Files
kicad-zone-resistance/.gitea/workflows/build-pcm.yml
T
grabowski e71f373675
Build PCM package / build (push) Successful in 24s
Pin workflow actions to commit SHAs
Mutable tags on third-party actions could be repointed at code that
runs with the repo token; pin checkout, upload-artifact and
gitea-release-action to their current commits.
2026-07-15 19:54:19 +07:00

46 lines
1.4 KiB
YAML

name: Build PCM package
on:
push:
branches: [main]
tags: ["v*"]
workflow_dispatch:
jobs:
build:
runs-on: ubuntu-latest
steps:
# third-party actions pinned to commit SHAs: mutable tags could be
# repointed at malicious code that runs with repo/token access
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Check tag matches metadata.json version
if: startsWith(github.ref, 'refs/tags/v')
run: |
meta=$(python3 -c "import json; print(json.load(open('metadata.json'))['versions'][0]['version'])")
tag="${GITHUB_REF_NAME#v}"
if [ "$meta" != "$tag" ]; then
echo "tag v$tag does not match metadata.json version $meta" >&2
exit 1
fi
- name: Build package
run: python3 tools/build_package.py
- name: Upload artifact
uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3
with:
name: pcm-package
path: |
dist/*.zip
dist/metadata-registry.json
- name: Create release with the zip attached
if: startsWith(github.ref, 'refs/tags/v')
uses: akkuman/gitea-release-action@b8d9144f302c68610911db1aaf722708d5c02d94 # v1
with:
files: |
dist/*.zip
dist/metadata-registry.json
token: ${{ secrets.GITEA_TOKEN }}