diff --git a/.crabbox.yaml b/.crabbox.yaml index c99d875..c202e75 100644 --- a/.crabbox.yaml +++ b/.crabbox.yaml @@ -24,7 +24,7 @@ actions: ephemeral: true aws: region: eu-west-1 - rootGB: 160 + rootGB: 400 sync: delete: true checksum: false diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a663c9a..1fb9f59 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -30,7 +30,7 @@ jobs: run: make lint-check GOLANGCI_LINT=golangci-lint - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: - node-version: "26.8.2" + node-version: "26.10.0" - name: Documentation metadata run: | node --test scripts/llms-metadata.test.mjs @@ -88,13 +88,13 @@ jobs: - uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 with: distribution: goreleaser - version: v2.18.1 + version: v2.18.2 args: check --config .goreleaser.yml - name: Build credential-free snapshot uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 with: distribution: goreleaser - version: v2.18.1 + version: v2.18.2 args: release --snapshot --clean --skip=publish --config .goreleaser.yml - name: Snapshot binary vulnerability scan env: diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e839040..b17f6c0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -56,7 +56,7 @@ jobs: uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3 with: distribution: goreleaser - version: v2.18.1 + version: v2.18.2 args: release --snapshot --clean --skip=publish --config .goreleaser.yml - name: Snapshot binary vulnerability scan env: diff --git a/scripts/recheck-release-source.sh b/scripts/recheck-release-source.sh index 7be902a..2b2ebbd 100755 --- a/scripts/recheck-release-source.sh +++ b/scripts/recheck-release-source.sh @@ -12,7 +12,7 @@ readonly grep_bin=/usr/bin/grep readonly official_origin=https://github.com/openclaw/goplaces.git readonly system_path=/usr/bin:/bin:/usr/sbin:/sbin readonly expected_go_version=go1.26.8 -readonly expected_goreleaser_version=2.18.1 +readonly expected_goreleaser_version=2.18.2 die() { echo "release source recheck: $*" >&2 diff --git a/scripts/release-local b/scripts/release-local index 97f2689..6a9b2ce 100755 --- a/scripts/release-local +++ b/scripts/release-local @@ -36,11 +36,11 @@ readonly GREP_BIN="/usr/bin/grep" readonly CMP_BIN="/usr/bin/cmp" readonly TAR_BIN="/usr/bin/bsdtar" readonly UNAME_BIN="/usr/bin/uname" -readonly EXPECTED_GORELEASER_VERSION="2.18.1" -readonly EXPECTED_NODE_VERSION="v26.8.2" +readonly EXPECTED_GORELEASER_VERSION="2.18.2" +readonly EXPECTED_NODE_VERSION="v26.9.0" readonly EXPECTED_EXPECT_VERSION="expect version 5.45.4" readonly EXPECTED_PYTHON_VERSION="Python 3.14.7" -readonly EXPECTED_GH_VERSION="2.100.0" +readonly EXPECTED_GH_VERSION="2.101.0" readonly EXPECTED_JQ_VERSION="jq-1.8.2" readonly EXPECTED_GOVULNCHECK_MODULE_SUM="h1:clG4qBU6zH5VKjti8n5j8BBuYzoSha392xXMkXS351U=" @@ -235,8 +235,8 @@ resolve_producer_tools() { resolved_python="$(resolve_executable python3)" if [[ "${GOPLACES_RELEASE_LOCAL_TESTING:-0}" != 1 ]]; then [[ "$resolved_go" =~ ^(/opt/homebrew|/usr/local)/Cellar/go(@1\.26)?/1\.26\.8/libexec/bin/go$ ]] || die "Go must resolve to the canonical Homebrew 1.26.8 executable" - [[ "$resolved_goreleaser" =~ ^(/opt/homebrew|/usr/local)/Cellar/goreleaser/2\.18\.1/bin/goreleaser$ ]] || die "GoReleaser must resolve to the canonical Homebrew 2.18.1 executable" - [[ "$resolved_node" =~ ^(/opt/homebrew|/usr/local)/Cellar/node/26\.8\.2/bin/node$ ]] || die "Node must resolve to the reviewed Homebrew 26.8.2 executable" + [[ "$resolved_goreleaser" =~ ^(/opt/homebrew|/usr/local)/Cellar/goreleaser/2\.18\.2/bin/goreleaser$ ]] || die "GoReleaser must resolve to the canonical Homebrew 2.18.2 executable" + [[ "$resolved_node" =~ ^(/opt/homebrew|/usr/local)/Cellar/node/26\.9\.0/bin/node$ ]] || die "Node must resolve to the reviewed Homebrew 26.9.0 executable" [[ "$resolved_expect" =~ ^(/opt/homebrew|/usr/local)/Cellar/expect/5\.45\.4_3/bin/expect$ ]] || die "Expect must resolve to the canonical Homebrew 5.45.4_3 executable" [[ "$resolved_python" =~ ^(/opt/homebrew|/usr/local)/Cellar/python@3\.14/3\.14\.7/Frameworks/Python\.framework/Versions/3\.14/bin/python3\.14$ ]] || die "Python must resolve to the canonical Homebrew 3.14.7 executable" producer_go_root="${resolved_go%/bin/go}" diff --git a/scripts/test-release-local.sh b/scripts/test-release-local.sh index d0045ec..475f2e2 100755 --- a/scripts/test-release-local.sh +++ b/scripts/test-release-local.sh @@ -208,8 +208,8 @@ EOF grep -Fq 'HOMEBREW_NO_INSTALL_FROM_API=1' "$release_script" || die "Homebrew package inventory can trigger API installation" grep -Fq 'homebrew_command list "$kind_flag" --full-name' "$release_script" || die "Homebrew installed-state proof is not a no-name full inventory" grep -Fq 'homebrew_command --prefix --formula goplaces' "$release_script" || die "installed binary lookup is not Formula-specific" - grep -Fq 'readonly EXPECTED_GH_VERSION="2.100.0"' "$release_script" || die "GitHub CLI version is not pinned" - grep -Fq 'Cellar/node/26\.8\.2/bin/node' "$release_script" || die "reviewed Node formula revision is not allowlisted" + grep -Fq 'readonly EXPECTED_GH_VERSION="2.101.0"' "$release_script" || die "GitHub CLI version is not pinned" + grep -Fq 'Cellar/node/26\.9\.0/bin/node' "$release_script" || die "reviewed Node formula revision is not allowlisted" grep -Fq 'candidate=/opt/homebrew/opt/gh/bin/gh' "$release_script" || die "GitHub CLI does not bypass the mutable bin wrapper" ! grep -Fq 'candidate=/opt/homebrew/bin/gh' "$release_script" || die "GitHub CLI still freezes the mutable wrapper" grep -Fq "select(.path == \$path)" "$release_script" || die "workflow path is not exact" @@ -1186,7 +1186,7 @@ EOF #!/bin/bash -p set -euo pipefail if [[ "$*" == --version ]]; then - printf 'GitVersion: 2.18.1\n' + printf 'GitVersion: 2.18.2\n' exit 0 fi [[ "${1:-}" == release ]] || exit 92 @@ -1334,7 +1334,7 @@ EOF #!/bin/bash -p set -euo pipefail [[ "$*" == --version ]] || exit 93 -printf 'v26.8.2\n' +printf 'v26.9.0\n' EOF cat > "${directory}/expect" <<'EOF' #!/bin/bash -p @@ -1371,7 +1371,7 @@ test_producer_gate_hardening() { alias_tmp="${scratch}/tmp-alias" mkdir -p "$real_tmp" ln -s "$real_tmp" "$alias_tmp" - make_fake_producer_tools "$tools" go1.26.8 2.18.1 + make_fake_producer_tools "$tools" go1.26.8 2.18.2 mkdir -p "$launch" ln -s "${tools}/go" "${launch}/go" ln -s "${tools}/goreleaser" "${launch}/goreleaser" @@ -1436,7 +1436,7 @@ EOF [[ ! -e "$sentinel" ]] || die "hostile PATH utility executed during producer resolution" old_go="${scratch}/old-go" - make_fake_producer_tools "$old_go" go1.26.4 2.18.1 + make_fake_producer_tools "$old_go" go1.26.4 2.18.2 if ( export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper" source "$release_script" @@ -1459,7 +1459,7 @@ EOF fi mutation="${scratch}/mutation-tools" - make_fake_producer_tools "$mutation" go1.26.8 2.18.1 + make_fake_producer_tools "$mutation" go1.26.8 2.18.2 if ( export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper" source "$release_script" @@ -1472,7 +1472,7 @@ EOF ) >/dev/null 2>&1; then die "same-byte GoReleaser inode replacement was accepted" fi - make_fake_producer_tools "$mutation" go1.26.8 2.18.1 + make_fake_producer_tools "$mutation" go1.26.8 2.18.2 if ( export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper" source "$release_script" @@ -1484,7 +1484,7 @@ EOF ) >/dev/null 2>&1; then die "in-place Go byte mutation was accepted" fi - make_fake_producer_tools "$mutation" go1.26.8 2.18.1 + make_fake_producer_tools "$mutation" go1.26.8 2.18.2 if ( export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper" source "$release_script" @@ -1497,7 +1497,7 @@ EOF ) >/dev/null 2>&1; then die "same-byte release-mac-app replacement was accepted" fi - make_fake_producer_tools "$mutation" go1.26.8 2.18.1 + make_fake_producer_tools "$mutation" go1.26.8 2.18.2 if ( export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper" source "$release_script" @@ -1784,7 +1784,7 @@ EOF set -euo pipefail printf 'goreleaser' >> "$MOCK_LOG"; printf ' <%s>' "$@" >> "$MOCK_LOG"; printf '\n' >> "$MOCK_LOG" [[ "$*" == --version ]] || { echo "unexpected goreleaser command: $*" >&2; exit 90; } -printf 'GitVersion: %s\n' "${MOCK_GORELEASER_VERSION:-2.18.1}" +printf 'GitVersion: %s\n' "${MOCK_GORELEASER_VERSION:-2.18.2}" EOF cat > "${root}/mock-bin/gh" <<'EOF' #!/usr/bin/env bash @@ -1835,7 +1835,7 @@ fi EOF printf '# frozen mock helper library\n' > "${root}/mock-bin/lib/mac_release.sh" chmod +x "${root}/mock-bin/"* - write_fixture_producer_tools "$root" go1.26.8 2.18.1 + write_fixture_producer_tools "$root" go1.26.8 2.18.2 } write_fixture_producer_tools() { @@ -1857,7 +1857,7 @@ EOF #!/bin/bash -p set -euo pipefail [[ "$*" == --version ]] || exit 93 -printf 'v26.8.2\n' +printf 'v26.9.0\n' EOF cat > "${root}/mock-bin/expect" <<'EOF' #!/bin/bash -p @@ -1891,7 +1891,7 @@ run_fixture() { hostile_environment+=("${name}=${!name}") fi done - write_fixture_producer_tools "$root" "${MOCK_GO_VERSION:-go1.26.8}" "${MOCK_GORELEASER_VERSION:-2.18.1}" + write_fixture_producer_tools "$root" "${MOCK_GO_VERSION:-go1.26.8}" "${MOCK_GORELEASER_VERSION:-2.18.2}" ( cd "$root" /usr/bin/env -i \ @@ -1899,7 +1899,7 @@ run_fixture() { PATH="${root}/mock-bin:/opt/homebrew/bin:/usr/bin:/bin" \ HOME="${root}/home" TMPDIR="${root}/tmp" MOCK_LOG="${root}/mock.log" \ MOCK_GO_VERSION="${MOCK_GO_VERSION:-go1.26.8}" MOCK_GIT_STATUS="${MOCK_GIT_STATUS:-}" \ - MOCK_GORELEASER_VERSION="${MOCK_GORELEASER_VERSION:-2.18.1}" \ + MOCK_GORELEASER_VERSION="${MOCK_GORELEASER_VERSION:-2.18.2}" \ MOCK_ORIGIN="${MOCK_ORIGIN:-https://github.com/openclaw/goplaces}" MOCK_BRANCH="${MOCK_BRANCH:-main}" MOCK_SHA="$SHA" \ MOCK_PROTECTED="${MOCK_PROTECTED:-true}" MOCK_API_SHA="${MOCK_API_SHA:-$SHA}" \ MOCK_FIXTURE_ROOT="$root" MOCK_FRESH_STATUS="${MOCK_FRESH_STATUS:-}" \ diff --git a/scripts/test-security-ci.sh b/scripts/test-security-ci.sh index dd454b2..3be8915 100755 --- a/scripts/test-security-ci.sh +++ b/scripts/test-security-ci.sh @@ -152,7 +152,7 @@ raise "missing active source scan" unless run_lines.any? { |line| line.match?(%r snapshot = steps.find { |step| step["run"].to_s.strip == "./scripts/verify-snapshot-security.sh" } raise "snapshot clean gate missing" unless snapshot&.fetch("env", {})&.fetch("SNAPSHOT_REQUIRE_CLEAN", nil).to_s == "1" goreleaser = steps.find { |step| step["uses"] == "goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94" && step.fetch("with", {})["args"] == "release --snapshot --clean --skip=publish --config .goreleaser.yml" } -raise "active GoReleaser snapshot missing" unless goreleaser && goreleaser.fetch("with", {})["version"] == "v2.18.1" +raise "active GoReleaser snapshot missing" unless goreleaser && goreleaser.fetch("with", {})["version"] == "v2.18.2" RUBY } @@ -160,7 +160,7 @@ assert_workflow_proof() { local workflow="$1" local contract_test - require_code_pattern "$workflow" '^[[:space:]]+version:[[:space:]]+v2\.18\.1[[:space:]]*$' "GoReleaser v2.18.1 pin" + require_code_pattern "$workflow" '^[[:space:]]+version:[[:space:]]+v2\.18\.2[[:space:]]*$' "GoReleaser v2.18.2 pin" require_code_pattern "$workflow" '^[[:space:]]+args:[[:space:]]+release --snapshot --clean --skip=publish --config \.goreleaser\.yml[[:space:]]*$' "non-publishing snapshot" require_code_pattern "$workflow" '^[[:space:]]+run:[[:space:]]+go install golang\.org/x/vuln/cmd/govulncheck@v1\.8\.0[[:space:]]*$' "govulncheck v1.8.0 install" # shellcheck disable=SC2016