The v0.5.3 release failed to attach binaries ("open node-lookup-linux-amd64:
no such file or directory"). Woodpecker substitutes ${...} expressions in
`commands` at parse time, so the build loop's shell parameter expansions
(${name}, ${osarch%/*}, ${pkg}) and the release step's ${PREV_TAG}/${NOTES}
were blanked before the shell ran — the per-os/arch binaries were written to
garbled names and the release notes came out empty.
- Escape all shell variables and command substitutions in the build loop and
release-notes block as $$, matching the existing upload-rpm step. Real
Woodpecker vars (${CI_COMMIT_TAG}, ${CI_REPO}) stay single-$.