Files
probo/.goreleaser.yaml
Bryan Frimin ccbd9e250c Disable binary signing in snapshot mode
Snapshot builds failed for external contributors due to cosign.
Since snapshot builds are not official releases, we do not need
to sign binaries. Disabling signing in this mode fixes the issue.

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
2025-08-22 10:58:23 +02:00

207 lines
5.6 KiB
YAML

# yaml-language-server: $schema=https://goreleaser.com/static/schema.json
version: 2
project_name: probod
before:
hooks:
- make @probo/console
builds:
- id: probod
main: ./cmd/probod/main.go
binary: probod
ldflags:
- -s -w
- -X 'main.version={{.Version}}'
- -X 'main.env=prod'
gcflags:
- -e
env:
- CGO_ENABLED=0
goos:
- windows
- darwin
goarch:
- amd64
- arm64
ignore:
- goos: windows
goarch: arm64
# Docker-specific builds for Linux only
- id: probod-docker
main: ./cmd/probod/main.go
binary: probod
ldflags:
- -s -w
- -X 'main.version={{.Version}}'
- -X 'main.env=prod'
gcflags:
- -e
env:
- CGO_ENABLED=0
goos:
- linux
goarch:
- amd64
- arm64
archives:
- name_template: >-
{{ .ProjectName }}_
{{- title .Os }}_
{{- if eq .Arch "amd64" }}x86_64
{{- else if eq .Arch "386" }}i386
{{- else }}{{ .Arch }}{{ end }}
{{- if .Arm }}v{{ .Arm }}{{ end }}
files:
- README.md
- LICENSE
- CHANGELOG.md
checksum:
name_template: "checksums.txt"
sboms:
- artifacts: archive
documents:
- "{{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
cmd: syft
args:
- "dir:."
- "--output=cyclonedx-json={{ .ProjectName }}_{{ .Version }}_{{ .Os }}_{{ .Arch }}_sbom.json"
- "--source-name={{ .ProjectName }}"
- "--source-version={{ .Version }}"
signs:
- cmd: sh
env:
- COSIGN_EXPERIMENTAL=1
certificate: "${artifact}.pem"
args:
- -c
- |
if [ "{{ .IsSnapshot }}" = "true" ]; then
echo "Skipping signing (snapshot: {{ .IsSnapshot }})"
else
cosign sign-blob --output-certificate="${certificate}" --output-signature="${signature}" "${artifact}" --yes
fi
artifacts: checksum
output: true
docker_manifests:
- name_template: "ghcr.io/getprobo/probo:{{ .Tag }}"
image_templates:
- "ghcr.io/getprobo/probo:{{ .Tag }}-amd64"
- "ghcr.io/getprobo/probo:{{ .Tag }}-arm64"
skip_push: "{{ .IsSnapshot }}"
- name_template: "ghcr.io/getprobo/probo:latest"
image_templates:
- "ghcr.io/getprobo/probo:latest-amd64"
- "ghcr.io/getprobo/probo:latest-arm64"
skip_push: "{{ .IsSnapshot }}"
docker_signs:
- id: images
cmd: sh
env:
- COSIGN_EXPERIMENTAL=1
artifacts: images
output: true
args:
- -c
- |
if [ "{{ .IsSnapshot }}" = "true" ]; then
echo "Skipping Docker image signing (snapshot: {{ .IsSnapshot }})"
else
cosign sign "${artifact}@${digest}" --yes
fi
- id: manifests
cmd: sh
env:
- COSIGN_EXPERIMENTAL=1
artifacts: manifests
output: true
args:
- -c
- |
if [ "{{ .IsSnapshot }}" = "true" ]; then
echo "Skipping Docker manifest signing (snapshot: {{ .IsSnapshot }})"
else
cosign sign "${artifact}@${digest}" --yes
fi
dockers:
- image_templates:
- "ghcr.io/getprobo/probo:{{ .Tag }}-amd64"
- "ghcr.io/getprobo/probo:latest-amd64"
dockerfile: Dockerfile
use: buildx
build_flag_templates:
- "--platform=linux/amd64"
- "--label=org.opencontainers.image.title={{.ProjectName}}"
- "--label=org.opencontainers.image.description=Probo compliance management platform"
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.version={{.Version}}"
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
- "--label=org.opencontainers.image.licenses=MIT"
# Use the Docker-specific build with AMD64 filtering
ids:
- probod-docker
goos: linux
goarch: amd64
skip_push: "{{ .IsSnapshot }}"
- image_templates:
- "ghcr.io/getprobo/probo:{{ .Tag }}-arm64"
- "ghcr.io/getprobo/probo:latest-arm64"
dockerfile: Dockerfile
use: buildx
build_flag_templates:
- "--platform=linux/arm64"
- "--label=org.opencontainers.image.title={{.ProjectName}}"
- "--label=org.opencontainers.image.description=Probo compliance management platform"
- "--label=org.opencontainers.image.url=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.source=https://github.com/getprobo/probo"
- "--label=org.opencontainers.image.version={{.Version}}"
- '--label=org.opencontainers.image.created={{time "2006-01-02T15:04:05Z07:00"}}'
- "--label=org.opencontainers.image.revision={{.FullCommit}}"
- "--label=org.opencontainers.image.licenses=MIT"
# Use the Docker-specific build with ARM64 filtering
ids:
- probod-docker
goos: linux
goarch: arm64
skip_push: "{{ .IsSnapshot }}"
changelog:
sort: asc
filters:
exclude:
- "^docs:"
- "^test:"
- "^chore:"
- "^style:"
- "^refactor:"
- "^ci:"
- "^build:"
- Merge pull request
- Merge branch
- go mod tidy
release:
draft: false
prerelease: auto
mode: replace
header: |
## Changes in {{ .Tag }}
footer: |
## Docker Images
- `ghcr.io/getprobo/probo:{{ .Tag }}` (multi-arch: linux/amd64, linux/arm64)
- `ghcr.io/getprobo/probo:latest` (multi-arch: linux/amd64, linux/arm64)
### Architecture-specific images
- `ghcr.io/getprobo/probo:{{ .Tag }}-amd64`
- `ghcr.io/getprobo/probo:{{ .Tag }}-arm64`