From ccef85c26c9377fcb0e5202bec969d4c31cbaf11 Mon Sep 17 00:00:00 2001 From: Ian Hildebrand <25069719+iHildy@users.noreply.github.com> Date: Tue, 22 Sep 2026 20:32:52 -0700 Subject: [PATCH 1/3] fix: authenticate OpenCode smoke version lookup --- .github/workflows/opencode-smoke.yml | 20 +++++++++++++++++--- src/release-workflows.test.ts | 12 ++++++++++++ 2 files changed, 29 insertions(+), 3 deletions(-) diff --git a/.github/workflows/opencode-smoke.yml b/.github/workflows/opencode-smoke.yml index e072a50..15a00fb 100644 --- a/.github/workflows/opencode-smoke.yml +++ b/.github/workflows/opencode-smoke.yml @@ -87,12 +87,26 @@ jobs: echo "spec=opencode-synced@$VERSION" >> "$GITHUB_OUTPUT" echo "version=$VERSION" >> "$GITHUB_OUTPUT" + - name: Resolve OpenCode version + id: opencode-version + env: + GH_TOKEN: ${{ github.token }} + run: | + set -euo pipefail + OPENCODE_VERSION=$(gh api repos/anomalyco/opencode/releases/latest --jq '.tag_name') + if [[ ! "$OPENCODE_VERSION" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([.-][0-9A-Za-z.-]+)?$ ]]; then + echo "Invalid OpenCode release version: $OPENCODE_VERSION" + exit 1 + fi + echo "version=$OPENCODE_VERSION" >> "$GITHUB_OUTPUT" + - name: Install opencode env: - opencode_install_dir: ${{ runner.temp }}/opencode/bin + OPENCODE_VERSION: ${{ steps.opencode-version.outputs.version }} run: | - curl -fsSL https://opencode.ai/install | bash - echo "${opencode_install_dir}" >> "$GITHUB_PATH" + set -euo pipefail + curl -fsSL --retry 3 --retry-all-errors https://opencode.ai/install | + bash -s -- --version "$OPENCODE_VERSION" --no-modify-path - name: Configure clean opencode home env: diff --git a/src/release-workflows.test.ts b/src/release-workflows.test.ts index 412189c..6b0c8ff 100644 --- a/src/release-workflows.test.ts +++ b/src/release-workflows.test.ts @@ -59,6 +59,18 @@ describe('release workflows', () => { expect(smokeWorkflow).toContain('Expected exact version $REQUESTED_VERSION'); }); + it('keeps the GitHub token out of the external OpenCode installer step', () => { + expect(smokeWorkflow).toContain('GH_TOKEN: $' + '{{ github.token }}'); + expect(smokeWorkflow).toContain( + "gh api repos/anomalyco/opencode/releases/latest --jq '.tag_name'" + ); + expect(smokeWorkflow).toContain( + 'OPENCODE_VERSION: $' + '{{ steps.opencode-version.outputs.version }}' + ); + expect(smokeWorkflow).toContain('bash -s -- --version "$OPENCODE_VERSION" --no-modify-path'); + expect(smokeWorkflow).not.toContain('curl -fsSL https://opencode.ai/install | bash'); + }); + it('uses string comparisons for release-please boolean outputs and frozen setup', () => { expect(releaseWorkflow).toContain("outputs.releases_created == 'true'"); expect(releaseWorkflow).toContain("outputs.prs_created == 'true'"); From a977ca3c2849a76ef8527a6ac27cf04ee8e4920f Mon Sep 17 00:00:00 2001 From: Ian Hildebrand <25069719+iHildy@users.noreply.github.com> Date: Tue, 22 Sep 2026 20:34:07 -0700 Subject: [PATCH 2/3] docs: note release smoke reliability fix --- CHANGELOG.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index d04c435..e88ab92 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,6 +19,10 @@ All notable changes to this project will be documented here by Release Please. * Pin the remaining GitHub Actions to immutable commits ([#82](https://github.com/iHildy/opencode-synced/pull/82)). +### Release Reliability + +* Authenticate OpenCode version lookup in the macOS prepublish smoke without exposing the token to its installer ([#87](https://github.com/iHildy/opencode-synced/pull/87)). + ### Documentation * Explain v1/v2 requirements, configuration keys, and the Node shell shim ([#84](https://github.com/iHildy/opencode-synced/pull/84)). From 6468191e339212298f66fd4b48d6bb8aa8772f3a Mon Sep 17 00:00:00 2001 From: Ian Hildebrand <25069719+iHildy@users.noreply.github.com> Date: Tue, 22 Sep 2026 20:36:18 -0700 Subject: [PATCH 3/3] style: prefix smoke version errors --- .github/workflows/opencode-smoke.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/opencode-smoke.yml b/.github/workflows/opencode-smoke.yml index 15a00fb..f37be3f 100644 --- a/.github/workflows/opencode-smoke.yml +++ b/.github/workflows/opencode-smoke.yml @@ -95,7 +95,7 @@ jobs: set -euo pipefail OPENCODE_VERSION=$(gh api repos/anomalyco/opencode/releases/latest --jq '.tag_name') if [[ ! "$OPENCODE_VERSION" =~ ^v[0-9]+\.[0-9]+\.[0-9]+([.-][0-9A-Za-z.-]+)?$ ]]; then - echo "Invalid OpenCode release version: $OPENCODE_VERSION" + echo "[ERROR] Invalid OpenCode release version: $OPENCODE_VERSION" exit 1 fi echo "version=$OPENCODE_VERSION" >> "$GITHUB_OUTPUT"