ci: v4 builtin:checkout instead of hand-rolled git with token-in-URL
Test / test (push) Successful in 10s

builtin:checkout is native Go (no Node — the aarch64 klokka leg has none) and
keeps the job token out of the fetch URL (it was visible in process args on the
host runner).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Bendik Aagaard Lynghaug
2026-09-28 13:35:48 +02:00
co-authored by Claude Opus 4.8
parent 1c75dd5681
commit 8e35af8c99
+3 -8
View File
@@ -41,15 +41,10 @@ jobs:
SCCACHE_DIR: /var/local/sccache
SCCACHE_SERVER_PORT: "4228"
steps:
# Plain git: the aarch64 host runner has no Node.js for
# actions/checkout (same as uhhm/corp).
# v4 built-in checkout: native Go, needs no Node (the aarch64 host runner
# has none) and keeps the token out of a fetch URL.
- name: Checkout
run: |
git init -q .
git fetch -q --depth 1 "https://ci:${{ gitea.token }}@${GITEA_SERVER#https://}/${{ gitea.repository }}.git" "${{ gitea.sha }}"
git checkout -q FETCH_HEAD
env:
GITEA_SERVER: ${{ gitea.server_url }}
uses: builtin:checkout
- name: Check tag matches pkgver
run: |