| CI | =build= (build, vet) and =test= (full suite against real git, ssh, sshd, gpg) on every push; =vuln= (govulncheck) nightly and before release (=.gitbay/ci.yml=) |
90
90
| Static checks | =deploy/audit.sh=: vet, govulncheck, short fuzz runs of the pkt-line, commit, signature, PGP key and tokenizer parsers |
91
91
| Build | =CGO_ENABLED=0 -trimpath -ldflags='-s -w -buildid='= for reproducible binaries; the commit is stamped in (=deploy/release.sh=, =Makefile=) |
92
| Release | =SHA256SUMS= for every binary; a minisign signature of the manifest when the release key is present (optional) |
92
| Release | binaries gzipped; =SHA256SUMS= for every archive; a minisign signature of the manifest when the release key is present (optional) |
93
93
| Distribution | release assets on the forge; Homebrew formula in krz/homebrew-tap built from the tag; push mirror to GitHub (read-only copy) |
94
94
| Deploy | =make deploy= refuses a dirty tree, then copies, checks config and restarts over operator SSH |
95
95
| CI image | built on the host from =deploy/Containerfile.ci= (=golang:1.27-trixie= plus git-lfs, gnupg, openssh, python3, sqlite3); tagged, never pulled at build time |
deploy/release.sh+4−2
@@ -1,12 +1,13 @@
1
1
#!/bin/sh
2
2
# Build release binaries for a tag: reproducible cross-compiled gitbay,
3
# gitbayd and gitbay-runner with a checksum manifest.
3
# gitbayd and gitbay-runner, each gzipped, with a checksum manifest.