Move the cask to the org-wide tap and fail loudly without the token - #175
Merged
Merged
Conversation
Lumen is about to ship a cask too, and a tap per project means a user tapping twice for two projects from the same org. `brew tap ghost-language/tap` now covers both. The silent skip goes with it. Deriving skip_upload from the presence of HOMEBREW_TAP_TOKEN meant a release with no token produced a green run, published binaries, and a tap that was never touched - which is exactly what v1.0.0-beta.3 did, and it was invisible until someone ran `brew install` and found nothing there. The token is now checked in verify, before any archive is built, so the failure is loud, early, and free. Existing users of ghost-language/homebrew-ghost keep the beta.3 cask that is already there; they need to re-tap to get anything newer. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
.goreleaser.yml: the cask now goes toghost-language/homebrew-tapinstead ofghost-language/homebrew-ghost..goreleaser.yml:skip_uploadis gone, so the push always happens..github/workflows/release.yml:verifychecksHOMEBREW_TAP_TOKENis present onreleaseevents, before anything is built.Formula/ghost.rbfrom the tap — that's done.Why the shared tap
Lumen ships a cask in ghost-language/lumen#19, and a tap per project means users tap twice for two projects from the same org. One
brew tap ghost-language/tapnow covers both, and anything else that ships a binary later.Why the silent skip had to go
skip_uploadwas derived from the presence of the token:The intent was reasonable — don't fail a release whose binaries are already published. The effect was worse than a failure.
v1.0.0-beta.3released with no token set: the run went green, nine archives published, and the tap was never touched. Nothing in the log said so above debug level, and it only surfaced whenbrew installfound nothing.Checking in
verifyinverts that. A missing token now costs one job that hasn't built anything, and the error says exactly what to add.For existing users
Anyone tapped on
ghost-language/homebrew-ghostkeeps the1.0.0-beta.3cask sitting there — it stays installable. They need to re-tap to receive anything newer:Given
1.0.0-beta.3is a few hours old, that population is approximately nobody.Note
HOMEBREW_TAP_TOKENcurrently on this repo is scoped tohomebrew-ghost. It needs re-scoping tohomebrew-tap, or the first release after this merges fails inverify— loudly, which is the point.🤖 Generated with Claude Code