ci: pin the protoc plugins instead of installing @latest

these generate the committed stubs, so @latest makes codegen depend on
whatever released most recently. pinned to the versions proto/ records:
protoc-gen-go v1.36.11, protoc-gen-go-grpc v1.6.0.
This commit is contained in:
pj committed 2026-08-16 17:20:59 +05:30
1 parent fe0c4ee2f7
commit 644e036578
1 file changed
+6 -2
+6 -2
View File
@@ -86,10 +86,14 @@ jobs:
setup_only: true
github_token: ${{ secrets.GITHUB_TOKEN }}
# Pinned, not @latest: these two write the committed stubs, so a floating
# version is an unreviewed input to generated code. The versions are the
# ones the stubs under proto/ record generating them, so what CI builds
# with and what is checked in stay the same thing.
- name: Install protoc plugins
run: |
go install google.golang.org/protobuf/cmd/protoc-gen-go@latest
go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@latest
go install google.golang.org/protobuf/cmd/protoc-gen-go@v1.36.11
go install google.golang.org/grpc/cmd/protoc-gen-go-grpc@v1.6.0
echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH"
- name: Cache Gradle