Compare commits
6
Commits
5760eed824
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
42900ae1d5 | ||
|
|
f1aff4ba07 | ||
|
|
f5478cb50e | ||
|
|
f45ef16d98 | ||
|
|
139f7e73da | ||
|
|
8ba5d58f76 |
@@ -0,0 +1,96 @@
|
|||||||
|
# CI on the self-hosted Gitea, ported from .gitlab-ci.yml during the move off
|
||||||
|
# GitLab (2026-09-22). Gitea reads .gitea/workflows and ignores .github/ once
|
||||||
|
# this directory exists; .github/workflows stays as it was for GitHub.
|
||||||
|
#
|
||||||
|
# Every job runs in an image pinned by digest (tag in the trailing comment),
|
||||||
|
# and the only action used is coffey-labs/actions/checkout pinned by SHA. The
|
||||||
|
# instance resolves short `uses:` against itself, never GitHub, so nothing
|
||||||
|
# unreviewed can be pulled in.
|
||||||
|
#
|
||||||
|
# The shape is the same as before -- tag-driven, amd64 and arm64,
|
||||||
|
# reproducible. GitLab needed a generic package registry plus release-cli
|
||||||
|
# links; Gitea attaches the tarballs to the Release itself, as GitHub did, so
|
||||||
|
# the build and the release are one job and nothing is handed between jobs.
|
||||||
|
name: ci
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
tags: ["v*"]
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ${{ github.workflow }}-${{ github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: light
|
||||||
|
container:
|
||||||
|
image: golang:1.26-bookworm@sha256:a688600ca24f8a4d3ca77f95b0dd40704a9fc787c826660eb7ba0b641b8b175d # 1.26-bookworm
|
||||||
|
steps:
|
||||||
|
- uses: coffey-labs/actions/checkout@fab0c4d45e0162963965f1555df27b7bed5e20ec
|
||||||
|
- run: go vet ./...
|
||||||
|
- run: go test ./...
|
||||||
|
# Kept as `go run ...@latest` exactly as the workflow had it: the point
|
||||||
|
# of a vulnerability check is to use today's database, not a pinned copy
|
||||||
|
# of last month's.
|
||||||
|
- run: go run golang.org/x/vuln/cmd/govulncheck@latest ./...
|
||||||
|
|
||||||
|
release:
|
||||||
|
if: startsWith(github.ref, 'refs/tags/')
|
||||||
|
needs: [test]
|
||||||
|
runs-on: light
|
||||||
|
container:
|
||||||
|
image: golang:1.26-bookworm@sha256:a688600ca24f8a4d3ca77f95b0dd40704a9fc787c826660eb7ba0b641b8b175d # 1.26-bookworm
|
||||||
|
steps:
|
||||||
|
# Full history: the ancestry check below cannot be answered from a
|
||||||
|
# shallow clone. The checkout also fetches every branch as origin/*.
|
||||||
|
- uses: coffey-labs/actions/checkout@fab0c4d45e0162963965f1555df27b7bed5e20ec
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
# The workflow refused to release a tag that is not an ancestor of main,
|
||||||
|
# so that a release can never describe code that was never reviewed onto
|
||||||
|
# the default branch.
|
||||||
|
- shell: bash
|
||||||
|
env:
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
run: |
|
||||||
|
git merge-base --is-ancestor "$(git rev-parse "${TAG}^{commit}")" origin/main \
|
||||||
|
|| { echo "!! $TAG is not on main"; exit 1; }
|
||||||
|
# SOURCE_DATE_EPOCH is what makes the tarballs reproducible: without it
|
||||||
|
# every build stamps a new mtime and two builds of one tag differ.
|
||||||
|
- shell: bash
|
||||||
|
env:
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
run: |
|
||||||
|
SOURCE_DATE_EPOCH="$(git log -1 --format=%ct "$TAG")" scripts/build-release.sh "$TAG" dist
|
||||||
|
sha256sum dist/*.tar.gz
|
||||||
|
# Create the Release, then attach every file. Archive names carry no
|
||||||
|
# version, so /releases/latest/download/<name> always means the newest.
|
||||||
|
# The API is reached on the internal address so the uploads never cross
|
||||||
|
# Cloudflare. If an upload fails the half-made Release is deleted: a
|
||||||
|
# Release whose assets 404 is worse than no Release, since the install
|
||||||
|
# guide sends people straight at these URLs.
|
||||||
|
- shell: bash
|
||||||
|
env:
|
||||||
|
TAG: ${{ github.ref_name }}
|
||||||
|
TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
REPO: ${{ github.repository }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
