Release binaries for linux amd64 and arm64

Pushing a v* tag runs .github/workflows/release.yml: vet, test,
govulncheck, then scripts/build-release.sh builds reproducible archives
for linux/amd64 and linux/arm64 with a SHA256SUMS file, and attaches
them to the release. workflow_dispatch takes a tag for a run that never
started. Same shape as ihasmail-oneshot's releases.

Adds a version subcommand, set at build time.

go.mod moves to 1.26.8: the workflow builds with the go.mod version,
and govulncheck finds four standard-library vulnerabilities the tool
reaches in 1.26.5 (GO-2026-6218, GO-2026-6090, GO-2026-5972,
GO-2026-5026), all fixed in 1.26.6.

README installs from the latest release, with building from source as
the alternative; CONTRIBUTING describes how releases are cut.
This commit is contained in:
2026-09-15 14:26:05 -07:00
parent f3a4d021ab
commit 0543931616
6 changed files with 157 additions and 15 deletions
+7 -1
View File
@@ -13,6 +13,9 @@ import (
"os"
)
// version is set at build time: -ldflags "-X main.version=...".
var version = "dev"
func main() {
if len(os.Args) < 2 {
usage()
@@ -33,6 +36,8 @@ func main() {
err = runStatus(os.Args[2:])
case "report":
err = runReport(os.Args[2:])
case "version", "--version":
fmt.Println("stalwart-migrate", version)
default:
usage()
os.Exit(1)
@@ -53,5 +58,6 @@ commands:
run perform the migration (needs --yes and --recovery-point-confirmed)
tenants show which tenant owns which domain, and what blocks a migration (read-only)
status show the state of an in-progress or completed run
report print the validation report for a run`)
report print the validation report for a run
version print the version of this binary`)
}