mirror of
https://github.com/usestrix/strix.git
synced 2026-08-18 17:52:32 +02:00
Every `uses:` in build-release.yml was a mutable tag; the `release` job has `contents: write` and publishes the binaries users install, so a compromised action could tamper the release. Action tag-hijacking keeps recurring (aquasecurity/trivy-action, 75 tags, Mar 2026 TeamPCP; tj-actions, 2025; codfish/semantic-release-action, Jun 2026) and SHA-pinned workflows were immune each time. Pin all six actions to the commit each @major resolves to today (concrete version in a trailing comment; setup-uv's annotated tag dereferenced to its commit, not the tag object, so Dependabot tracks it). Also add a top-level `permissions: contents: read` (the release job keeps its explicit write) and `persist-credentials: false` on the build checkout. actionlint passes. Pairs with #860 (Dependabot github-actions keeps the pins current). Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
84 lines
2.4 KiB
YAML
84 lines
2.4 KiB
YAML
name: Build & Release
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v*'
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- os: macos-latest
|
|
target: macos-arm64
|
|
- os: macos-15-intel
|
|
target: macos-x86_64
|
|
- os: ubuntu-22.04
|
|
target: linux-x86_64
|
|
- os: windows-latest
|
|
target: windows-x86_64
|
|
|
|
runs-on: ${{ matrix.os }}
|
|
|
|
steps:
|
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0
|
|
with:
|
|
python-version: '3.12'
|
|
|
|
- uses: astral-sh/setup-uv@d4b2f3b6ecc6e67c4457f6d3e41ec42d3d0fcb86 # v5.4.2
|
|
|
|
- name: Build
|
|
shell: bash
|
|
run: |
|
|
uv sync --frozen
|
|
uv run pyinstaller strix.spec --noconfirm
|
|
|
|
VERSION=$(grep '^version' pyproject.toml | head -1 | sed 's/.*"\(.*\)"/\1/')
|
|
mkdir -p dist/release
|
|
|
|
if [[ "${{ runner.os }}" == "Windows" ]]; then
|
|
cp dist/strix.exe "dist/release/strix-${VERSION}-${{ matrix.target }}.exe"
|
|
(cd dist/release && 7z a "strix-${VERSION}-${{ matrix.target }}.zip" "strix-${VERSION}-${{ matrix.target }}.exe")
|
|
else
|
|
cp dist/strix "dist/release/strix-${VERSION}-${{ matrix.target }}"
|
|
chmod +x "dist/release/strix-${VERSION}-${{ matrix.target }}"
|
|
tar -C dist/release -czvf "dist/release/strix-${VERSION}-${{ matrix.target }}.tar.gz" "strix-${VERSION}-${{ matrix.target }}"
|
|
fi
|
|
|
|
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
|
|
with:
|
|
name: strix-${{ matrix.target }}
|
|
path: |
|
|
dist/release/*.tar.gz
|
|
dist/release/*.zip
|
|
if-no-files-found: error
|
|
|
|
release:
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: write
|
|
|
|
steps:
|
|
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
|
|
with:
|
|
path: release
|
|
merge-multiple: true
|
|
|
|
- name: Create Release
|
|
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2
|
|
with:
|
|
prerelease: ${{ !startsWith(github.ref, 'refs/tags/') }}
|
|
generate_release_notes: true
|
|
files: release/*
|