diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 8071afd..58ca027 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -69,7 +69,10 @@ jobs: # float means a future release can change the output — or drift from the # library it generates against — with nothing in this repository # changing. The release workflow pins the same version. - run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.15.0 + # Kept in step with the wails/v2 requirement in go.mod. This pin is a + # `go install` argument, so Dependabot does not manage it: bumping the + # library without this leaves releases built by an older CLI. + run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.16.0 - name: Build shell: bash diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index e2801b0..b94a834 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -54,7 +54,10 @@ jobs: # produces the binaries that are then checksummed and signed, so an # unpinned @latest would make releases non-reproducible and would put a # compromised Wails release straight into a signed artifact. - run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.15.0 + # Kept in step with the wails/v2 requirement in go.mod. This pin is a + # `go install` argument, so Dependabot does not manage it: bumping the + # library without this leaves releases built by an older CLI. + run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.16.0 - name: Install frontend deps run: npm ci working-directory: frontend @@ -105,7 +108,7 @@ jobs: # produces the binaries that are then checksummed and signed, so an # unpinned @latest would make releases non-reproducible and would put a # compromised Wails release straight into a signed artifact. - run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.15.0 + run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.16.0 - name: Install frontend deps run: npm ci working-directory: frontend @@ -158,7 +161,7 @@ jobs: # produces the binaries that are then checksummed and signed, so an # unpinned @latest would make releases non-reproducible and would put a # compromised Wails release straight into a signed artifact. - run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.15.0 + run: go install github.com/wailsapp/wails/v2/cmd/wails@v2.16.0 - name: Install frontend deps run: npm ci working-directory: frontend