ci(release): refuse a tag the security policy does not name
Assisted-by: DeepSeek V4.1 Flash
This commit is contained in:
@@ -55,6 +55,25 @@ jobs:
|
||||
print qq{tag $v\n};
|
||||
'
|
||||
|
||||
- name: Security policy names this release
|
||||
# The supported-versions table is the one part of SECURITY.md that
|
||||
# carries a version, so it goes stale the moment a tag is cut. Fail
|
||||
# here rather than publish a policy naming the previous release.
|
||||
env:
|
||||
VERSION: ${{ gitea.ref_name }}
|
||||
run: |
|
||||
perl -e '
|
||||
my $v = $ENV{VERSION} // q{};
|
||||
(my $nv = $v) =~ s/^v//;
|
||||
open(my $f, q{<}, q{SECURITY.md}) or die qq{SECURITY.md: $!\n};
|
||||
local $/;
|
||||
my $t = <$f>;
|
||||
close $f;
|
||||
$t =~ m{^\|\s*\Q$nv\E\s*\|\s*yes\s*\|}m
|
||||
or die qq{ERROR: SECURITY.md does not name $nv as supported; update the table before releasing.\n};
|
||||
print qq{SECURITY.md names $nv\n};
|
||||
'
|
||||
|
||||
- name: Build
|
||||
run: go build ./...
|
||||
|
||||
@@ -78,6 +97,11 @@ jobs:
|
||||
# The same command as in test.yml, so the floor is the same number everywhere.
|
||||
run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./arch/... ./asm/... ./ast/... ./disasm/... ./format/... ./lexer/... ./lint/... ./lsp/... ./parser/... ./token/... ./verify/...
|
||||
|
||||
- name: Tests outside the coverage set
|
||||
# The same command as in test.yml: the CLI's exit codes and manual-page guard,
|
||||
# and the debugger's architecture-neutral units, run outside the floor.
|
||||
run: go test -count=1 -timeout 10m ./cmd/... ./debug/...
|
||||
|
||||
- name: Coverage floor
|
||||
run: |
|
||||
perl -e '
|
||||
|
||||
Reference in New Issue
Block a user