From 60c87da38e0a88e0efdfd8ff2b7cffa4b265fbe4 Mon Sep 17 00:00:00 2001 From: Bryan Van Deusen Date: Tue, 6 Oct 2026 10:00:24 -0400 Subject: [PATCH] ci(govulncheck): check out with plain git; the golang image has no node (M462 #4984) actions/checkout runs on node, which golang:1.26-bookworm does not carry, so the lane died at checkout (run 8272, exit 127) before scanning anything. That run was also the gate's first red: every other lane passed, and image-release and release-assets both skipped, leaving :dev on the previous build. Co-Authored-By: Claude Opus 5.5 --- .gitea/workflows/release.yml | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index d60c0ddf..6a0bf115 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -383,8 +383,19 @@ jobs: image: golang:1.26-bookworm steps: + # Plain git, not actions/checkout: that action runs on node, which the + # golang image does not carry. This step is dash (rule 81). - name: Checkout - uses: actions/checkout@v4 + env: + TOKEN: ${{ github.token }} + run: | + set -eu + auth=$(printf 'x-access-token:%s' "$TOKEN" | base64 -w0) + git init -q . + git remote add origin "${{ github.server_url }}/${{ github.repository }}.git" + git -c http.extraHeader="Authorization: Basic ${auth}" fetch -q --depth 1 origin "${{ github.sha }}" + git checkout -q FETCH_HEAD + git log -1 --format='%H %s' - name: govulncheck run: |