mirror of
https://github.com/goreleaser/goreleaser.git
synced 2025-01-24 04:16:27 +02:00
d524d93086
- [x] if the default is the zero-value for the field, do not specify - [ ] TODO: add a "how to read this docs" section somewhere explaining that - [x] if the change was introduced in a v1.x.0, say only v1.x - [x] drop trail ending `.` from Since, Default, etc - [x] wording: always use `Default: ` instead of `Defaults to` and others - [x] add a note to templateable fields - [x] default value of a field, if its a string, always between single quotes `'` --------- Signed-off-by: Carlos A Becker <caarlos0@users.noreply.github.com>
51 lines
1.5 KiB
Markdown
51 lines
1.5 KiB
Markdown
# Verifiable Builds
|
|
|
|
GoReleaser has support for creating verifiable builds. A [verifiable build][vgo]
|
|
is one that records enough information to be precise about exactly how to repeat
|
|
it. All dependencies are loaded via `proxy.golang.org`, and verified against the
|
|
checksum database `sum.golang.org`. A GoReleaser-created verifiable build will
|
|
include module information in the resulting binary, which can be printed using
|
|
`go version -m mybinary`.
|
|
|
|
Configuration options available are described below.
|
|
|
|
```yaml
|
|
# goreleaser.yaml
|
|
|
|
gomod:
|
|
# Proxy a module from proxy.golang.org, making the builds verifiable.
|
|
# This will only be effective if running against a tag. Snapshots will ignore
|
|
# this setting.
|
|
# Notice: for this to work your `build.main` must be a package, not a `.go` file.
|
|
proxy: true
|
|
|
|
# If proxy is true, use these environment variables when running `go mod`
|
|
# commands (namely, `go mod tidy`).
|
|
#
|
|
# Default: `os.Environ()` merged with what you set the root `env` section.
|
|
env:
|
|
- GOPROXY=https://proxy.golang.org,direct
|
|
- GOSUMDB=sum.golang.org
|
|
- GOPRIVATE=example.com/blah
|
|
|
|
# Sets the `-mod` flag value.
|
|
#
|
|
# Since: v1.7
|
|
mod: mod
|
|
|
|
# Which Go binary to use.
|
|
#
|
|
# Default: `go`.
|
|
gobinary: go1.17
|
|
```
|
|
|
|
!!! tip
|
|
You can use `debug.ReadBuildInfo()` to get the version/checksum/dependencies
|
|
of the module.
|
|
|
|
!!! warning
|
|
VCS Info will not be embedded in the binary, as in practice it is not being
|
|
built from the source, but from the Go Mod Proxy.
|
|
|
|
[vgo]: https://research.swtch.com/vgo-repro
|