ci(release): refuse a tag the security policy does not name
Assisted-by: DeepSeek V4.1 Flash
This commit is contained in:
@@ -55,6 +55,25 @@ jobs:
|
|||||||
print qq{tag $v\n};
|
print qq{tag $v\n};
|
||||||
'
|
'
|
||||||
|
|
||||||
|
- name: Security policy names this release
|
||||||
|
# The supported-versions table is the one part of SECURITY.md that
|
||||||
|
# carries a version, so it goes stale the moment a tag is cut. Fail
|
||||||
|
# here rather than publish a policy naming the previous release.
|
||||||
|
env:
|
||||||
|
VERSION: ${{ gitea.ref_name }}
|
||||||
|
run: |
|
||||||
|
perl -e '
|
||||||
|
my $v = $ENV{VERSION} // q{};
|
||||||
|
(my $nv = $v) =~ s/^v//;
|
||||||
|
open(my $f, q{<}, q{SECURITY.md}) or die qq{SECURITY.md: $!\n};
|
||||||
|
local $/;
|
||||||
|
my $t = <$f>;
|
||||||
|
close $f;
|
||||||
|
$t =~ m{^\|\s*\Q$nv\E\s*\|\s*yes\s*\|}m
|
||||||
|
or die qq{ERROR: SECURITY.md does not name $nv as supported; update the table before releasing.\n};
|
||||||
|
print qq{SECURITY.md names $nv\n};
|
||||||
|
'
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
run: go build ./...
|
run: go build ./...
|
||||||
|
|
||||||
@@ -78,6 +97,11 @@ jobs:
|
|||||||
# The same command as in test.yml, so the floor is the same number everywhere.
|
# The same command as in test.yml, so the floor is the same number everywhere.
|
||||||
run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./arch/... ./asm/... ./ast/... ./disasm/... ./format/... ./lexer/... ./lint/... ./lsp/... ./parser/... ./token/... ./verify/...
|
run: go test -count=1 -timeout 10m -coverprofile=coverage.out ./arch/... ./asm/... ./ast/... ./disasm/... ./format/... ./lexer/... ./lint/... ./lsp/... ./parser/... ./token/... ./verify/...
|
||||||
|
|
||||||
|
- name: Tests outside the coverage set
|
||||||
|
# The same command as in test.yml: the CLI's exit codes and manual-page guard,
|
||||||
|
# and the debugger's architecture-neutral units, run outside the floor.
|
||||||
|
run: go test -count=1 -timeout 10m ./cmd/... ./debug/...
|
||||||
|
|
||||||
- name: Coverage floor
|
- name: Coverage floor
|
||||||
run: |
|
run: |
|
||||||
perl -e '
|
perl -e '
|
||||||
|
|||||||
Reference in New Issue
Block a user