Skip to content

feat(release): add release automation with goreleaser and release-please - #20

Merged
jmgilman merged 2 commits into
masterfrom
feat/release-automation
Jan 24, 2026
Merged

jmgilman merged 2 commits into
masterfrom
feat/release-automation

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

  • Add GoReleaser v2 configuration for automated multi-platform releases
  • Add release-please for semantic versioning and changelog management
  • Add version command (blob version) with build info injection
  • Add release-dry-run job to CI for goreleaser validation

Features

GoReleaser Configuration

  • Multi-platform builds: linux/darwin (amd64, arm64), windows (amd64)
  • Cosign keyless signing for checksums and SBOMs
  • SBOM generation via Syft (SPDX JSON format)
  • Homebrew tap publishing (meigma/homebrew-tap)
  • Scoop bucket publishing (meigma/scoop-bucket)

Release-Please Integration

  • Automated release PRs based on conventional commits
  • Changelog sections: Features, Bug Fixes, Performance
  • Starting version: 0.0.0

Version Command

$ blob version
blob dev
  commit: none
  built:  unknown

Required GitHub Secrets

Before the release flow will work, configure these secrets:

  • RELEASE_PAT - Personal access token for release-please
  • HOMEBREW_TAP_TOKEN - Token with write access to meigma/homebrew-tap
  • SCOOP_BUCKET_TOKEN - Token with write access to meigma/scoop-bucket

Test plan

  • just ci passes
  • blob version command works
  • goreleaser check validates config
  • Snapshot build produces correct artifacts for all platforms

🤖 Generated with Claude Code

- Add .goreleaser.yaml for multi-platform builds (linux/darwin/windows)
- Add release-please config for automated semantic versioning
- Add release workflow triggered on version tags
- Add release-please workflow for automated release PRs
- Add version command with ldflags injection for build info
- Add release-dry-run job to CI for goreleaser validation
- Add empty CHANGELOG.md (managed by release-please)

Includes:
- Cosign keyless signing for checksums and SBOMs
- SBOM generation via Syft
- Homebrew tap publishing (meigma/homebrew-tap)
- Scoop bucket publishing (meigma/scoop-bucket)

Required secrets: RELEASE_PAT, HOMEBREW_TAP_TOKEN, SCOOP_BUCKET_TOKEN

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

kusari-inspector Bot commented Jan 24, 2026 •

Copy link
Copy Markdown

Kusari Inspector

Kusari Analysis Results:

Proceed with these changes

✅ No Flagged Issues Detected
All values appear to be within acceptable risk parameters.

No pinned version dependency changes, code issues or exposed secrets detected!

Note

View full detailed analysis result for more information on the output and the checks that were run.


@kusari-inspector rerun - Trigger a re-analysis of this PR
@kusari-inspector feedback [your message] - Send feedback to our AI and team
See Kusari's documentation for setup and configuration.
Commit: 65d46b5, performed at: 2026-01-24T00:57:35Z

Found this helpful? Give it a 👍 or 👎 reaction!

Comment thread .github/workflows/release-please.yml Outdated
name: Release Please
runs-on: ubuntu-latest
steps:
- uses: googleapis/release-please-action@v4

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: The googleapis/release-please-action should be pinned to a specific commit hash instead of using @v4. This prevents automatic updates that could introduce malicious code.

Recommended Code Changes:

Change from:
  - uses: googleapis/release-please-action@v4

To: Pin to a specific commit hash (lookup the latest v4 commit hash and use):
  - uses: googleapis/release-please-action@<commit-hash> # v4.x.x

Comment thread .github/workflows/ci.yml
name: Release (Dry Run)
runs-on: ubuntu-latest
steps:
- name: Checkout code

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: Add persist-credentials: false to the checkout action to prevent credentials from being accessible to subsequent workflow steps.

Recommended Code Changes:

- name: Checkout code
  uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
  with:
    fetch-depth: 0
    persist-credentials: false

Comment thread .github/workflows/ci.yml
fetch-depth: 0

- name: Set up Go
uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: Disable caching in setup-go to prevent cache poisoning attacks in release pipelines.

Recommended Code Changes:

- name: Set up Go
  uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
  with:
    go-version: "1.25"
    cache: false

name: Release
runs-on: ubuntu-latest
steps:
- name: Checkout code

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: Add persist-credentials: false to the checkout action to prevent credentials from being accessible to subsequent workflow steps.

Recommended Code Changes:

- name: Checkout code
  uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
  with:
    fetch-depth: 0
    ref: ${{ inputs.tag || github.ref }}
    persist-credentials: false

fetch-depth: 0
ref: ${{ inputs.tag || github.ref }}

- name: Set up Go

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Issue: Disable caching in setup-go to prevent cache poisoning attacks in release pipelines where artifacts are published.

Recommended Code Changes:

- name: Set up Go
  uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
  with:
    go-version: "1.25"
    cache: false

- Pin googleapis/release-please-action to commit hash (16a9c90)
- Add persist-credentials: false to checkout actions in release workflows
- Disable Go module caching in release pipelines to prevent cache poisoning

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
@kusari-inspector

Copy link
Copy Markdown

Kusari PR Analysis rerun based on - 65d46b5 performed at: 2026-01-24T00:57:36Z - link to updated analysis

@jmgilman
jmgilman merged commit c370975 into master Jan 24, 2026
7 checks passed
@jmgilman
jmgilman deleted the feat/release-automation branch January 24, 2026 01:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant