echo "Please refer to [CHANGELOG.md](https://github.com/${{ github.repository }}/blob/${{ inputs.ffversion }}/CHANGELOG.md) for details." > fastfetch-release-notes.md
|
|
echo -e "\n---\n\n<details><summary>SHA256SUMs</summary><br>\n\n\`\`\`" >> fastfetch-release-notes.md
|
|
sha256sum fastfetch-*/* >> fastfetch-release-notes.md
|
|
echo -e "\`\`\`\n</details>" >> fastfetch-release-notes.md
|
|
echo -e "\n<details><summary>SHA512SUMs</summary><br>\n\n\`\`\`" >> fastfetch-release-notes.md
|
|
sha512sum fastfetch-*/* >> fastfetch-release-notes.md
|
|
echo -e "\`\`\`\n</details>" >> fastfetch-release-notes.md
|
|
|
|
- name: update release body
|
|
if: inputs.ffversion != steps.get_version_release.outputs.release
|
|
uses: ncipollo/release-action@339a81892b84b4eeb0f6e744e4574d79d0d9b8dd # v1.21.0
|
|
with:
|
|
tag: ${{ inputs.ffversion }}
|
|
commit: ${{ github.sha }}
|
|
bodyFile: fastfetch-release-notes.md
|
|
allowUpdates: true
|