From 2931bbd6b2b99e0060b584c8e9e5d731bd3fa8d3 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Petr=20Balv=C3=ADn?= Date: Sun, 20 Sep 2026 01:40:51 +0200 Subject: [PATCH] ci(release): refuse a tag the security policy does not name Assisted-by: DeepSeek V4.1 Flash --- .gitea/workflows/release.yml | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 58a37d6..fda6674 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -55,6 +55,25 @@ jobs: print qq{tag $v\n}; ' + - name: Security policy names this release + # The supported-versions table is the one part of SECURITY.md that + # carries a version, so it goes stale the moment a tag is cut. Fail + # here rather than publish a policy naming the previous release. + env: + VERSION: ${{ gitea.ref_name }} + run: | + perl -e ' + my $v = $ENV{VERSION} // q{}; + (my $nv = $v) =~ s/^v//; + open(my $f, q{<}, q{SECURITY.md}) or die qq{SECURITY.md: $!\n}; + local $/; + my $t = <$f>; + close $f; + $t =~ m{^\|\s*\Q$nv\E\s*\|\s*yes\s*\|}m + or die qq{ERROR: SECURITY.md does not name $nv as supported; update the table before releasing.\n}; + print qq{SECURITY.md names $nv\n}; + ' + - name: Build run: go build ./... @@ -78,6 +97,11 @@ jobs: # The same command as in test.yml, so the floor is the same number everywhere. run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./arch/... ./asm/... ./ast/... ./disasm/... ./format/... ./lexer/... ./lint/... ./lsp/... ./parser/... ./token/... ./verify/... + - name: Tests outside the coverage set + # The same command as in test.yml: the CLI's exit codes and manual-page guard, + # and the debugger's architecture-neutral units, run outside the floor. + run: go test -count=1 -timeout 10m ./cmd/... ./debug/... + - name: Coverage floor run: | perl -e '