# CI_SERVER_INTERNAL is set on every job container by the runner.
|
||||||
|
API="$CI_SERVER_INTERNAL/api/v1/repos/$REPO"
|
||||||
|
auth=(--header "Authorization: token $TOKEN")
|
||||||
|
id=$(curl --fail --silent --show-error "${auth[@]}" \
|
||||||
|
--header "Content-Type: application/json" \
|
||||||
|
--data "{\"tag_name\":\"$TAG\",\"name\":\"$TAG\",\"body\":\"Binaries for linux/amd64 and linux/arm64. Verify with SHA256SUMS.\"}" \
|
||||||
|
"$API/releases" | grep -o '^{"id":[0-9]*' | cut -d: -f2)
|
||||||
|
[ -n "$id" ] || { echo "!! could not create the release"; exit 1; }
|
||||||
|
for f in dist/*; do
|
||||||
|
n=$(basename "$f")
|
||||||
|
echo "uploading $n"
|
||||||
|
curl --fail --silent --show-error --output /dev/null "${auth[@]}" \
|
||||||
|
--form "attachment=@$f" "$API/releases/$id/assets?name=$n" \
|
||||||
|
|| { curl --silent "${auth[@]}" -X DELETE "$API/releases/$id"; exit 1; }
|
||||||
|
done
|
||||||
+1
-1
@@ -27,7 +27,7 @@ write access to the checkpoint directory.
|
|||||||
Releases are tagged by date, like ihasmail's: `v2026.9.15`, with `.1`, `.2`
|
Releases are tagged by date, like ihasmail's: `v2026.9.15`, with `.1`, `.2`
|
||||||
added for another release the same day. Binaries for `linux/amd64` and
|
added for another release the same day. Binaries for `linux/amd64` and
|
||||||
`linux/arm64` and a `SHA256SUMS` file are attached to every
|
`linux/arm64` and a `SHA256SUMS` file are attached to every
|
||||||
[release](https://github.com/Coffey-Labs/stalwart-migrator/releases).
|
[release](https://git.coffeylabs.org/coffey-labs/stalwart-migrator/releases).
|
||||||
|
|
||||||
Every release is built by the [release workflow](.github/workflows/release.yml)
|
Every release is built by the [release workflow](.github/workflows/release.yml)
|
||||||
from a tagged commit on `main`, after the tests and a known-vulnerabilities
|
from a tagged commit on `main`, after the tests and a known-vulnerabilities
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# stalwart-migrator
|
# stalwart-migrator
|
||||||
|
|
||||||
[](https://github.com/Coffey-Labs/stalwart-migrator/releases/latest)
|
[](https://git.coffeylabs.org/coffey-labs/stalwart-migrator/releases/latest)
|
||||||
[](LICENSE)
|
[](LICENSE)
|
||||||
[](https://docs.ihasmail.org/install/stalwart-migrator/)
|
[](https://docs.ihasmail.org/install/stalwart-migrator/)
|
||||||
|
|
||||||
@@ -9,7 +9,7 @@ checkpoint at every step so an interrupted run resumes instead of restarting,
|
|||||||
and automated validation that the server still works afterwards. Go, standard
|
and automated validation that the server still works afterwards. Go, standard
|
||||||
library only.
|
library only.
|
||||||
|
|
||||||
A companion to [**ihasmail**](https://github.com/Coffey-Labs/ihasmail), a
|
A companion to [**ihasmail**](https://git.coffeylabs.org/coffey-labs/ihasmail), a
|
||||||
JMAP-first webmail client for Stalwart. That one is what you read your mail in;
|
JMAP-first webmail client for Stalwart. That one is what you read your mail in;
|
||||||
this one gets the server underneath it onto a version that speaks the protocol
|
this one gets the server underneath it onto a version that speaks the protocol
|
||||||
it needs.
|
it needs.
|
||||||
@@ -60,8 +60,8 @@ Details: [Known Stalwart problems](docs/known-stalwart-problems.md).
|
|||||||
|
|
||||||
```sh
|
```sh
|
||||||
ARCH=amd64 # or arm64
|
ARCH=amd64 # or arm64
|
||||||
curl -fsSLO https://github.com/Coffey-Labs/stalwart-migrator/releases/latest/download/stalwart-migrate-linux-$ARCH.tar.gz
|
curl -fsSLO https://git.coffeylabs.org/coffey-labs/stalwart-migrator/releases/download/latest/stalwart-migrate-linux-$ARCH.tar.gz
|
||||||
curl -fsSLO https://github.com/Coffey-Labs/stalwart-migrator/releases/latest/download/SHA256SUMS
|
curl -fsSLO https://git.coffeylabs.org/coffey-labs/stalwart-migrator/releases/download/latest/SHA256SUMS
|
||||||
sha256sum --ignore-missing -c SHA256SUMS
|
sha256sum --ignore-missing -c SHA256SUMS
|
||||||
tar -xzf stalwart-migrate-linux-$ARCH.tar.gz
|
tar -xzf stalwart-migrate-linux-$ARCH.tar.gz
|
||||||
sudo install -m 0755 stalwart-migrate /usr/local/bin/
|
sudo install -m 0755 stalwart-migrate /usr/local/bin/
|
||||||
|
|||||||
Reference in New Issue
Block a user