Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .crabbox.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ actions:
ephemeral: true
aws:
region: eu-west-1
rootGB: 160
rootGB: 400
sync:
delete: true
checksum: false
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ jobs:
run: make lint-check GOLANGCI_LINT=golangci-lint
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "26.8.2"
node-version: "26.10.0"
- name: Documentation metadata
run: |
node --test scripts/llms-metadata.test.mjs
Expand Down Expand Up @@ -88,13 +88,13 @@ jobs:
- uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
distribution: goreleaser
version: v2.18.1
version: v2.18.2
args: check --config .goreleaser.yml
- name: Build credential-free snapshot
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
distribution: goreleaser
version: v2.18.1
version: v2.18.2
args: release --snapshot --clean --skip=publish --config .goreleaser.yml
- name: Snapshot binary vulnerability scan
env:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,7 @@ jobs:
uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7.2.3
with:
distribution: goreleaser
version: v2.18.1
version: v2.18.2
args: release --snapshot --clean --skip=publish --config .goreleaser.yml
- name: Snapshot binary vulnerability scan
env:
Expand Down
2 changes: 1 addition & 1 deletion scripts/recheck-release-source.sh
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ readonly grep_bin=/usr/bin/grep
readonly official_origin=https://github.com/openclaw/goplaces.git
readonly system_path=/usr/bin:/bin:/usr/sbin:/sbin
readonly expected_go_version=go1.26.8
readonly expected_goreleaser_version=2.18.1
readonly expected_goreleaser_version=2.18.2

die() {
echo "release source recheck: $*" >&2
Expand Down
10 changes: 5 additions & 5 deletions scripts/release-local
Original file line number Diff line number Diff line change
Expand Up @@ -36,11 +36,11 @@ readonly GREP_BIN="/usr/bin/grep"
readonly CMP_BIN="/usr/bin/cmp"
readonly TAR_BIN="/usr/bin/bsdtar"
readonly UNAME_BIN="/usr/bin/uname"
readonly EXPECTED_GORELEASER_VERSION="2.18.1"
readonly EXPECTED_NODE_VERSION="v26.8.2"
readonly EXPECTED_GORELEASER_VERSION="2.18.2"
readonly EXPECTED_NODE_VERSION="v26.9.0"
readonly EXPECTED_EXPECT_VERSION="expect version 5.45.4"
readonly EXPECTED_PYTHON_VERSION="Python 3.14.7"
readonly EXPECTED_GH_VERSION="2.100.0"
readonly EXPECTED_GH_VERSION="2.101.0"
readonly EXPECTED_JQ_VERSION="jq-1.8.2"
readonly EXPECTED_GOVULNCHECK_MODULE_SUM="h1:clG4qBU6zH5VKjti8n5j8BBuYzoSha392xXMkXS351U="

