Skip to content

Add CI to style and audit the tap - #10

Merged
joe4dev merged 4 commits into
mainfrom
add-tap-ci
Sep 23, 2026
Merged

joe4dev merged 4 commits into
mainfrom
add-tap-ci

Conversation

@joe4dev

@joe4dev joe4dev commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

Motivation

This tap has no CI. Content arrives two ways — release bots push generated files to main, and people hand-edit them (#8) — and nothing checks either. The deprecated postflight stanza (#7) shipped that way and survived two lstk releases.

localstack/lstk#511 adds a gate on the generating side, but one class of fault is invisible there: it renders the cask before the release it points at exists, so its urls 404 and its sha256 values are of locally built archives. Whether the published artifacts actually resolve and match can only be checked here.

Solution

One job on macos-latest, since casks are macOS artifacts and the runner ships Homebrew. The checkout is installed as localstack/tap because both brew audit and the cask cops resolve a tap name rather than a path.

  • brew style --cask localstack/tap/lstk
  • brew audit --cask --online localstack/tap/lstk — fetches every url and verifies every checksum, the part lstk cannot do
  • brew style + brew audit --formula --online for localstack-cli

Measured on main today

Check Result
brew style --cask lstk passes
brew audit --cask --online lstk passes, downloads and verifies both darwin archives
brew style --formula localstack-cli 5 offences
brew audit --formula --online localstack-cli 7 problems

So the cask half is green and enforced. The formula half runs with continue-on-error: true: Formula/localstack-cli.rb is generated by localstack-cli's Homebrew Releaser, and its problems are upstream of this repo — a redundant version, a non-standard NOASSERTION SPDX license, and four style offences. They are reported in the log rather than blocking. Fixing them here would be overwritten by the next release; localstack/localstack-cli#57 fixes them at the source.

One scheduled exception

brew style on the cask runs with --except-cops=Cask/StanzaOrder and a TODO(localstack/lstk#512).

It is green without the exception right now, because #8 hand-patched the cask. The next lstk release regenerates it from .goreleaser.yaml, where the interim fix writes the stanza through custom_block — which renders it first in the file and trips Cask/StanzaOrder on every stanza after it. localstack/lstk#512 moves to the hooks.post.install_steps form, which renders it in place; the exception comes out then.

It is scoped to that one cop, so Cask/InstallSteps — the cop that catches #7 — still fires.

Dependencies

Both halves of this job carry a deliberate escape hatch, and each one closes when a fix lands elsewhere and a release regenerates the file. Merging the upstream PR alone changes nothing here.

Waiting on Unblocks Then
localstack/localstack-cli#57 Formula/localstack-cli.rb linting clean (verified: style, audit and audit --online all clean) drop continue-on-error: true from the formula step
localstack/lstk#512 the cask stanza rendering in place rather than first drop --except-cops=Cask/StanzaOrder

Neither blocks merging this PR — it is useful as soon as it lands, and reports what it cannot yet enforce.

Review

Human review advised: it is this repo's first workflow, and it decides what can land in the tap.

Guards against a recurrence of #7, which #8 fixed by hand.

🤖 Generated with Claude Code

joe4dev and others added 3 commits September 22, 2026 14:59
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Claude <noreply@anthropic.com>
@joe4dev
joe4dev marked this pull request as ready for review September 22, 2026 15:57

@anisaoshafi anisaoshafi left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good work! Thanks for adding these guardrails 🦺

Comment thread .github/workflows/ci.yml
# because `-e` would otherwise abort before the audit.
- name: Style and audit the formula
if: always()
continue-on-error: true

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

when do we change this to false? localstack/localstack-cli#57 is already approved. So the plan is to release that #57 first, then make this CI step blocking?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I created a personal reminder to follow up once a new localstack-cli release ships. Refining the deprecation warning would be such a change that triggers a release.
I felt it wasn't worth triggering a dummy release.

@joe4dev
joe4dev merged commit aea0d46 into main Sep 23, 2026
1 check passed
@joe4dev
joe4dev deleted the add-tap-ci branch September 23, 2026 15:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants