From 54ef50731c73b595b8ed8b560d00c760b0206828 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 18:03:35 +0000 Subject: [PATCH 1/8] Initial plan From 579e79e2a90a638897a471ac6fc8e3978d939a61 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 18:07:07 +0000 Subject: [PATCH 2/8] feat: publish releases to WinGet via vedantmgoyal9/winget-releaser Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/95b63705-9a9b-467c-9f21-bde357cd648d Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- .github/workflows/release.yml | 16 ++++++++++++++++ README.md | 6 ++++++ docs/site/installation-and-quickstart.md | 6 ++++++ 3 files changed, 28 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 0bd5ed59b..9ebeacf3c 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -487,3 +487,19 @@ jobs: git config user.name "github-actions[bot]" git config user.email "41898282+github-actions[bot]@users.noreply.github.com" task docs:deploy-version VERSION="$VERSION" + + winget-release: + name: Publish to WinGet + needs: + - determine-version + - release + if: ${{ needs.determine-version.outputs.should_release == 'true' }} + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - name: Publish to WinGet + uses: vedantmgoyal9/winget-releaser@v2 + with: + identifier: VriesDeMichael.bb + token: ${{ secrets.WINGET_TOKEN }} diff --git a/README.md b/README.md index ff0473590..f46f214c6 100644 --- a/README.md +++ b/README.md @@ -28,6 +28,12 @@ repository cloning and browser navigation ergonomics tailored to Bitbucket-hoste ## Quick start +Install on Windows via WinGet: + +```powershell +winget install VriesDeMichael.bb +``` + Install from Releases (Linux amd64 example): ```bash diff --git a/docs/site/installation-and-quickstart.md b/docs/site/installation-and-quickstart.md index 7a22a54ff..c2536b696 100644 --- a/docs/site/installation-and-quickstart.md +++ b/docs/site/installation-and-quickstart.md @@ -1,5 +1,11 @@ # Installation and Quickstart +## Install on Windows via WinGet + +```powershell +winget install VriesDeMichael.bb +``` + ## Install from release artifacts 1. Select a release version (example: `v0.1.0`). From 1e24eb5608c28ac1c79f81b0ed470db2713ee932 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 18:28:35 +0000 Subject: [PATCH 3/8] fix: lowercase winget identifier to vriesdemichael.bb Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/91133e9a-4cd8-4ec8-84c4-a2f90a1cce21 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- .github/workflows/release.yml | 2 +- README.md | 2 +- docs/site/installation-and-quickstart.md | 2 +- 3 files changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 9ebeacf3c..36bbffe2f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -501,5 +501,5 @@ jobs: - name: Publish to WinGet uses: vedantmgoyal9/winget-releaser@v2 with: - identifier: VriesDeMichael.bb + identifier: vriesdemichael.bb token: ${{ secrets.WINGET_TOKEN }} diff --git a/README.md b/README.md index f46f214c6..040e96790 100644 --- a/README.md +++ b/README.md @@ -31,7 +31,7 @@ repository cloning and browser navigation ergonomics tailored to Bitbucket-hoste Install on Windows via WinGet: ```powershell -winget install VriesDeMichael.bb +winget install vriesdemichael.bb ``` Install from Releases (Linux amd64 example): diff --git a/docs/site/installation-and-quickstart.md b/docs/site/installation-and-quickstart.md index c2536b696..7d9d3bc85 100644 --- a/docs/site/installation-and-quickstart.md +++ b/docs/site/installation-and-quickstart.md @@ -3,7 +3,7 @@ ## Install on Windows via WinGet ```powershell -winget install VriesDeMichael.bb +winget install vriesdemichael.bb ``` ## Install from release artifacts From 0c5d456e1d076eb6e6e189abedcf7de59402a1b8 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 20:58:47 +0000 Subject: [PATCH 4/8] feat: add Scoop bucket release job and install docs Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/a74dac33-7d32-4a11-9537-3ac81a78b1e1 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- .github/workflows/release.yml | 81 ++++++++++++++++++++++++ README.md | 7 ++ docs/site/installation-and-quickstart.md | 7 ++ 3 files changed, 95 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 36bbffe2f..722de72a5 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -503,3 +503,84 @@ jobs: with: identifier: vriesdemichael.bb token: ${{ secrets.WINGET_TOKEN }} + + scoop-release: + name: Publish to Scoop + needs: + - determine-version + - release + if: ${{ needs.determine-version.outputs.should_release == 'true' }} + runs-on: ubuntu-latest + permissions: + contents: read + env: + VERSION: ${{ needs.determine-version.outputs.version }} + steps: + - name: Download checksums from release + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + set -euo pipefail + gh release download "$VERSION" \ + --repo "$GITHUB_REPOSITORY" \ + --pattern "sha256sums.txt" \ + --output sha256sums.txt + + - name: Update Scoop bucket manifest + env: + SCOOP_BUCKET_TOKEN: ${{ secrets.SCOOP_BUCKET_TOKEN }} + run: | + set -euo pipefail + export VERSION_NO_V="${VERSION#v}" + export HASH_AMD64 + HASH_AMD64=$(grep "bb_${VERSION_NO_V}_windows_amd64.zip" sha256sums.txt | awk '{print $1}') + export HASH_ARM64 + HASH_ARM64=$(grep "bb_${VERSION_NO_V}_windows_arm64.zip" sha256sums.txt | awk '{print $1}') + export BASE_URL="https://github.com/${GITHUB_REPOSITORY}/releases/download/${VERSION}" + + git clone \ + "https://x-access-token:${SCOOP_BUCKET_TOKEN}@github.com/vriesdemichael/scoop-bb.git" \ + scoop-bucket + cd scoop-bucket + + python - <<'PY' + import json, os + version_no_v = os.environ["VERSION_NO_V"] + hash_amd64 = os.environ["HASH_AMD64"] + hash_arm64 = os.environ["HASH_ARM64"] + base_url = os.environ["BASE_URL"] + repo_url = f"https://github.com/{os.environ['GITHUB_REPOSITORY']}" + manifest = { + "version": version_no_v, + "description": "A CLI for Bitbucket Server / Bitbucket Data Center", + "homepage": repo_url, + "license": "MIT", + "architecture": { + "64bit": { + "url": f"{base_url}/bb_{version_no_v}_windows_amd64.zip", + "hash": hash_amd64, + }, + "arm64": { + "url": f"{base_url}/bb_{version_no_v}_windows_arm64.zip", + "hash": hash_arm64, + }, + }, + "bin": "bb.exe", + "checkver": {"github": repo_url}, + "autoupdate": { + "architecture": { + "64bit": {"url": f"{repo_url}/releases/download/v$version/bb_$version_windows_amd64.zip"}, + "arm64": {"url": f"{repo_url}/releases/download/v$version/bb_$version_windows_arm64.zip"}, + }, + }, + } + with open("bb.json", "w", encoding="utf-8") as f: + json.dump(manifest, f, indent=2) + f.write("\n") + PY + + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + git add bb.json + git diff --cached --quiet || git commit -m "Update bb to ${VERSION}" + git push diff --git a/README.md b/README.md index 040e96790..2a2bf29ad 100644 --- a/README.md +++ b/README.md @@ -34,6 +34,13 @@ Install on Windows via WinGet: winget install vriesdemichael.bb ``` +Install on Windows via Scoop: + +```powershell +scoop bucket add scoop-bb https://github.com/vriesdemichael/scoop-bb +scoop install scoop-bb/bb +``` + Install from Releases (Linux amd64 example): ```bash diff --git a/docs/site/installation-and-quickstart.md b/docs/site/installation-and-quickstart.md index 7d9d3bc85..26e8f4804 100644 --- a/docs/site/installation-and-quickstart.md +++ b/docs/site/installation-and-quickstart.md @@ -6,6 +6,13 @@ winget install vriesdemichael.bb ``` +## Install on Windows via Scoop + +```powershell +scoop bucket add scoop-bb https://github.com/vriesdemichael/scoop-bb +scoop install scoop-bb/bb +``` + ## Install from release artifacts 1. Select a release version (example: `v0.1.0`). From d810dffadab580f3c5a9aa6c5bb0595b29c9b03b Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 21:03:49 +0000 Subject: [PATCH 5/8] fix: rename Scoop bucket repo from scoop-bb to scoop Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/9ddcdb18-68ee-40b6-af26-a717fe09b537 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- .github/workflows/release.yml | 2 +- README.md | 4 ++-- docs/site/installation-and-quickstart.md | 4 ++-- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 722de72a5..9e2494d84 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -539,7 +539,7 @@ jobs: export BASE_URL="https://github.com/${GITHUB_REPOSITORY}/releases/download/${VERSION}" git clone \ - "https://x-access-token:${SCOOP_BUCKET_TOKEN}@github.com/vriesdemichael/scoop-bb.git" \ + "https://x-access-token:${SCOOP_BUCKET_TOKEN}@github.com/vriesdemichael/scoop.git" \ scoop-bucket cd scoop-bucket diff --git a/README.md b/README.md index 2a2bf29ad..f6cad005c 100644 --- a/README.md +++ b/README.md @@ -37,8 +37,8 @@ winget install vriesdemichael.bb Install on Windows via Scoop: ```powershell -scoop bucket add scoop-bb https://github.com/vriesdemichael/scoop-bb -scoop install scoop-bb/bb +scoop bucket add scoop https://github.com/vriesdemichael/scoop +scoop install scoop/bb ``` Install from Releases (Linux amd64 example): diff --git a/docs/site/installation-and-quickstart.md b/docs/site/installation-and-quickstart.md index 26e8f4804..1d6cc945b 100644 --- a/docs/site/installation-and-quickstart.md +++ b/docs/site/installation-and-quickstart.md @@ -9,8 +9,8 @@ winget install vriesdemichael.bb ## Install on Windows via Scoop ```powershell -scoop bucket add scoop-bb https://github.com/vriesdemichael/scoop-bb -scoop install scoop-bb/bb +scoop bucket add scoop https://github.com/vriesdemichael/scoop +scoop install scoop/bb ``` ## Install from release artifacts From d90226fff89460115c783682c7a8d52b27e4cb07 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 21:11:02 +0000 Subject: [PATCH 6/8] fix: use vriesdemichael as Scoop bucket alias in install commands Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/5979277e-1730-4643-90fb-1bcc32a49ccd Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- README.md | 4 ++-- docs/site/installation-and-quickstart.md | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index f6cad005c..5514e6772 100644 --- a/README.md +++ b/README.md @@ -37,8 +37,8 @@ winget install vriesdemichael.bb Install on Windows via Scoop: ```powershell -scoop bucket add scoop https://github.com/vriesdemichael/scoop -scoop install scoop/bb +scoop bucket add vriesdemichael https://github.com/vriesdemichael/scoop +scoop install vriesdemichael/bb ``` Install from Releases (Linux amd64 example): diff --git a/docs/site/installation-and-quickstart.md b/docs/site/installation-and-quickstart.md index 1d6cc945b..a024e9284 100644 --- a/docs/site/installation-and-quickstart.md +++ b/docs/site/installation-and-quickstart.md @@ -9,8 +9,8 @@ winget install vriesdemichael.bb ## Install on Windows via Scoop ```powershell -scoop bucket add scoop https://github.com/vriesdemichael/scoop -scoop install scoop/bb +scoop bucket add vriesdemichael https://github.com/vriesdemichael/scoop +scoop install vriesdemichael/bb ``` ## Install from release artifacts From 6eee6c350fffddf695835ce280c7a031b2ecc315 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Wed, 8 Apr 2026 21:55:05 +0000 Subject: [PATCH 7/8] feat: add Apache 2.0 license; fix scoop workflow token handling and Python setup Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/6a2383ab-4e90-44a1-9028-20b8e6861b59 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- .github/workflows/release.yml | 13 ++- LICENSE | 192 ++++++++++++++++++++++++++++++++++ 2 files changed, 201 insertions(+), 4 deletions(-) create mode 100644 LICENSE diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 9e2494d84..5db1510f9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -526,6 +526,11 @@ jobs: --pattern "sha256sums.txt" \ --output sha256sums.txt + - name: Set up Python + uses: actions/setup-python@v5 + with: + python-version: "3.x" + - name: Update Scoop bucket manifest env: SCOOP_BUCKET_TOKEN: ${{ secrets.SCOOP_BUCKET_TOKEN }} @@ -538,10 +543,10 @@ jobs: HASH_ARM64=$(grep "bb_${VERSION_NO_V}_windows_arm64.zip" sha256sums.txt | awk '{print $1}') export BASE_URL="https://github.com/${GITHUB_REPOSITORY}/releases/download/${VERSION}" - git clone \ - "https://x-access-token:${SCOOP_BUCKET_TOKEN}@github.com/vriesdemichael/scoop.git" \ - scoop-bucket + git clone https://github.com/vriesdemichael/scoop.git scoop-bucket cd scoop-bucket + git config credential.helper \ + '!f() { printf "username=x-access-token\npassword=%s\n" "${SCOOP_BUCKET_TOKEN}"; }; f' python - <<'PY' import json, os @@ -554,7 +559,7 @@ jobs: "version": version_no_v, "description": "A CLI for Bitbucket Server / Bitbucket Data Center", "homepage": repo_url, - "license": "MIT", + "license": "Apache-2.0", "architecture": { "64bit": { "url": f"{base_url}/bb_{version_no_v}_windows_amd64.zip", diff --git a/LICENSE b/LICENSE new file mode 100644 index 000000000..ada21a0e6 --- /dev/null +++ b/LICENSE @@ -0,0 +1,192 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship made available under + the License, as indicated by a copyright notice that is included in + or attached to the work (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean, as submitted to the Licensor for inclusion + in the Work by the copyright owner or by an individual or Legal Entity + authorized to submit on behalf of the copyright owner. For the purposes + of this definition, "submitted" means any form of electronic, verbal, + or written communication sent to the Licensor or its representatives, + including but not limited to communication on electronic mailing lists, + source code control systems, and issue tracking systems that are managed + by, or on behalf of, the Licensor for the purpose of discussing and + improving the Work, but excluding communication that is conspicuously + marked or designated in writing by the copyright owner as "Not a + Contribution." + + "Contributor" shall mean Licensor and any Legal Entity on behalf of + whom a Contribution has been received by the Licensor and included + within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by the combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a cross-claim + or counterclaim in a lawsuit) alleging that the Work or any patent + claim embodied in the Work constitutes direct or contributory patent + infringement, then any patent licenses granted to You under this License + for that Work shall terminate as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or Derivative + Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, You must include a readable copy of the + attribution notices contained within such NOTICE file, in + at least one of the following places: within a NOTICE text + file distributed as part of the Derivative Works; within + the Source form or documentation, if provided along with the + Derivative Works; or, within a display generated by the + Derivative Works, if and wherever such third-party notices + normally appear. The contents of the NOTICE file are for + informational purposes only and do not modify the License. + You may add Your own attribution notices within Derivative + Works that You distribute, alongside or in addition to the + NOTICE text from the Work, provided that such additional + attribution notices cannot be construed as modifying the + License. + + You may add Your own license statement for Your modifications and + may provide additional grant of rights to use, reproduce, modify, + and distribute those modifications, or for such Derivative Works + as a whole, under the terms of this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or reproducing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or exemplary damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or all other + commercial damages or losses), even if such Contributor has been + advised of the possibility of such damages. + + 9. Accepting Warranty or Liability. While redistributing the Work or + Derivative Works thereof, You may choose to offer, and charge a fee + for, acceptance of support, warranty, indemnity, or other liability + obligations and/or rights consistent with this License. However, in + accepting such obligations, You may offer such conditions only on + Your own behalf and on Your sole responsibility, not on behalf of + any other Contributor, and only if You agree to indemnify, defend, + and hold each Contributor harmless for any liability incurred by, + or claims asserted against, such Contributor by reason of your + accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the format in question. Please also make a + copy of the license document for recipients. + + Copyright 2024 Michael de Vries + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. From aebd12ecad8b189912ef71b3020b342989d7344e Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Sat, 11 Apr 2026 18:12:25 +0000 Subject: [PATCH 8/8] feat: harden Windows binary to reduce Defender false positives MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Add -s -w -buildid= to Go ldflags: strips debug/DWARF tables and makes builds reproducible (same source → same hash), which prevents reputation resets in Microsoft SmartScreen/Wacatac heuristics - Add go-winres step (Windows matrix only) to embed PE metadata into the .exe before go build: company name, product name, description, copyright, and version resource — making bb.exe look like a legitimate Windows application instead of a bare Go binary - gitignore the generated rsrc_windows_*.syso files Agent-Logs-Url: https://github.com/vriesdemichael/bitbucket-server-cli/sessions/e1bf7d7e-c04d-45f4-86af-9b34e8b066a0 Co-authored-by: vriesdemichael <9072548+vriesdemichael@users.noreply.github.com> --- .github/workflows/release.yml | 24 +++++++++++++++++++++++- .gitignore | 2 ++ 2 files changed, 25 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 5db1510f9..1c1d49f20 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -197,6 +197,28 @@ jobs: exit 1 fi + - name: Embed Windows PE metadata + if: matrix.goos == 'windows' + env: + VERSION: ${{ needs.determine-version.outputs.version }} + run: | + set -euo pipefail + go install github.com/tc-hib/go-winres@v0.3.3 + VERSION_NO_V="${VERSION#v}" + # PE version must be X.Y.Z.W (four numeric components) + PE_VERSION="${VERSION_NO_V}.0" + YEAR="$(date -u +%Y)" + go-winres simply \ + --arch amd64,arm64 \ + --out cmd/bb/rsrc \ + --manifest cli \ + --file-description "Bitbucket Server CLI" \ + --product-name "Bitbucket Server CLI" \ + --file-version "${PE_VERSION}" \ + --product-version "${PE_VERSION}" \ + --copyright "Copyright ${YEAR} Michael de Vries" \ + --original-filename "bb.exe" + - name: Build and package artifact env: VERSION: ${{ needs.determine-version.outputs.version }} @@ -212,7 +234,7 @@ jobs: BINARY_NAME="bb${BINARY_EXT}" ARCHIVE_BASENAME="bb_${VERSION_NO_V}_${GOOS}_${GOARCH}" - CGO_ENABLED=0 GOOS="$GOOS" GOARCH="$GOARCH" go build -trimpath -ldflags "-X main.Version=${VERSION}" -o "$BINARY_NAME" ./cmd/bb + CGO_ENABLED=0 GOOS="$GOOS" GOARCH="$GOARCH" go build -trimpath -ldflags "-s -w -buildid= -X main.Version=${VERSION}" -o "$BINARY_NAME" ./cmd/bb if [[ "$ARCHIVE" == "zip" ]]; then ARCHIVE_NAME="${ARCHIVE_BASENAME}.zip" diff --git a/.gitignore b/.gitignore index 100772161..1dc787644 100644 --- a/.gitignore +++ b/.gitignore @@ -14,3 +14,5 @@ __pycache__/ /docs/.venv/ /.tmp/* !/.tmp/.gitkeep +# Generated Windows PE resource files (created by go-winres during CI builds) +cmd/bb/rsrc_windows_*.syso