-
Notifications
You must be signed in to change notification settings - Fork 0
GitHub Action
danielriddell21/letsgo-action installs letsgo on a runner and runs it. It lives in its own repository, versioned separately from the binary it runs — the action is packaging rather than tooling.
name: release
on:
push:
tags: ["v*"]
permissions:
contents: write # create the release and upload assets
id-token: write # provenance attestation
attestations: write
packages: write # only if you publish a container image
jobs:
release:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
- uses: danielriddell21/letsgo-action@v1A shallow clone is fine. letsgo falls back to the GitHub compare API when the changelog needs history the runner does not have.
| Input | Default | Description |
|---|---|---|
version |
a pinned tag | The letsgo release to install, or latest
|
command |
release |
release, plan, build, verify, diff, tag, yank, or empty to install only |
args |
"" |
Extra arguments, split on whitespace |
working-directory |
. |
Where to run |
token |
github.token |
The forge token letsgo publishes with |
| Output | Description |
|---|---|
letsgo-version |
The letsgo version that ran |
version |
The project version that was built or published, without a leading v
|
release-url |
The release page, when a release was published |
manifest |
Path to the letsgo.json letsgo wrote |
Outputs come from the manifest rather than from parsing stdout — it is the file letsgo writes precisely so machines do not have to read the part meant for people.
- uses: danielriddell21/letsgo-action@v1
id: release
- run: echo "published ${{ steps.release.outputs.release-url }}"plan resolves and gates a release without building one, in about two seconds:
- uses: danielriddell21/letsgo-action@v1
with:
command: plan
args: --explain - uses: danielriddell21/letsgo-action@v1
with:
command: ""
- run: letsgo plan && letsgo buildletsgo decides the archive layout and the linker flags, so it is a build input like the compiler. A release built by a version you did not choose is a release you cannot reproduce. version: latest is available and is the wrong default. Bump the pin deliberately — Dependabot offers it when you pin the action by tag.
go install github.com/danielriddell21/letsgo/cmd/letsgo@<version>.
The module proxy checks what it fetches against the public checksum database, which is a stronger guarantee than any digest the action could carry, and it works on every runner without a platform matrix. The cost is a short compile; letsgo has no dependencies, so it is short.
Go is a prerequisite, not something the action installs. The Go version changes the bytes of the binaries you ship, so choosing it belongs to the workflow that knows which one your project releases with. The action fails with a clear message if Go is missing.
contents: write is the only one a plain release needs. Add id-token: write and attestations: write for build provenance, and packages: write for a container image.
A Homebrew tap lives in another repository, and the workflow token cannot write to one: that needs a PAT or an App token passed as token. See Publishing.