Repository navigation
feat(release): add release automation with goreleaser and release-please - #20
Conversation
- Add .goreleaser.yaml for multi-platform builds (linux/darwin/windows) - Add release-please config for automated semantic versioning - Add release workflow triggered on version tags - Add release-please workflow for automated release PRs - Add version command with ldflags injection for build info - Add release-dry-run job to CI for goreleaser validation - Add empty CHANGELOG.md (managed by release-please) Includes: - Cosign keyless signing for checksums and SBOMs - SBOM generation via Syft - Homebrew tap publishing (meigma/homebrew-tap) - Scoop bucket publishing (meigma/scoop-bucket) Required secrets: RELEASE_PAT, HOMEBREW_TAP_TOKEN, SCOOP_BUCKET_TOKEN Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Kusari Analysis Results:
No pinned version dependency changes, code issues or exposed secrets detected! Note View full detailed analysis result for more information on the output and the checks that were run.
Found this helpful? Give it a 👍 or 👎 reaction! |
| name: Release Please | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - uses: googleapis/release-please-action@v4 |
There was a problem hiding this comment.
Issue: The googleapis/release-please-action should be pinned to a specific commit hash instead of using @v4. This prevents automatic updates that could introduce malicious code.
Recommended Code Changes:
Change from:
- uses: googleapis/release-please-action@v4
To: Pin to a specific commit hash (lookup the latest v4 commit hash and use):
- uses: googleapis/release-please-action@<commit-hash> # v4.x.x
| name: Release (Dry Run) | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout code |
There was a problem hiding this comment.
Issue: Add persist-credentials: false to the checkout action to prevent credentials from being accessible to subsequent workflow steps.
Recommended Code Changes:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0
persist-credentials: false
| fetch-depth: 0 | ||
|
|
||
| - name: Set up Go | ||
| uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0 |
There was a problem hiding this comment.
Issue: Disable caching in setup-go to prevent cache poisoning attacks in release pipelines.
Recommended Code Changes:
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: "1.25"
cache: false
| name: Release | ||
| runs-on: ubuntu-latest | ||
| steps: | ||
| - name: Checkout code |
There was a problem hiding this comment.
Issue: Add persist-credentials: false to the checkout action to prevent credentials from being accessible to subsequent workflow steps.
Recommended Code Changes:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
fetch-depth: 0
ref: ${{ inputs.tag || github.ref }}
persist-credentials: false
| fetch-depth: 0 | ||
| ref: ${{ inputs.tag || github.ref }} | ||
|
|
||
| - name: Set up Go |
There was a problem hiding this comment.
Issue: Disable caching in setup-go to prevent cache poisoning attacks in release pipelines where artifacts are published.
Recommended Code Changes:
- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: "1.25"
cache: false
- Pin googleapis/release-please-action to commit hash (16a9c90) - Add persist-credentials: false to checkout actions in release workflows - Disable Go module caching in release pipelines to prevent cache poisoning Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
|
Kusari PR Analysis rerun based on - 65d46b5 performed at: 2026-01-24T00:57:36Z - link to updated analysis |
Summary
blob version) with build info injectionFeatures
GoReleaser Configuration
meigma/homebrew-tap)meigma/scoop-bucket)Release-Please Integration
Version Command
Required GitHub Secrets
Before the release flow will work, configure these secrets:
RELEASE_PAT- Personal access token for release-pleaseHOMEBREW_TAP_TOKEN- Token with write access tomeigma/homebrew-tapSCOOP_BUCKET_TOKEN- Token with write access tomeigma/scoop-bucketTest plan
just cipassesblob versioncommand worksgoreleaser checkvalidates config🤖 Generated with Claude Code