Compare commits
2 Commits
4714bfe272
...
44f499dc52
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
44f499dc52 | ||
|
|
43827593e7 |
@@ -40,6 +40,7 @@ A `### Breaking` section is used in addition to Keep a Changelog's standard sect
|
||||
- Pinned `securego/gosec` and `golang/govulncheck-action` to concrete version tags (`v2.22.4` and `v1.0.4`) so self-hosted Gitea runners can resolve them via direct git clone without relying on the GitHub Actions floating-tag API.
|
||||
- Restored explicit gosec caching by storing a pinned `v2.22.4` binary under `${{ runner.temp }}/gosec-bin` with `actions/cache@v4`, so CI keeps fast security scans while still using the Go 1.26 toolchain from `setup-go`.
|
||||
- Replaced `securego/gosec` composite action with a direct `go install github.com/securego/gosec/v2/cmd/gosec@v2.22.4 && gosec ./...` run step so gosec uses the Go 1.26 toolchain installed by `setup-go` rather than the action's bundled Go 1.24 binary which ignores `GOTOOLCHAIN=auto`.
|
||||
- Fixed nested local composite-action references to use `./../run-vociferate` (instead of `../run-vociferate`) so strict runners that enforce `{org}/{repo}[/path]@ref` for non-local paths correctly classify them as local actions.
|
||||
|
||||
## [1.0.2] - 2026-03-21
|
||||
|
||||
|
||||
@@ -164,7 +164,7 @@ runs:
|
||||
- name: Extract changelog unreleased entries
|
||||
id: extract-changelog
|
||||
if: steps.changelog-file.outputs.exists == 'true'
|
||||
uses: ../run-vociferate
|
||||
uses: ./../run-vociferate
|
||||
with:
|
||||
root: ${{ github.workspace }}
|
||||
changelog: ${{ inputs.changelog }}
|
||||
|
||||
@@ -66,7 +66,7 @@ runs:
|
||||
- name: Recommend version
|
||||
id: recommend-version
|
||||
if: steps.normalize-version.outputs.value == ''
|
||||
uses: ../run-vociferate
|
||||
uses: ./../run-vociferate
|
||||
with:
|
||||
root: ${{ github.workspace }}
|
||||
version-file: ${{ inputs.version-file }}
|
||||
@@ -102,7 +102,7 @@ runs:
|
||||
printf 'value=%s\n' "$(date -u +%F)" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Prepare release files
|
||||
uses: ../run-vociferate
|
||||
uses: ./../run-vociferate
|
||||
with:
|
||||
root: ${{ github.workspace }}
|
||||
version-file: ${{ inputs.version-file }}
|
||||
|
||||
@@ -65,7 +65,7 @@ runs:
|
||||
|
||||
- name: Extract release notes
|
||||
id: extract-notes
|
||||
uses: ../run-vociferate
|
||||
uses: ./../run-vociferate
|
||||
with:
|
||||
root: ${{ github.workspace }}
|
||||
changelog: ${{ inputs.changelog }}
|
||||
|
||||
Reference in New Issue
Block a user