From 4c937e15a300e0db65f03da8979e3aa681d93764 Mon Sep 17 00:00:00 2001 From: Lennart Espe <3391295+lnsp@users.noreply.github.com> Date: Sat, 25 Jul 2026 17:49:06 +0200 Subject: [PATCH 1/2] Repair the release workflow The v4.3.0 tag never produced a release: the run failed on "Set up Go 1.21" and the release and homebrew jobs never started. The workflow was pinned to actions/setup-go@v1, actions/checkout@v1 and the archived actions/create-release, all of which run on Node runtimes GitHub has retired, and it asked for Go 1.21 while go.mod now requires 1.24. Move to current actions, take the Go version from go.mod so the two cannot drift again, and publish with the gh CLI instead of the archived release actions. Correct the ldflags path while here. It set -X valar/cli/cmd.version, but the module is github.com/valar/cli, and the linker silently ignores -X for a symbol that does not exist. Every released binary therefore had an empty version string, which left cobra without a --version flag at all. A new step asserts the built binary reports the tag before publishing. Fix two latent bugs in the homebrew job that would have fired the first time it ran: it redirected awk into the same file it was reading, which truncates the formula before awk opens it, and it embedded the trailing " -" of sha256sum output into the formula. Also run build, vet and test on pushes and pull requests. The repository has tests now and nothing was running them. --- .github/workflows/go.yml | 228 ++++++++++++++++----------------------- 1 file changed, 91 insertions(+), 137 deletions(-) diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 5635c74..9362eab 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -1,156 +1,110 @@ name: Go + on: push: - tags: - - 'v*' + branches: [master] + tags: ['v*'] + pull_request: + +permissions: + contents: read + jobs: - build: - name: Build + test: + name: Test runs-on: ubuntu-latest steps: - - name: Set up Go 1.21 - uses: actions/setup-go@v1 - with: - go-version: 1.21 - - name: Check out code into the Go module directory - uses: actions/checkout@v1 - - name: Get dependencies - run: go get -v -t -d ./... - - name: Set version environment - run: echo "VALAR_VERSION=$(echo ${GITHUB_REF:10})" >> $GITHUB_ENV - - name: Build - run: | - CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -a -tags netgo -ldflags "-X valar/cli/cmd.version=$VALAR_VERSION -s -w -extldflags \"-static\"" -o valar_linux_amd64 . - CGO_ENABLED=0 GOOS=linux GOARCH=arm go build -a -tags netgo -ldflags "-X valar/cli/cmd.version=$VALAR_VERSION -s -w -extldflags \"-static\"" -o valar_linux_arm . - CGO_ENABLED=0 GOOS=linux GOARCH=arm64 go build -a -tags netgo -ldflags "-X valar/cli/cmd.version=$VALAR_VERSION -s -w -extldflags \"-static\"" -o valar_linux_arm64 . - CGO_ENABLED=0 GOOS=darwin GOARCH=amd64 go build -a -tags netgo -ldflags "-X valar/cli/cmd.version=$VALAR_VERSION -s -w -extldflags \"-static\"" -o valar_darwin_amd64 . - CGO_ENABLED=0 GOOS=darwin GOARCH=arm64 go build -a -tags netgo -ldflags "-X valar/cli/cmd.version=$VALAR_VERSION -s -w -extldflags \"-static\"" -o valar_darwin_arm64 . - - uses: actions/upload-artifact@v4 - with: - name: valar_darwin_amd64 - path: valar_darwin_amd64 - - uses: actions/upload-artifact@v4 - with: - name: valar_darwin_arm64 - path: valar_darwin_arm64 - - uses: actions/upload-artifact@v4 - with: - name: valar_linux_amd64 - path: valar_linux_amd64 - - uses: actions/upload-artifact@v4 - with: - name: valar_linux_arm - path: valar_linux_arm - - uses: actions/upload-artifact@v4 - with: - name: valar_linux_arm64 - path: valar_linux_arm64 + - uses: actions/checkout@v4 + - uses: actions/setup-go@v5 + with: + go-version-file: go.mod + - run: go build ./... + - run: go vet ./... + - run: go test ./... + release: name: Release + needs: [test] + if: startsWith(github.ref, 'refs/tags/v') runs-on: ubuntu-latest - needs: [build] + permissions: + contents: write steps: - - uses: actions/download-artifact@v4 - with: - name: valar_linux_arm - - uses: actions/download-artifact@v4 - with: - name: valar_linux_arm64 - - uses: actions/download-artifact@v4 - with: - name: valar_linux_amd64 - - uses: actions/download-artifact@v4 - with: - name: valar_darwin_amd64 - - uses: actions/download-artifact@v4 - with: - name: valar_darwin_arm64 - - name: Create Release - id: create_release - uses: actions/create-release@v1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - tag_name: ${{ github.ref }} - release_name: ${{ github.ref }} - draft: false - prerelease: false - - name: Upload release asset (linux_amd64) - uses: actions/upload-release-asset@v1.0.1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./valar_linux_amd64 - asset_name: valar_linux_amd64 - asset_content_type: binary/octet-stream - - name: Upload release asset (linux_arm64) - uses: actions/upload-release-asset@v1.0.1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./valar_linux_arm64 - asset_name: valar_linux_arm64 - asset_content_type: binary/octet-stream - - name: Upload release asset (linux_arm) - uses: actions/upload-release-asset@v1.0.1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./valar_linux_arm - asset_name: valar_linux_arm - asset_content_type: binary/octet-stream - - name: Upload release asset (darwin_amd64) - uses: actions/upload-release-asset@v1.0.1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./valar_darwin_amd64 - asset_name: valar_darwin_amd64 - asset_content_type: binary/octet-stream - - name: Upload release asset (darwin_arm64) - uses: actions/upload-release-asset@v1.0.1 - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - with: - upload_url: ${{ steps.create_release.outputs.upload_url }} - asset_path: ./valar_darwin_arm64 - asset_name: valar_darwin_arm64 - asset_content_type: binary/octet-stream - homebrew: + - uses: actions/checkout@v4 + - uses: actions/setup-go@v5 + with: + go-version-file: go.mod + + # The -X path must be the full module path of the package holding the + # variable. An -X for a symbol that does not exist is silently ignored, so + # a wrong path leaves every released binary reporting an empty version. + - name: Build release binaries + env: + VALAR_VERSION: ${{ github.ref_name }} + run: | + set -eu + mkdir -p dist + for target in linux/amd64 linux/arm linux/arm64 darwin/amd64 darwin/arm64; do + os="${target%/*}" + arch="${target#*/}" + CGO_ENABLED=0 GOOS="$os" GOARCH="$arch" go build \ + -a -tags netgo \ + -ldflags "-X github.com/valar/cli/cmd.version=${VALAR_VERSION} -s -w -extldflags \"-static\"" \ + -o "dist/valar_${os}_${arch}" . + done + + - name: Verify the version was stamped + run: | + set -eu + got="$(./dist/valar_linux_amd64 --version)" + case "$got" in + *"${GITHUB_REF_NAME#v}"*) ;; + *) echo "binary reports '$got', expected it to contain ${GITHUB_REF_NAME#v}"; exit 1 ;; + esac + + - name: Publish release + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + gh release create "${GITHUB_REF_NAME}" dist/* \ + --title "${GITHUB_REF_NAME}" \ + --generate-notes + + homebrew: name: Update homebrew-tap - runs-on: macos-latest - needs: [build, release] + needs: [release] + runs-on: ubuntu-latest steps: - - uses: actions/checkout@v2 - - name: Setup SSH Keys and known_hosts + - name: Configure deploy key env: - SSH_AUTH_SOCK: /tmp/ssh_agent.sock DEPLOY_KEY: ${{ secrets.DEPLOY_KEY }} run: | + set -eu mkdir -p ~/.ssh ssh-keyscan github.com >> ~/.ssh/known_hosts - ssh-agent -a $SSH_AUTH_SOCK > /dev/null - ssh-add - <<< "${DEPLOY_KEY}" - git config --global user.email "action@github.com" - git config --global user.name "GitHub Actions" - - name: Extract version - id: get_version - run: | - echo ::set-output name=version::${GITHUB_REF#refs/*/} - echo ::set-output name=short_version::$(echo ${GITHUB_REF#refs/*/} | cut -c2-) - - name: Bump archive version + install -m 600 /dev/stdin ~/.ssh/id_deploy <<< "${DEPLOY_KEY}" + + # sed writes through a temporary file: redirecting into the file being + # read truncates it before it is opened. + - name: Bump formula env: - SSH_AUTH_SOCK: /tmp/ssh_agent.sock + GIT_SSH_COMMAND: ssh -i ~/.ssh/id_deploy -o IdentitiesOnly=yes run: | - git clone git@github.com:valar/homebrew-tap.git ~/valar-tap && cd ~/valar-tap - NEW_URL="https://github.com/valar/cli/archive/refs/tags/${{ steps.get_version.outputs.version }}.tar.gz" - NEW_SHA256="$(curl -sSL $NEW_URL | sha256sum -)" - awk -v new_url="$NEW_URL" '{gsub(/url ".*"/, "url \""new_url"\"")} 1' Formula/valar.rb > Formula/valar.rb - awk -v new_sha256="$NEW_SHA256" '{gsub(/sha256 ".*"/, "sha256 \""new_sha256"\"")} 1' Formula/valar.rb > Formula/valar.rb - git commit -a -m "Bump version to ${{ steps.get_version.outputs.version }}" - git push -u - + set -eu + git config --global user.email "action@github.com" + git config --global user.name "GitHub Actions" + git clone git@github.com:valar/homebrew-tap.git tap + cd tap + url="https://github.com/valar/cli/archive/refs/tags/${GITHUB_REF_NAME}.tar.gz" + sha="$(curl -sSL "$url" | sha256sum | cut -d' ' -f1)" + tmp="$(mktemp)" + sed -e "s|url \".*\"|url \"${url}\"|" \ + -e "s|sha256 \".*\"|sha256 \"${sha}\"|" \ + Formula/valar.rb > "$tmp" + mv "$tmp" Formula/valar.rb + if git diff --quiet; then + echo "formula already up to date" + exit 0 + fi + git commit -am "Bump valar to ${GITHUB_REF_NAME}" + git push From 3d8746955e497826295fb47861bd8d7d32e2208f Mon Sep 17 00:00:00 2001 From: Lennart Espe <3391295+lnsp@users.noreply.github.com> Date: Sat, 25 Jul 2026 17:53:09 +0200 Subject: [PATCH 2/2] Use action versions that run on Node 24 checkout@v4 and setup-go@v5 target Node 20, which GitHub has deprecated and is already force-running on Node 24. Node 20 reaching end of life on the runners is the same bit-rot that broke this workflow before. --- .github/workflows/go.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/go.yml b/.github/workflows/go.yml index 9362eab..ff5b6e8 100644 --- a/.github/workflows/go.yml +++ b/.github/workflows/go.yml @@ -14,8 +14,8 @@ jobs: name: Test runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/checkout@v5 + - uses: actions/setup-go@v6 with: go-version-file: go.mod - run: go build ./... @@ -30,8 +30,8 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@v4 - - uses: actions/setup-go@v5 + - uses: actions/checkout@v5 + - uses: actions/setup-go@v6 with: go-version-file: go.mod