Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 20 additions & 2 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,6 +60,23 @@ jobs:
fi
echo "$TAG matches version/version.go"

# The cask is pushed at the end of the release, once the binaries are
# already published. A token discovered missing at that point leaves a
# green release pointing at a stale tap - which is what v1.0.0-beta.3 did
# - so it is checked here, before anything is built.
- name: Check the Homebrew tap token is present
if: github.event_name == 'release'
env:
HOMEBREW_TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}
run: |
if [ -z "$HOMEBREW_TAP_TOKEN" ]; then
echo "::error::HOMEBREW_TAP_TOKEN is not set on this repository."
echo "The cask in ghost-language/homebrew-tap cannot be updated without it."
echo "Add a token with contents:write on ghost-language/homebrew-tap, then re-run."
exit 1
fi
echo "HOMEBREW_TAP_TOKEN is present"

# fmt, vet, test and bench - the same gate a pull request has to pass.
- name: Check
run: make check
Expand Down Expand Up @@ -98,8 +115,9 @@ jobs:
${{ github.event_name == 'workflow_dispatch' && '--snapshot --skip=publish,announce' || '' }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Optional. Absent, GoReleaser skips the Homebrew formula rather than
# failing the release - see skip_upload in .goreleaser.yml.
# Required for a real release: GoReleaser pushes the cask to
# ghost-language/homebrew-tap with it. Verify has already checked it
# is present, so a failure here is a real failure.
HOMEBREW_TAP_TOKEN: ${{ secrets.HOMEBREW_TAP_TOKEN }}

- name: Upload the dry run's archives
Expand Down
14 changes: 5 additions & 9 deletions .goreleaser.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,25 +72,21 @@ homebrew_casks:
- name: ghost
repository:
owner: ghost-language
name: homebrew-ghost
# The org-wide tap, shared with Lumen and anything else that ships a
# binary, rather than a tap per project: `brew tap ghost-language/tap`
# once covers all of them.
name: homebrew-tap
# The tap is a separate repository, so the workflow's automatic
# GITHUB_TOKEN cannot push to it. This needs a personal access token
# with contents:write on ghost-language/homebrew-ghost, stored as the
# with contents:write on ghost-language/homebrew-tap, stored as the
# HOMEBREW_TAP_TOKEN secret.
token: "{{ .Env.HOMEBREW_TAP_TOKEN }}"
# Without the token the cask cannot be pushed. Skipping that one step is
# better than failing a release whose binaries are already published.
skip_upload: '{{ if .Env.HOMEBREW_TAP_TOKEN }}false{{ else }}true{{ end }}'
commit_author:
name: github-actions[bot]
email: 41898282+github-actions[bot]@users.noreply.github.com
homepage: "https://github.com/ghost-language/ghost"
description: "Ghost, a dynamically typed scripting language."
license: "MIT"
# No conflict is declared against the formula this cask replaces, even
# though both install the same binary: a cask can only conflict with
# another cask. Formula/ghost.rb has to be deleted from the tap by hand
# once the first cask release has landed.
hooks:
post:
# The binaries are not signed or notarised, so macOS quarantines them
Expand Down
Loading