diff --git a/.github/workflows/opencode-smoke.yml b/.github/workflows/opencode-smoke.yml index e072a50..f37be3f 100644 --- a/.github/workflows/opencode-smoke.yml +++ b/.github/workflows/opencode-smoke.yml @@ -87,12 +87,26 @@ jobs: echo "spec=opencode-synced@$VERSION" >> "$GITHUB_OUTPUT" echo "version=$VERSION" >> "$GITHUB_OUTPUT" + - name: Resolve OpenCode version + id: opencode-version + env: + GH_TOKEN: ${{ github.token }} + run: | + set -euo pipefail + OPENCODE_VERSION=$(gh api repos/anomalyco/opencode/releases/latest --jq '.tag_name') + if [[ ! "$OPENCODE_VERSION" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([.-][0-9A-Za-z.-]+)?$ ]]; then + echo "[ERROR] Invalid OpenCode release version: $OPENCODE_VERSION" + exit 1 + fi + echo "version=$OPENCODE_VERSION" >> "$GITHUB_OUTPUT" + - name: Install opencode env: - opencode_install_dir: ${{ runner.temp }}/opencode/bin + OPENCODE_VERSION: ${{ steps.opencode-version.outputs.version }} run: | - curl -fsSL https://opencode.ai/install | bash - echo "${opencode_install_dir}" >> "$GITHUB_PATH" + set -euo pipefail + curl -fsSL --retry 3 --retry-all-errors https://opencode.ai/install | + bash -s -- --version "$OPENCODE_VERSION" --no-modify-path - name: Configure clean opencode home env: diff --git a/CHANGELOG.md b/CHANGELOG.md index d04c435..e88ab92 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,10 @@ All notable changes to this project will be documented here by Release Please. * Pin the remaining GitHub Actions to immutable commits ([#82](https://github.com/iHildy/opencode-synced/pull/82)). +### Release Reliability + +* Authenticate OpenCode version lookup in the macOS prepublish smoke without exposing the token to its installer ([#87](https://github.com/iHildy/opencode-synced/pull/87)). + ### Documentation * Explain v1/v2 requirements, configuration keys, and the Node shell shim ([#84](https://github.com/iHildy/opencode-synced/pull/84)). diff --git a/src/release-workflows.test.ts b/src/release-workflows.test.ts index 412189c..6b0c8ff 100644 --- a/src/release-workflows.test.ts +++ b/src/release-workflows.test.ts @@ -59,6 +59,18 @@ describe('release workflows', () => { expect(smokeWorkflow).toContain('Expected exact version $REQUESTED_VERSION'); }); + it('keeps the GitHub token out of the external OpenCode installer step', () => { + expect(smokeWorkflow).toContain('GH_TOKEN: $' + '{{ github.token }}'); + expect(smokeWorkflow).toContain( + "gh api repos/anomalyco/opencode/releases/latest --jq '.tag_name'" + ); + expect(smokeWorkflow).toContain( + 'OPENCODE_VERSION: $' + '{{ steps.opencode-version.outputs.version }}' + ); + expect(smokeWorkflow).toContain('bash -s -- --version "$OPENCODE_VERSION" --no-modify-path'); + expect(smokeWorkflow).not.toContain('curl -fsSL https://opencode.ai/install | bash'); + }); + it('uses string comparisons for release-please boolean outputs and frozen setup', () => { expect(releaseWorkflow).toContain("outputs.releases_created == 'true'"); expect(releaseWorkflow).toContain("outputs.prs_created == 'true'");