Pin GoReleaser to requested release tag - #112
Merged
Merged
Conversation
Co-authored-by: c1-squire-dev[bot] <c1-squire-dev[bot]@users.noreply.github.com>
pquerna
approved these changes
Aug 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
When a prerelease and final tag point at one commit, GoReleaser auto-detects the prerelease tag. Production workflow runs then build prerelease-named assets and fail before distribution publication.
Change
Set GORELEASER_CURRENT_TAG from the reusable workflow tag input in binary, Windows, Public ECR, and Lambda GoReleaser invocations. Add a workflow test that guards every invocation.
Security impact
Artifact names, release metadata, and image digest files now derive from the verified workflow tag even when several tags identify the same source commit.
Verification
Release recovery
The failed v0.0.42 and v0.5.1 attempts remain unused in dist. Replacement releases use new patch versions after this shared workflow patch is published.