From 8e35af8c99ba3eeaa029ec62622a72683d381859 Mon Sep 17 00:00:00 2001 From: Bendik Aagaard Lynghaug Date: Mon, 28 Sep 2026 13:35:48 +0200 Subject: [PATCH] ci: v4 builtin:checkout instead of hand-rolled git with token-in-URL MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit builtin:checkout is native Go (no Node — the aarch64 klokka leg has none) and keeps the job token out of the fetch URL (it was visible in process args on the host runner). Co-Authored-By: Claude Opus 4.8 --- .gitea/workflows/publish.yml | 11 +++-------- 1 file changed, 3 insertions(+), 8 deletions(-) diff --git a/.gitea/workflows/publish.yml b/.gitea/workflows/publish.yml index 1b8e964..9ac3335 100644 --- a/.gitea/workflows/publish.yml +++ b/.gitea/workflows/publish.yml @@ -41,15 +41,10 @@ jobs: SCCACHE_DIR: /var/local/sccache SCCACHE_SERVER_PORT: "4228" steps: - # Plain git: the aarch64 host runner has no Node.js for - # actions/checkout (same as uhhm/corp). + # v4 built-in checkout: native Go, needs no Node (the aarch64 host runner + # has none) and keeps the token out of a fetch URL. - name: Checkout - run: | - git init -q . - git fetch -q --depth 1 "https://ci:${{ gitea.token }}@${GITEA_SERVER#https://}/${{ gitea.repository }}.git" "${{ gitea.sha }}" - git checkout -q FETCH_HEAD - env: - GITEA_SERVER: ${{ gitea.server_url }} + uses: builtin:checkout - name: Check tag matches pkgver run: |