Expand Down Expand Up @@ -235,8 +235,8 @@ resolve_producer_tools() {
resolved_python="$(resolve_executable python3)"
if [[ "${GOPLACES_RELEASE_LOCAL_TESTING:-0}" != 1 ]]; then
[[ "$resolved_go" =~ ^(/opt/homebrew|/usr/local)/Cellar/go(@1\.26)?/1\.26\.8/libexec/bin/go$ ]] || die "Go must resolve to the canonical Homebrew 1.26.8 executable"
[[ "$resolved_goreleaser" =~ ^(/opt/homebrew|/usr/local)/Cellar/goreleaser/2\.18\.1/bin/goreleaser$ ]] || die "GoReleaser must resolve to the canonical Homebrew 2.18.1 executable"
[[ "$resolved_node" =~ ^(/opt/homebrew|/usr/local)/Cellar/node/26\.8\.2/bin/node$ ]] || die "Node must resolve to the reviewed Homebrew 26.8.2 executable"
[[ "$resolved_goreleaser" =~ ^(/opt/homebrew|/usr/local)/Cellar/goreleaser/2\.18\.2/bin/goreleaser$ ]] || die "GoReleaser must resolve to the canonical Homebrew 2.18.2 executable"
[[ "$resolved_node" =~ ^(/opt/homebrew|/usr/local)/Cellar/node/26\.9\.0/bin/node$ ]] || die "Node must resolve to the reviewed Homebrew 26.9.0 executable"
[[ "$resolved_expect" =~ ^(/opt/homebrew|/usr/local)/Cellar/expect/5\.45\.4_3/bin/expect$ ]] || die "Expect must resolve to the canonical Homebrew 5.45.4_3 executable"
[[ "$resolved_python" =~ ^(/opt/homebrew|/usr/local)/Cellar/python@3\.14/3\.14\.7/Frameworks/Python\.framework/Versions/3\.14/bin/python3\.14$ ]] || die "Python must resolve to the canonical Homebrew 3.14.7 executable"
producer_go_root="${resolved_go%/bin/go}"
Expand Down
30 changes: 15 additions & 15 deletions scripts/test-release-local.sh
Original file line number Diff line number Diff line change
Expand Up @@ -208,8 +208,8 @@ EOF
grep -Fq 'HOMEBREW_NO_INSTALL_FROM_API=1' "$release_script" || die "Homebrew package inventory can trigger API installation"
grep -Fq 'homebrew_command list "$kind_flag" --full-name' "$release_script" || die "Homebrew installed-state proof is not a no-name full inventory"
grep -Fq 'homebrew_command --prefix --formula goplaces' "$release_script" || die "installed binary lookup is not Formula-specific"
grep -Fq 'readonly EXPECTED_GH_VERSION="2.100.0"' "$release_script" || die "GitHub CLI version is not pinned"
grep -Fq 'Cellar/node/26\.8\.2/bin/node' "$release_script" || die "reviewed Node formula revision is not allowlisted"
grep -Fq 'readonly EXPECTED_GH_VERSION="2.101.0"' "$release_script" || die "GitHub CLI version is not pinned"
grep -Fq 'Cellar/node/26\.9\.0/bin/node' "$release_script" || die "reviewed Node formula revision is not allowlisted"
grep -Fq 'candidate=/opt/homebrew/opt/gh/bin/gh' "$release_script" || die "GitHub CLI does not bypass the mutable bin wrapper"
! grep -Fq 'candidate=/opt/homebrew/bin/gh' "$release_script" || die "GitHub CLI still freezes the mutable wrapper"
grep -Fq "select(.path == \$path)" "$release_script" || die "workflow path is not exact"
Expand Down Expand Up @@ -1186,7 +1186,7 @@ EOF
#!/bin/bash -p
set -euo pipefail
if [[ "$*" == --version ]]; then
printf 'GitVersion: 2.18.1\n'
printf 'GitVersion: 2.18.2\n'
exit 0
fi
[[ "${1:-}" == release ]] || exit 92
Expand Down Expand Up @@ -1334,7 +1334,7 @@ EOF
#!/bin/bash -p
set -euo pipefail
[[ "$*" == --version ]] || exit 93
printf 'v26.8.2\n'
printf 'v26.9.0\n'
EOF
cat > "${directory}/expect" <<'EOF'
#!/bin/bash -p
Expand Down Expand Up @@ -1371,7 +1371,7 @@ test_producer_gate_hardening() {
alias_tmp="${scratch}/tmp-alias"
mkdir -p "$real_tmp"
ln -s "$real_tmp" "$alias_tmp"
make_fake_producer_tools "$tools" go1.26.8 2.18.1
make_fake_producer_tools "$tools" go1.26.8 2.18.2
mkdir -p "$launch"
ln -s "${tools}/go" "${launch}/go"
ln -s "${tools}/goreleaser" "${launch}/goreleaser"
Expand Down Expand Up @@ -1436,7 +1436,7 @@ EOF
[[ ! -e "$sentinel" ]] || die "hostile PATH utility executed during producer resolution"

old_go="${scratch}/old-go"
make_fake_producer_tools "$old_go" go1.26.4 2.18.1
make_fake_producer_tools "$old_go" go1.26.4 2.18.2
if (
export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper"
source "$release_script"
Expand All @@ -1459,7 +1459,7 @@ EOF
fi

mutation="${scratch}/mutation-tools"
make_fake_producer_tools "$mutation" go1.26.8 2.18.1
make_fake_producer_tools "$mutation" go1.26.8 2.18.2
if (
export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper"
source "$release_script"
Expand All @@ -1472,7 +1472,7 @@ EOF
) >/dev/null 2>&1; then
die "same-byte GoReleaser inode replacement was accepted"
fi
make_fake_producer_tools "$mutation" go1.26.8 2.18.1
make_fake_producer_tools "$mutation" go1.26.8 2.18.2
if (
export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper"
source "$release_script"
Expand All @@ -1484,7 +1484,7 @@ EOF
) >/dev/null 2>&1; then
die "in-place Go byte mutation was accepted"
fi
make_fake_producer_tools "$mutation" go1.26.8 2.18.1
make_fake_producer_tools "$mutation" go1.26.8 2.18.2
if (
export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper"
source "$release_script"
Expand All @@ -1497,7 +1497,7 @@ EOF
) >/dev/null 2>&1; then
die "same-byte release-mac-app replacement was accepted"
fi
make_fake_producer_tools "$mutation" go1.26.8 2.18.1
make_fake_producer_tools "$mutation" go1.26.8 2.18.2
if (
export GOPLACES_RELEASE_LOCAL_TESTING=1 GOPLACES_RELEASE_LOCAL_SOURCE_ONLY=1 RELEASE_MAC_APP_BIN="$helper"
source "$release_script"
Expand Down Expand Up @@ -1784,7 +1784,7 @@ EOF
set -euo pipefail
printf 'goreleaser' >> "$MOCK_LOG"; printf ' <%s>' "$@" >> "$MOCK_LOG"; printf '\n' >> "$MOCK_LOG"
[[ "$*" == --version ]] || { echo "unexpected goreleaser command: $*" >&2; exit 90; }
printf 'GitVersion: %s\n' "${MOCK_GORELEASER_VERSION:-2.18.1}"
printf 'GitVersion: %s\n' "${MOCK_GORELEASER_VERSION:-2.18.2}"
EOF
cat > "${root}/mock-bin/gh" <<'EOF'
#!/usr/bin/env bash
Expand Down Expand Up @@ -1835,7 +1835,7 @@ fi
EOF
printf '# frozen mock helper library\n' > "${root}/mock-bin/lib/mac_release.sh"
chmod +x "${root}/mock-bin/"*
write_fixture_producer_tools "$root" go1.26.8 2.18.1
write_fixture_producer_tools "$root" go1.26.8 2.18.2
}

