Skip to content

Release

Release #41

Workflow file for this run

name: Release
on:
push:
tags: ['v*']
# Least privilege by default (audit T61): the workflow as a whole is
# read-only; only the publishing job escalates to contents: write.
permissions:
contents: read
jobs:
verify:
# The exact commit being released must pass the same gates CI runs —
# previously the tag pipeline published without running a single test
# (audit F64).
uses: ./.github/workflows/ci.yml
release:
needs: verify
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
with:
fetch-depth: 0
- uses: actions/setup-go@40f1582b2485089dde7abd97c1529aa768e1baff # v5.6.0
with:
go-version: '1.26'
- uses: goreleaser/goreleaser-action@e435ccd777264be153ace6237001ef4d979d3a7a # v6.4.0
with:
version: latest
args: release --clean
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
HOMEBREW_TAP_GITHUB_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}