Skip to content

Releases: xraph/workflows

v1.18.0

Choose a tag to compare

@github-actions github-actions released this 05 Sep 15:56
1fb7007

What's Changed

  • feat(go-ci): warm the build cache before linting, and let callers set the timeout by @juicycleff in #8

Full Changelog: v1.17.0...v1.18.0

v1.17.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 16:58
88a2fe6

What's Changed

  • feat(go-ci): fetch private modules when given a token by @juicycleff in #5

Full Changelog: v1.16.0...v1.17.0

v1.16.0

Choose a tag to compare

@github-actions github-actions released this 27 Aug 01:46
6695b98

What's Changed

  • Catch and fix nested modules that require unpublishable versions by @juicycleff in #4

Full Changelog: v1.15.0...v1.16.0

v1.15.0

Choose a tag to compare

@github-actions github-actions released this 17 Aug 16:58
fb1d0f5

What's Changed

  • fix(go-ci): resolve a bare Go minor to the newest patch by @juicycleff in #3

Full Changelog: v1.14.0...v1.15.0

v1.14.0

Choose a tag to compare

@github-actions github-actions released this 11 Aug 22:15
86abd01

What's Changed

  • feat(pub-publish): add a reusable pub.dev publish workflow by @juicycleff in #2

Full Changelog: v1.13.1...v1.14.0

v1.13.1

Choose a tag to compare

@github-actions github-actions released this 07 Aug 20:44
9e0edec

What's Changed

  • fix(go-binary-release): grant packages: write so GHCR pushes can succeed by @juicycleff in #1

Why

go-binary-release.yml's goreleaser job declared permissions: contents: write and nothing else. Once a permissions: block exists, everything unlisted is none — so GITHUB_TOKEN had packages: none, while the docker: true path logs into the registry as exactly that token and then pushes. Releases built fully and then failed at the last step with:

denied: installation not allowed to Write organization package

That message reads like a registry ACL problem and is not one: the token had no packages scope to exercise, so granting a repository write access on the GHCR package changed nothing.

Callers could not work around it either — a reusable workflow's own permissions: block is authoritative for its jobs, so a caller declaring packages: write on the calling job had no effect, and GORELEASER_TOKEN never reaches the login step, which hardcodes secrets.GITHUB_TOKEN.

Harmless when docker is false: nothing authenticates to a registry on that path, so the scope goes unused.

For callers pinned at @v1

The v1 tag has been moved to this commit, so uses: xraph/workflows/.github/workflows/go-binary-release.yml@v1 picks this up on the next run — no change needed on your side.

Full Changelog: v1.13.0...v1.13.1

v1.13.0

Choose a tag to compare

@github-actions github-actions released this 06 Aug 20:31

Full Changelog: v1.12.2...v1.13.0

v1.12.2

Choose a tag to compare

@github-actions github-actions released this 04 Aug 23:10

Full Changelog: v1.12.1...v1.12.2

v1.12.1

Choose a tag to compare

@github-actions github-actions released this 04 Aug 03:05

Full Changelog: v1.12.0...v1.12.1

v1.12.0

Choose a tag to compare

@github-actions github-actions released this 03 Aug 01:43

Full Changelog: v1.11.0...v1.12.0