Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,12 +2,17 @@ name: CI

on:
push:
branches: [main]
pull_request:
workflow_dispatch:

permissions:
contents: read

concurrency:
group: embedledger-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
Comment on lines +12 to +14

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Queue every main release workflow

When three pushes to main arrive while the first workflow is still running, the shared top-level concurrency group keeps only the newest pending run even though cancel-in-progress is false; GitHub documents that an existing pending run is canceled unless queue: max is enabled. Because publication occurs only within each push's workflow, this can silently discard a pending version-bump run, causing that version to be skipped entirely if the following push bumps again, or causing its tag to point at a later commit if the version remains unchanged. Queue all runs, or move serialization to the publish job so verified release commits cannot be replaced.

Useful? React with 👍 / 👎.


jobs:
verify:
name: Verify (${{ matrix.os }})
Expand All @@ -33,6 +38,17 @@ jobs:
- name: Require Go formatting
shell: bash
run: test -z "$(gofmt -l .)"
- name: Build and verify native distribution
run: go run ./scripts/package
- name: Keep verified native distribution
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: embedledger-native-${{ runner.os }}-${{ runner.arch }}
path: |
dist/embedledger_*.zip
dist/embedledger_*.zip.sha256
if-no-files-found: error
overwrite: true

race:
name: Race detector
Expand All @@ -44,3 +60,28 @@ jobs:
go-version: '1.27.1'
cache: false
- run: go test -race -count=1 ./...

publish:
name: Publish verified release
needs: [verify, race]
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: write
concurrency:
group: embedledger-release
cancel-in-progress: false
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Read packages from this verified run
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
pattern: embedledger-native-*
path: release-artifacts
merge-multiple: true
- name: Publish complete packages
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
with:
script: |
const publish = require('./scripts/release.cjs');
await publish({ github, context, core });
12 changes: 12 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,17 @@
# Changelog

## 1.0.0

Released October 6, 2026.

- Adopt the MIT license and publish native ZIP packages with SHA256 checksums.
- Include documentation and the checked example in each package. Go 1.27 or newer remains required on PATH for asset resolution.
- Verify each native package after unpacking on Windows, Linux, and macOS before publishing it.
- Define the 1.x compatibility contract for documented commands, flags, exit codes, and schema-1 baselines.
- Resolve filesystem aliases consistently when comparing Go package directories with the module root, including macOS temporary directories.

The baseline format is unchanged. Existing 0.1.1 baselines remain compatible when their build scope matches. Upgrade the executable, keep the same scan options, and run `check`; a new snapshot is not required.

## 0.1.1

Released September 19, 2026.
Expand Down
14 changes: 9 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,15 +15,15 @@ One Go CLI, standard library only. No account or service required.
Install [Go 1.27 or newer](https://go.dev/doc/install), then check that `go version` works in your terminal. Go must remain on PATH because EmbedLedger uses its resolver when scanning your project.

```sh
go install github.com/agammann/embedledger@v0.1.1
go install github.com/agammann/embedledger@v1.0.0
embedledger version
```

Expected output: `embedledger 0.1.1`.
Expected output: `embedledger 1.0.0`.

If your terminal cannot find `embedledger`, follow the [PATH setup instructions](docs/troubleshooting.md#command-not-found). This release is installed from source through Go; it does not include prebuilt binary downloads.
If your terminal cannot find `embedledger`, follow the [PATH setup instructions](docs/troubleshooting.md#command-not-found). Prebuilt native ZIP packages are also available from the release page. Download the package matching your OS and architecture, verify its SHA256 checksum, and unpack it. Each package includes the CLI, MIT license, documentation, and the checked example. Go 1.27 or newer must remain on PATH when using either installation method.