write_fixture_producer_tools() {
Expand All @@ -1857,7 +1857,7 @@ EOF
#!/bin/bash -p
set -euo pipefail
[[ "$*" == --version ]] || exit 93
printf 'v26.8.2\n'
printf 'v26.9.0\n'
EOF
cat > "${root}/mock-bin/expect" <<'EOF'
#!/bin/bash -p
Expand Down Expand Up @@ -1891,15 +1891,15 @@ run_fixture() {
hostile_environment+=("${name}=${!name}")
fi
done
write_fixture_producer_tools "$root" "${MOCK_GO_VERSION:-go1.26.8}" "${MOCK_GORELEASER_VERSION:-2.18.1}"
write_fixture_producer_tools "$root" "${MOCK_GO_VERSION:-go1.26.8}" "${MOCK_GORELEASER_VERSION:-2.18.2}"
(
cd "$root"
/usr/bin/env -i \
"${hostile_environment[@]}" \
PATH="${root}/mock-bin:/opt/homebrew/bin:/usr/bin:/bin" \
HOME="${root}/home" TMPDIR="${root}/tmp" MOCK_LOG="${root}/mock.log" \
MOCK_GO_VERSION="${MOCK_GO_VERSION:-go1.26.8}" MOCK_GIT_STATUS="${MOCK_GIT_STATUS:-}" \
MOCK_GORELEASER_VERSION="${MOCK_GORELEASER_VERSION:-2.18.1}" \
MOCK_GORELEASER_VERSION="${MOCK_GORELEASER_VERSION:-2.18.2}" \
MOCK_ORIGIN="${MOCK_ORIGIN:-https://github.com/openclaw/goplaces}" MOCK_BRANCH="${MOCK_BRANCH:-main}" MOCK_SHA="$SHA" \
MOCK_PROTECTED="${MOCK_PROTECTED:-true}" MOCK_API_SHA="${MOCK_API_SHA:-$SHA}" \
MOCK_FIXTURE_ROOT="$root" MOCK_FRESH_STATUS="${MOCK_FRESH_STATUS:-}" \
Expand Down
4 changes: 2 additions & 2 deletions scripts/test-security-ci.sh
Original file line number Diff line number Diff line change
Expand Up @@ -152,15 +152,15 @@ raise "missing active source scan" unless run_lines.any? { |line| line.match?(%r
snapshot = steps.find { |step| step["run"].to_s.strip == "./scripts/verify-snapshot-security.sh" }
raise "snapshot clean gate missing" unless snapshot&.fetch("env", {})&.fetch("SNAPSHOT_REQUIRE_CLEAN", nil).to_s == "1"
goreleaser = steps.find { |step| step["uses"] == "goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94" && step.fetch("with", {})["args"] == "release --snapshot --clean --skip=publish --config .goreleaser.yml" }
raise "active GoReleaser snapshot missing" unless goreleaser && goreleaser.fetch("with", {})["version"] == "v2.18.1"
raise "active GoReleaser snapshot missing" unless goreleaser && goreleaser.fetch("with", {})["version"] == "v2.18.2"
RUBY
}

assert_workflow_proof() {
local workflow="$1"
local contract_test

require_code_pattern "$workflow" '^[[:space:]]+version:[[:space:]]+v2\.18\.1[[:space:]]*$' "GoReleaser v2.18.1 pin"
require_code_pattern "$workflow" '^[[:space:]]+version:[[:space:]]+v2\.18\.2[[:space:]]*$' "GoReleaser v2.18.2 pin"
require_code_pattern "$workflow" '^[[:space:]]+args:[[:space:]]+release --snapshot --clean --skip=publish --config \.goreleaser\.yml[[:space:]]*$' "non-publishing snapshot"
require_code_pattern "$workflow" '^[[:space:]]+run:[[:space:]]+go install golang\.org/x/vuln/cmd/govulncheck@v1\.8\.0[[:space:]]*$' "govulncheck v1.8.0 install"
# shellcheck disable=SC2016
Expand Down
Loading