Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ Versioning: [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
today keeps working across minor and patch releases; a change that would break
one waits for a major.

## [Unreleased]
## [0.6.5] - 2026-09-14

### Fixed

Expand Down Expand Up @@ -609,7 +609,8 @@ First release.
to be re-run still leaves the immutable tags behind.

[artifact-contract]: https://github.com/owfeed/owfeed/blob/main/docs/artifact-contract.md
[Unreleased]: https://github.com/owfeed/owlab/compare/v0.6.4...HEAD
[Unreleased]: https://github.com/owfeed/owlab/compare/v0.6.5...HEAD
[0.6.5]: https://github.com/owfeed/owlab/compare/v0.6.4...v0.6.5
[0.6.4]: https://github.com/owfeed/owlab/compare/v0.6.3...v0.6.4
[0.6.3]: https://github.com/owfeed/owlab/compare/v0.6.2...v0.6.3
[0.6.2]: https://github.com/owfeed/owlab/compare/v0.6.1...v0.6.2
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -246,7 +246,7 @@ output for one release.
### Check it in CI

```yaml
- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: "25.12.5 24.10.8"
install: dist/*/luci-app-mine-*
Expand Down
2 changes: 1 addition & 1 deletion README_ru.md
Original file line number Diff line number Diff line change
Expand Up @@ -247,7 +247,7 @@ dist/
### Проверять в CI

```yaml
- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: "25.12.5 24.10.8"
install: dist/*/luci-app-mine-*
Expand Down
8 changes: 4 additions & 4 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -63,16 +63,16 @@ alone would accept an attestation produced by any workflow in it holding
`attestations: write`, so a single merged pull request adding a workflow would
be enough to mint a valid attestation for arbitrary bytes.

Pin the action to a tag. The tag decides the binary too: `setup@v0.6.4` with no
`version:` installs v0.6.4. `latest`, a branch or a SHA means the tool a CI
Pin the action to a tag. The tag decides the binary too: `setup@v0.6.5` with no
`version:` installs v0.6.5. `latest`, a branch or a SHA means the tool a CI
result depends on can change between runs without a commit anywhere; the
installer warns when it is used.

## Verifying a download by hand

```sh
gh release download v0.6.4 -R owfeed/owlab -p 'owlab_0.6.4_linux_amd64.tar.gz'
gh attestation verify owlab_0.6.4_linux_amd64.tar.gz -R owfeed/owlab \
gh release download v0.6.5 -R owfeed/owlab -p 'owlab_0.6.5_linux_amd64.tar.gz'
gh attestation verify owlab_0.6.5_linux_amd64.tar.gz -R owfeed/owlab \
--signer-workflow owfeed/owlab/.github/workflows/release.yml
```

Expand Down
8 changes: 4 additions & 4 deletions docs/reference.md
Original file line number Diff line number Diff line change
Expand Up @@ -483,7 +483,7 @@ add'` is the whole of "is anything stale".
### In GitHub Actions

```yaml
- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: "25.12.5 24.10.8"
install: dist/*/luci-app-mine-*
Expand All @@ -495,12 +495,12 @@ add'` is the whole of "is anything stale".
Every flag above has an input with the same name; `assert` and `install` take
one per line. The action writes a table to the job summary and exposes
`report` (the JSON path), `passed` and `failed` as outputs.
`owfeed/owlab/setup@v0.6.4` installs the binary alone, for a job that drives
`owfeed/owlab/setup@v0.6.5` installs the binary alone, for a job that drives
`owlab` itself. Both verify the download against this repository's build
attestation before the binary is executed or put on `PATH`.

The tag in `uses:` is the version. `action@v0.6.4` and `setup@v0.6.4` install
owlab v0.6.4, so a dependabot bump of that line moves the binary too. Set
The tag in `uses:` is the version. `action@v0.6.5` and `setup@v0.6.5` install
owlab v0.6.5, so a dependabot bump of that line moves the binary too. Set
`version:` only to run a different release. Called at a branch or a SHA, both
install the latest release and say so in a warning.

Expand Down
8 changes: 4 additions & 4 deletions docs/reference_ru.md
Original file line number Diff line number Diff line change
Expand Up @@ -424,7 +424,7 @@ caught», lua-шный `stack traceback:`): поймав исключение, L
### В GitHub Actions

```yaml
- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: "25.12.5 24.10.8"
install: dist/*/luci-app-mine-*
Expand All @@ -435,13 +435,13 @@ caught», lua-шный `stack traceback:`): поймав исключение, L

У каждого флага выше есть одноимённый input; `assert` и `install` принимают по
одному значению на строку. Экшен пишет таблицу в summary джоба и отдаёт outputs
`report` (путь к JSON), `passed` и `failed`. `owfeed/owlab/setup@v0.6.4`
`report` (путь к JSON), `passed` и `failed`. `owfeed/owlab/setup@v0.6.5`
ставит только бинарь — для джоба, который сам вызывает `owlab`. Оба проверяют
скачанное по build attestation этого репозитория до того, как бинарь будет
запущен или попадёт в `PATH`.

Версия — это тег в `uses:`. `action@v0.6.4` и `setup@v0.6.4` ставят owlab
v0.6.4, поэтому бамп этой строки от dependabot двигает и бинарь. `version:`
Версия — это тег в `uses:`. `action@v0.6.5` и `setup@v0.6.5` ставят owlab
v0.6.5, поэтому бамп этой строки от dependabot двигает и бинарь. `version:`
задавайте, только если нужен другой релиз. Вызванные по ветке или SHA, оба
ставят последний релиз и предупреждают об этом.

Expand Down
4 changes: 2 additions & 2 deletions docs/runbook.md
Original file line number Diff line number Diff line change
Expand Up @@ -387,9 +387,9 @@ On Apple Silicon this runs under emulation — every `openwrt/sdk` tag is
In a package repository, with no `owlab.yaml`:

```yaml
- uses: owfeed/owlab/setup@v0.6.4
- uses: owfeed/owlab/setup@v0.6.5
- run: owlab build --release 25.12.5 --out dist
- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: "25.12.5 24.10.8"
install: dist/*/luci-app-mine-*
Expand Down
4 changes: 2 additions & 2 deletions docs/runbook_ru.md
Original file line number Diff line number Diff line change
Expand Up @@ -387,9 +387,9 @@ sync — нет, и на этой разнице ломались пакеты,
В репозитории пакета, без всякого `owlab.yaml`:

```yaml
- uses: owfeed/owlab/setup@v0.6.4
- uses: owfeed/owlab/setup@v0.6.5
- run: owlab build --release 25.12.5 --out dist
- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: "25.12.5 24.10.8"
install: dist/*/luci-app-mine-*
Expand Down
4 changes: 2 additions & 2 deletions examples/workflow/package-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ jobs:
# action@vX.Y.Z below, so a dependabot bump of these lines moves the binary
# too. Pin a branch or "latest" and a CI result can change without a
# commit anywhere in this repository.
- uses: owfeed/owlab/setup@v0.6.4
- uses: owfeed/owlab/setup@v0.6.5

# The verification tier: luci.mk minifies JS and CSS by default, so a real
# package is not the source tree. Code that works unminified and breaks
Expand All @@ -43,7 +43,7 @@ jobs:
- name: Build the package
run: owlab build --release '${{ matrix.release }}' --out dist

- uses: owfeed/owlab/action@v0.6.4
- uses: owfeed/owlab/action@v0.6.5
with:
releases: ${{ matrix.release }}
# A glob, because the version in the artifact's file name comes from
Expand Down