ci: v4 builtin:checkout instead of hand-rolled git with token-in-URL
Test / test (push) Successful in 10s
Test / test (push) Successful in 10s
builtin:checkout is native Go (no Node — the aarch64 klokka leg has none) and keeps the job token out of the fetch URL (it was visible in process args on the host runner). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
1c75dd5681
commit
8e35af8c99
@@ -41,15 +41,10 @@ jobs:
|
|||||||
SCCACHE_DIR: /var/local/sccache
|
SCCACHE_DIR: /var/local/sccache
|
||||||
SCCACHE_SERVER_PORT: "4228"
|
SCCACHE_SERVER_PORT: "4228"
|
||||||
steps:
|
steps:
|
||||||
# Plain git: the aarch64 host runner has no Node.js for
|
# v4 built-in checkout: native Go, needs no Node (the aarch64 host runner
|
||||||
# actions/checkout (same as uhhm/corp).
|
# has none) and keeps the token out of a fetch URL.
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
run: |
|
uses: builtin:checkout
|
||||||
git init -q .
|
|
||||||
git fetch -q --depth 1 "https://ci:${{ gitea.token }}@${GITEA_SERVER#https://}/${{ gitea.repository }}.git" "${{ gitea.sha }}"
|
|
||||||
git checkout -q FETCH_HEAD
|
|
||||||
env:
|
|
||||||
GITEA_SERVER: ${{ gitea.server_url }}
|
|
||||||
|
|
||||||
- name: Check tag matches pkgver
|
- name: Check tag matches pkgver
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
Reference in New Issue
Block a user