See the [0.1.1 release](https://github.com/agammann/embedledger/releases/tag/v0.1.1) and [changelog](CHANGELOG.md). Use `@latest` instead of `@v0.1.1` when you want the newest tagged version.
See the [1.0.0 release](https://github.com/agammann/embedledger/releases/tag/v1.0.0) and [changelog](CHANGELOG.md). Use `@latest` instead of `@v1.0.0` when you want the newest tagged version.

## Quick start

Expand Down Expand Up @@ -120,10 +120,14 @@ go vet ./...
go test -race ./...
```

The race detector needs a supported platform and C compiler. [Repository CI](.github/workflows/ci.yml) runs the real resolver and CLI tests on Windows, Linux, and macOS, plus the Linux race detector.
The race detector needs a supported platform and C compiler. [Repository CI](https://github.com/agammann/embedledger/blob/v1.0.0/.github/workflows/ci.yml) runs the real resolver and CLI tests on Windows, Linux, and macOS, plus the Linux race detector.

[Real project checks](docs/real-world-validation.md) · [Validation record](docs/validation.md) · [Research and related work](docs/research.md)

## Compatibility and upgrades

Version 1.x preserves the documented commands, flags and defaults, exit codes, and schema-1 baseline fields. Existing 0.1.1 baselines remain compatible when their build scope matches; upgrading does not require a new snapshot. See the [stability and upgrade contract](docs/compatibility.md) before updating automation.

## License

EmbedLedger is licensed under the [MIT License](LICENSE).
8 changes: 7 additions & 1 deletion collect.go
Original file line number Diff line number Diff line change
Expand Up @@ -192,7 +192,13 @@ func collect(ctx context.Context, opt options) (manifest, error) {
if pkg.ForTest != "" {
continue
}
dir, err := filepath.Rel(root, pkg.Dir)
// Go can report another filesystem alias for the same directory.
// Resolve it, as we did the module root, before checking containment.
packageDir, err := filepath.EvalSymlinks(pkg.Dir)
if err != nil {
return m, fmt.Errorf("resolve package %q directory: %w", pkg.ImportPath, err)
}
dir, err := filepath.Rel(root, packageDir)
if err != nil || !filepath.IsLocal(dir) {
return m, fmt.Errorf("package %q is outside the selected module", pkg.ImportPath)
}
Expand Down
34 changes: 34 additions & 0 deletions collect_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,14 @@ import (
"bytes"
"context"
"encoding/json"
"errors"
"os"
"os/exec"
"path/filepath"
"runtime"
"slices"
"strings"
"syscall"
"testing"
)

Expand Down Expand Up @@ -71,6 +73,38 @@ func TestGoResolverSemantics(t *testing.T) {
}
}

func TestGoResolverThroughModuleAlias(t *testing.T) {
dir, opt := fixture(t, "assets")
alias := filepath.Join(t.TempDir(), "module")
if err := os.Symlink(dir, alias); err != nil {
// Windows ERROR_PRIVILEGE_NOT_HELD: symlink creation needs permission.
if runtime.GOOS == "windows" && errors.Is(err, syscall.Errno(1314)) {
t.Skipf("symlink privilege unavailable: %v", err)
}
t.Fatal(err)
}
opt.Dir = alias
// Unix Go subprocesses may retain a valid PWD alias in package metadata.
t.Setenv("PWD", alias)
m, err := collect(context.Background(), opt)
if err != nil {
t.Fatal(err)
}
if len(m.Assets) != 2 || m.TotalBytes != 9 || m.Assets[0].Path != "assets/a.txt" || m.Assets[1].Path != "assets/nested/b.txt" {
t.Fatalf("unexpected inventory through module alias: %+v", m)
}
// A package alias that resolves outside the module must still fail.
outside := t.TempDir()
writeFixture(t, outside, "outside.go", "package outside\n")
if err := os.Symlink(outside, filepath.Join(dir, "outside")); err != nil {
t.Fatal(err)
}
opt.Patterns = []string{"./outside"}
if _, err := collect(context.Background(), opt); err == nil || !strings.Contains(err.Error(), "outside the selected module") {
t.Fatalf("expected outside-module rejection, got %v", err)
}
}

func TestBuildContextsAndTestAssets(t *testing.T) {
dir, opt := fixture(t, "assets")
writeFixture(t, dir, "special.go", "//go:build special\n\npackage fixture\nimport _ \"embed\"\n//go:embed special.txt\nvar Special string\n")
Expand Down
53 changes: 53 additions & 0 deletions docs/compatibility.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
# Stability and upgrades

[Back to the README](../README.md)

## The 1.x contract

EmbedLedger 1.x preserves the documented `scan`, `snapshot`, `check`, `version`, and `help` commands; existing flags and their defaults; and these exit codes:

| Exit code | Meaning |
| :--- | :--- |
| `0` | Complete inventory, saved baseline, or matching baseline |
| `1` | A complete comparison found added, removed, or changed assets |
| `2` | Invalid input, incompatible baseline, or an incomplete scan |

Schema-1 baselines retain their field names and meanings. Version 1.x continues to read existing valid schema-1 baselines. The JSON inventory and comparison fields documented in the [command reference](reference.md) retain their types and meanings. Additional commands and optional flags may be added; removing existing behavior or changing these formats requires a new major version.

A baseline comparison uses the recorded target OS, architecture, CGO setting, build tags, package selection, and test setting. Keep those options identical when saving and checking. The byte budget and timeout may differ. Go version is recorded as information and does not itself cause drift; Go's selected inputs can change between toolchains, so review any reported asset changes after a toolchain update.

Go 1.27 or newer must remain on PATH even when using a prebuilt executable. Native packages contain the CLI, MIT license, README, changelog, documentation, and the example module. The package filenames identify the OS and architecture that actually built and ran the package checks. These packages do not bundle Go.

## Upgrade from 0.1.1

Install the pinned source release:

```sh
go install github.com/agammann/embedledger@v1.0.0
embedledger version
```

The version output is `embedledger 1.0.0`. Alternatively, replace your previous executable with the verified native package for your OS and architecture.

Keep your reviewed `embedledger.json` and run `check` with the same options you used in 0.1.1:

```sh
embedledger check --goos linux --goarch amd64
```

The baseline format is unchanged; do not run `snapshot --force` merely to upgrade. If the check reports drift, review the inputs before deciding whether to accept a new baseline. Update the installation pin in your CI workflow separately.

## Verify a native package

Each ZIP has a matching `.zip.sha256` file. Compare its hash with the ZIP before unpacking. The release also includes `SHA256SUMS` for all native ZIP files.

On Windows PowerShell:

```powershell
Get-FileHash .\embedledger_1.0.0_windows_amd64.zip -Algorithm SHA256
Get-Content .\embedledger_1.0.0_windows_amd64.zip.sha256
```

On Linux, run `sha256sum -c` with the checksum filename. On macOS, run `shasum -a 256 -c` with it. Use the package matching your architecture.

After unpacking, use the CLI from the package directory or place it on PATH. Its included example baseline can be checked with `embedledger check --goos linux --goarch amd64`; this reports 112 bytes. In PowerShell, use `.\embedledger.exe` for the executable in the current directory. On macOS and Linux, use `./embedledger`.
2 changes: 1 addition & 1 deletion docs/github-actions.md
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ jobs:
- name: Prepare project dependencies
run: go mod download
- name: Install EmbedLedger
run: go install github.com/agammann/embedledger@v0.1.1
run: go install github.com/agammann/embedledger@v1.0.0
- name: Check reviewed embedded assets
run: embedledger check --goos linux --goarch amd64 --max-bytes 10485760 --timeout 5m
```
Expand Down
2 changes: 1 addition & 1 deletion main.go
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ import (
"time"
)

const version = "0.1.1"
const version = "1.0.0"

func main() { os.Exit(run(os.Args[1:], os.Stdout, os.Stderr)) }

Expand Down
Loading
Loading