name: Release on: push: tags: - v* permissions: contents: write packages: write id-token: write jobs: Release: runs-on: ubuntu-latest env: DOCKER_CLI_EXPERIMENTAL: "enabled" steps: # Setup steps - no external side effects. - name: Checkout uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6 with: fetch-depth: 0 - name: Set up QEMU uses: docker/setup-qemu-action@1f40c72289eff860ee54a304f1438e3cff362e0a # v4 - name: Docker Login to DockerHub uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Docker Login to GitHub Container Registry uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4 with: registry: ghcr.io username: ${{ github.repository_owner }} password: ${{ secrets.GITHUB_TOKEN }} - name: Set up Go uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6 with: go-version: "1.27" - name: Cosign install uses: sigstore/cosign-installer@7e8b541eb2e61bf99390e1afd4be13a184e9ebc5 # v3.10.1 - name: Install UPX run: | sudo apt-get update sudo apt-get install -y upx # GoReleaser pipeline (sequential, not atomic): # 1. build + archive + checksum + sign (local only, no side effects) # 2. homebrew tap update (commit to trufflesecurity/homebrew-trufflehog) # 3. docker images + manifests (DockerHub + GHCR, including :latest tags) # 4. github release creation (artifacts uploaded, make_latest: false) # # On failure: GoReleaser does not roll back completed phases. Depending # on where it failed, some subset of the above may have been published. # Check: # - Homebrew tap: https://github.com/trufflesecurity/homebrew-trufflehog # - DockerHub: https://hub.docker.com/r/trufflesecurity/trufflehog/tags # - GHCR: https://github.com/trufflesecurity/trufflehog/pkgs/container/trufflehog # - GH releases: https://github.com/trufflesecurity/trufflehog/releases # # If the GitHub release was created but artifacts are missing, the # install script (scripts/install.sh) will fail for users on that # version. The release is NOT marked latest (make_latest: false), so # /releases/latest still points to the previous good release. - name: Run GoReleaser uses: goreleaser/goreleaser-action@f06c13b6b1a9625abc9e6e439d9c05a8f2190e94 # v7 with: distribution: goreleaser-pro version: latest args: release --clean env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} HOMEBREW_TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }} GORELEASER_KEY: ${{ secrets.GORELEASER_KEY }} # Promotes the GitHub release to "latest" only after the Release job fully # succeeds (including post-steps). At this point, all artifacts have been # published: Docker images and :latest tags are live, the Homebrew tap is # updated, binaries are attached to the GitHub release, and checksums are # signed. # # If this job fails, the release exists with all artifacts but is not flagged # as latest. /releases/latest and scripts/install.sh still point to the # previous release. To manually promote: # gh release edit --latest --repo trufflesecurity/trufflehog mark-latest: needs: Release runs-on: ubuntu-latest steps: - name: Mark release as latest run: gh release edit "$TAG" --latest env: GH_TOKEN: ${{ github.token }} GH_REPO: ${{ github.repository }} TAG: ${{ github.ref_name }}